Security & HIPAA
Written for the person who has to answer the auditor.
Faxing exists in healthcare, law, and finance because those industries need a record. Here’s exactly how we protect it — and what we’ll sign.
The BAA
Every Signal Fax customer can execute a Business Associate Agreement at no cost, from the dashboard, on any plan. It’s a standard, unmodified BAA — read it before you sign up if you like. We are a business associate under HIPAA and we act like one.
Download the BAA (PDF)How your documents are protected
TLS 1.3 for everything web and API. Faxes travel our network encrypted end to end and are handed to the PSTN only at the final leg — which is true of every fax service, and we say so rather than implying otherwise.
AES-256 for documents at rest in object storage, with keys managed by the storage provider.
Two-factor authentication on user accounts, and role-based permissions that separate who can send from who can only view. Access to a fax is scoped to the number or group it belongs to.
Every view, send, download, and export is logged with user and timestamp, and exportable for your compliance file.
Your fax history is retained for as long as your account is open, and stays exportable for 30 days after you cancel. Deletion is real deletion, including from backups on a defined schedule.
What we commit to
What we won’t claim
There is no such thing as a “HIPAA-certified” fax service — HIPAA has no certification body. Any vendor telling you they’re “HIPAA certified” is telling you something that doesn’t exist. What matters is whether they’ll sign a BAA, what’s in it, and whether their controls hold up. We’ll show you all three.