HIPAA fax API for healthcare
mintfax lets your application send referrals, lab results, and other documents to a fax number. You can test the integration in a free sandbox and sign a Business Associate Agreement (BAA) in the dashboard before sending patient information.
Review and sign the BAA
An authorized signer can review the agreement, accept it, and download the signed PDF immediately. The BAA is available at every price tier. mintfax records who signed, when they signed, and which version they accepted.
The HIPAA page explains the agreement and the systems covered by mintfax’s commitments.
Control how long patient information is stored
Fax content, cover-page text, and sender and recipient names are subject to mintfax’s protected health information (PHI) retention settings. The default is 30 days after delivery or failure. You can set a period between 7 and 365 days for each environment.
You can also delete a fax’s content through the API. If you enable zero-footprint mode, mintfax deletes that content as soon as delivery succeeds or fails. The destination number and operational records, such as status and attempt history, remain.
The patient information guide explains what is deleted and how to configure these settings.
Track delivery and access
Signed webhooks tell your application when a fax is delivered or fails. Idempotency keys prevent duplicate submissions when your application retries the same request within the 24-hour expiry period.
The audit log records access to patient content, including access by mintfax staff through support tools. Staff entries include an identifier and a reason. You can export the log through the API or download it as CSV. Audit records are kept for six years.
Check the service fits your requirements
mintfax sends faxes; it does not receive them. Data is stored in one US region, with no region selection. mintfax does not hold SOC 2, HITRUST, ISO 27001, FedRAMP, or PCI DSS Level 1 certification.
The compliance page describes encryption and the limits of mintfax’s commitments, including the carrier and recipient systems outside its control.
Get started
Try the sandbox using sample documents, then follow the HIPAA implementation guide before sending patient information. Pricing is per page.