
So here's the real question: when fax moves off the old phone line and onto a VoIP or internet-based system, does that help or hurt security?
The short answer is that it depends almost entirely on encryption and compliance controls, not the fact that it's "internet-based." This guide breaks down how VoIP fax encryption actually works, which rules it needs to satisfy (HIPAA, GLBA, SOX), and what to verify before trusting any provider with sensitive documents.
Key Takeaways
- VoIP faxing can be more secure than analog fax, but only with proper TLS/SSL encryption and a provider that backs up its claims
- T.38 replaced the legacy T.30 protocol for IP transmission, but T.38 alone doesn't guarantee encryption
- HIPAA, GLBA, and SOX each impose different requirements, so encryption strength isn't the only compliance box to check
- Human error, not weak encryption, remains the leading cause of accidental fax disclosure
- A provider's willingness to sign a BAA and name a privacy contact says more than any "bank-level security" claim
What Is Faxing Over VoIP and How Does It Work?
VoIP faxing swaps the analog phone line and physical machine for an internet connection. Instead of a fax tone traveling over copper wire, your document becomes digital data that routes to a recipient's fax number or straight into an email inbox.
Two Ways to Send a Fax Over VoIP
There are two common delivery paths:
- A dedicated online fax service or app: you upload a document, and the platform handles transmission
- Email-to-fax: you attach a file to an email, and the address itself triggers the fax send
Recipients aren't locked out if they still use a physical machine, either. A gateway, a small piece of hardware or software that bridges digital and analog signals, converts the digital transmission back into a signal that a traditional fax machine understands on the receiving end.
This technical shift matters. Analog signals over PSTN lines become digital packets over IP networks, and that shift is what makes stronger encryption possible in the first place. It also introduces new dependencies: your fax security is now tied to device security and network hygiene, not just the phone line.

Why Businesses Still Rely on Fax in a Digital-First World
Email is fast, but it doesn't carry the same legal weight in many regulated contexts. A faxed signature or document creates a clear transmission trail that courts, regulators, and auditors recognize. A forwarded email thread often can't replicate that trail as cleanly.
That's why three industries lean on fax specifically:
- Healthcare — prescriptions, patient records, referrals
- Legal — court filings, signed contracts, discovery documents
- Financial services — loan documents, applications, account authorizations
The reliance isn't theoretical, at least not in healthcare. A Becker's Hospital Review analysis of a GAO study found that 47.4% of small hospitals and 42.8% of rural hospitals cited "mail or fax" as their most-used method for sending medical records. That figure blends mail and fax together, so it's not a pure fax number. Still, it's strong evidence that legacy delivery methods remain deeply embedded in healthcare operations rather than phased out.
Pipeline Media, a Toronto-based business communications agency operating since 2003, sees this pattern directly. Healthcare, financial services, and government organizations make up a meaningful share of its Fax Broadcast and Fax-To-Email client base. These sectors need a documented, traceable transmission more than they need speed, which is exactly what keeps fax relevant even as it moves onto digital infrastructure like VoIP.
How Encryption Actually Secures Your Faxes Over VoIP
T.38 vs. T.30: The Protocol Shift
The legacy T.30 protocol governs fax transmission over the traditional switched telephone network, it handles call setup, signaling, and the audio-based handshake between two machines. T.38 was built to carry that same fax signaling over IP networks instead, converting it into packets that survive the trip across the internet without data loss.
| Feature | T.30 | T.38 |
|---|---|---|
| Network type | PSTN (analog phone line) | VoIP/IP network |
| Data format | Audio tones | Digital packets |
| Connection type | Single point-to-point call | IP network compatible |
| Packet-loss handling | Not applicable | Built for it |
| Native encryption | None | None by default |

Here's the part that gets glossed over in marketing copy, T.38 itself doesn't include built-in security. The ITU standard defining T.38 explicitly states it lacks native encryption support. Security has to come from a separate, properly configured transport layer, not from T.38 alone.
The Three Layers That Actually Protect Your Fax
Since the protocol itself offers no protection, real security comes from stacking three layers on top of it. This is also the checklist worth applying when evaluating any fax-to-email provider's claims:
- 256-bit encryption (AES-256) — makes brute-force decryption computationally impractical
- SSL/TLS for authentication and transmission — verifies sender and recipient identity, then scrambles data as it moves
- Access controls — password-protected accounts and sender/number blocking add a practical layer beyond pure cryptography

