HIPAA compliant fax service

Before using mintfax to send protected health information (PHI), review and sign the Business Associate Agreement (BAA) in the dashboard. It is available at every price tier, at no extra cost.

An authorized signer can accept the agreement and download the signed PDF immediately. mintfax records the agreement version, signer details, and acceptance time.

Patient information controls

Encryption. Fax content is encrypted in storage with AES-256 under mintfax-managed keys. API requests and outbound webhooks use TLS 1.2 or higher. Webhook endpoints must use HTTPS.

Content retention. The default is 30 days after a fax is delivered or fails. You can set a period between 7 and 365 days for each environment. You can also delete a fax’s content through DELETE /v1/faxes/{id}/content.

Automatic deletion. Zero-footprint mode deletes PHI as soon as the fax is delivered or fails. It is off by default. The destination number and operational records remain, including status, error codes, timestamps, and attempt history. Billing records are kept permanently.

The patient information guide explains the affected fields and configuration steps.

Access records

The audit log records access to fax content through the API, dashboard, and mintfax support tools. Staff access entries include a staff identifier and a reason.

Audit records are kept for six years. Each entry includes linked hashes so you can check for alterations. Export the log through GET /v1/account/audit or download CSV from the dashboard.

Providers that process data

The subprocessor list identifies each provider’s role, region, and status. Changes to primary providers are announced at least 14 days in advance.

Standby providers are listed before use and may be activated on short notice. Adding a provider to the standby list requires the same advance notice.

Scope of the agreement

mintfax’s commitments cover its API infrastructure, content storage, operational databases, and application logs. They exclude upstream carriers, recipient fax systems, your webhook endpoints, and payment processors.

Fax transmission over the telephone network is not encrypted end to end. Review the BAA and the HIPAA implementation guide alongside your organization’s requirements.

Service limits

Data is stored in one US region. Region selection and customer-managed encryption keys are not available.

mintfax does not hold SOC 2, HITRUST, ISO 27001, FedRAMP, or PCI DSS Level 1 certification. A signed BAA and these controls do not establish compliance for your entire workflow.

You can keep copies of the signed BAA and export your audit log for your own records.

Next steps

START HERE

Try sending a fax in the sandbox.

Test the API with simulated deliveries before sending real faxes. The sandbox is free and does not require a credit card.

SANDBOXFree
SPECOpenAPI 3.1
CREDIT CARDNot required
WEBHOOKSSigned
ERRORSDocumented