PHI and EMS workflows

Business Associate Agreement required before PHI use

FaxSeal can be evaluated for regulated fax workflows only under an Enterprise agreement with a countersigned BAA, agency-specific retention instructions, and documented safeguards.

Required before PHI transmission

Execute the BAA

FaxSeal self-service use is not authorized for PHI. A covered entity or business associate must execute the Enterprise BAA before transmitting PHI.

Classify the workflow

Identify whether the documents include patient identifiers, EMS run data, incident narratives, behavioral health details, public-health reports, or other regulated data.

Define retention ownership

The agency or provider must decide whether FaxSeal is transport only or a contracted record repository with defined retention, export, and deletion duties.

Configure enterprise access

Use organization workspaces, SSO, member roles, shared fax numbers, and documented offboarding for staff who handle PHI.

Document disclosure logs

Covered entities generally retain PHI disclosure documentation for 6 years. FaxSeal receipts can support that log, but the agency remains responsible for the official record unless contracted otherwise.

Enterprise BAA package

Enterprise BAA for approved PHI customers

Security overview and sub-processor list

DPA and incident-notice language

SLA and support escalation terms

Receipt, hash, and delivery verification controls

Agency retention and export plan

Not included by default

Self-service authorization to transmit PHI

Automatic HIPAA compliance for the customer workflow

Clinical review of document contents

Guarantee that a recipient read or acted on a fax

Legal advice about EMS or state health-record rules

Important default rule

Unless a customer has a countersigned Enterprise BAA with FaxSeal, PHI transmission remains outside the authorized self-service use of the product. This page is a procurement path, not legal advice or a blanket compliance claim.

Contact [email protected]