"SSL" is often used loosely in marketing. Current NIST guidance requires TLS, not legacy SSL versions, for secure connections. If a provider only says "SSL encryption" without specifying protocol version, that's worth a follow-up question.
In Transit vs. At Rest — Both Matter
Encryption "in transit" protects your fax while it's moving across the network. Encryption "at rest" protects it once it lands, sitting in an inbox, a cloud archive, or a provider's storage system. A provider can have excellent transit encryption and still leave faxed documents exposed if storage isn't locked down too.
Encryption isn't a silver bullet. A compromised laptop or an unsecured device on the same network can still expose a faxed document regardless of transmission encryption strength. IT hygiene matters as much as protocol strength.
Compliance Requirements That VoIP Fax Providers Must Meet
Strong encryption is necessary but not sufficient. "Secure" also means satisfying the specific regulatory framework tied to your industry.
Healthcare: HIPAA
HIPAA's technical safeguards require:
- Encrypted transmission of electronic protected health information (ePHI)
- Access controls and audit logs that record who accessed data and when
- Business Associate Agreements (BAAs) with any vendor that transmits or stores ePHI
Here's the catch: HIPAA labels encryption "addressable," not mandatory in every scenario, but that doesn't mean optional. Organizations must document why an alternative safeguard is equally effective if they skip standard encryption. In practice, almost none do.
Financial Services: GLBA
Under the FTC Safeguards Rule, financial institutions must:
- Encrypt customer information both in transit and at rest
- Confirm secure retry and delivery mechanisms
- Maintain access controls, monitoring, and a documented incident-response plan
- Dispose of customer information within two years of last use, with some exceptions
Legal and Government
These sectors carry their own strict expectations. Requirements typically include:
- Confidentiality of privileged communications between parties
- Chain-of-custody documentation tracking a document's handling from send to receipt
- Delivery confirmation receipts that serve as evidentiary proof if a dispute arises later
The stakes are real. IBM's 2025 Cost of a Data Breach Report puts the average healthcare breach cost at $7.42 million — the highest of any industry for the 14th year running. That figure isn't fax-specific, but it's why regulated industries treat every transmission channel, fax included, as a compliance checkpoint rather than an afterthought. Providers handling fax traffic for healthcare, financial services, or government clients need to meet these standards by default, not as an add-on.

Common Security Risks to Watch for With VoIP Faxing
VoIP faxing introduces risks beyond encryption strength alone. Three areas deserve close attention:
- Shared infrastructure: VoIP faxing runs on the same network as your computers and other devices. An infected machine on that network can expose fax data even when the transmission itself is properly encrypted.
- Network reliability: Packet loss, jitter, or an unstable connection can cause incomplete transmissions. In a regulated context, an unconfirmed delivery is a potential compliance gap if you can't prove the document arrived.
- Human error: A misdialed fax number or an unencrypted email-to-fax setup without provider-side safeguards remains a leading cause of accidental disclosure. This risk is often underrated compared to encryption concerns.
The U.S. Department of Health and Human Services documented a case where a doctor's office mistakenly faxed HIV-related records to a patient's employer instead of their new provider. No encryption failure caused that; a wrong number did.
That last point matters more than most encryption discussions give it credit for. You can have flawless TLS and still send sensitive data to the wrong destination.
How to Choose a Secure, Compliant VoIP Fax Provider
Before signing with any provider, run through this checklist:
- Confirm TLS/SSL encryption is actively used, not just referenced generically
- Ask if they'll sign a BAA if you're handling protected health information
- Verify document storage: accounts should be password-protected, not open inboxes
- Check delivery and retry guarantees: regulated industries need proof of transmission, not just an attempt log
- Look for a named privacy contact, not a generic support ticket queue
End-to-end managed services also reduce your exposure compared to DIY email-to-fax setups. Every extra tool or workaround you stitch together yourself is another potential security gap you're responsible for closing.
This is where full-service providers earn their keep. Pipeline Media's Fax Broadcast and Fax-to-Email services handle the entire transmission process, retrying failed numbers automatically (three attempts, free of charge) and delivering detailed reports on exactly which faxes succeeded, which failed, and why. For organizations in Financial Services, Healthcare, and Government that need a hands-off solution without maintaining physical fax hardware, that kind of operational accountability matters as much as the underlying encryption.
Pipeline also names a specific point of contact for privacy questions, Mark Hunter, Director of Sales, rather than routing inquiries through a generic inbox. It's worth checking whether any provider you consider offers the same, since anonymous support lines rarely take ownership of compliance questions.
Before committing to any provider for HIPAA-regulated faxing specifically, confirm BAA availability directly with their team — this varies by provider and should never be assumed from marketing language alone.
Frequently Asked Questions
Is VoIP faxing HIPAA compliant?
VoIP faxing is a transmission method, not an automatic compliance guarantee. HIPAA compliance depends on the provider using encrypted transmission, signing a BAA, and maintaining audit controls.
Is faxing over VoIP secure?
With proper encryption (TLS/SSL, 256-bit) and a reputable provider, VoIP faxing is generally more secure than traditional analog faxing. Endpoint device security still matters just as much.
Do VoIP phone services include a fax service?
Many VoIP or UCaaS providers bundle fax as an add-on feature. Dedicated fax-focused providers typically offer more flexibility and features built specifically for compliant business faxing.
Can I fax without a landline connection?
Yes. VoIP faxing eliminates the need for a landline entirely, using an internet connection with either software or an analog telephone adapter for physical machines.
Is it safe to fax sensitive documents like medical records or contracts over VoIP?
Sensitive documents can be transmitted safely when the provider uses strong encryption, secure storage, and compliance certifications relevant to your document type and industry.
What's the difference between T.30 and T.38 fax protocols?
T.30 governs traditional analog PSTN fax transmission. T.38 is the IP-based protocol built for VoIP networks, offering better packet-loss handling and digital-native compatibility. Neither protocol includes built-in encryption by default.