· by L'équipe EnvoiFaxGratuit
Medical Fax and Health Data: What the Law Says
Medical fax, GDPR and professional secrecy: what French law really allows when transmitting health data, and how to secure every transmission.

Short answer: transmitting health data by fax is not prohibited in France, but it is not a blank cheque either. The GDPR classifies this information as sensitive data, the French Public Health Code imposes professional secrecy, and the CNIL expects the data controller to be able to demonstrate "appropriate" measures. In practice: a medical fax remains lawful provided the number is dialled correctly, it is sent to an identified machine, the cover page contains no diagnosis, and it is retained for a defined period. Secure health messaging remains the reference channel whenever the recipient has access to it.
Why the fax never left medical practices
There is an apparent contradiction here. On one side, since 2015 France has built an entire secure messaging ecosystem — the MSSanté space, operated by the Agence du numérique en santé (ANS) — designed precisely to replace unencrypted exchanges between professionals. On the other, testing laboratories, imaging departments, nursing homes, retail pharmacies and a share of private practices continue to send and receive faxes every single day.
There are three reasons for this, and none of them is irrational.
The first is unequal equipment. Secure messaging only works if both ends are connected to it and know how to use it. A fax works as soon as the recipient has a number. A locum doctor, a private nurse on her rounds, a facility in a rural area: coverage is not uniform, and the slowest channel sets the pace.
The second is proof of delivery. A fax transmission report attests that an identified machine picked up, accepted the document and confirmed receipt page by page. An email, even encrypted, proves that a message left a server; it does not prove that a human opened it. In a hospital department where a prescription must be delivered before a given hour, that distinction matters.
The third is organisational. A fax machine does not depend on any personal login. In a care station where the team changes three times a day, a document that lands in a physical tray stays visible; a document dropped into the inbox of a practitioner who is away for three days does not.

What the law actually says
Health data is "sensitive" data
Article 9 of the GDPR prohibits, as a matter of principle, the processing of data concerning health, then reopens the door through a list of exceptions. The one that applies to healthcare professionals is paragraph 2(h): processing is lawful where it is necessary for the purposes of preventive medicine, medical diagnosis, the provision of health care or the management of health systems, and where it is carried out by a professional bound by secrecy.
In other words: a doctor who faxes a report to a colleague for the continuity of care is acting within the framework foreseen by the text. No specific written consent is required for that exchange, but under Article 32 of the GDPR the doctor remains obliged to implement "appropriate technical and organisational measures" commensurate with the risk.
Professional secrecy under French law
Article L. 1110-4 of the Public Health Code establishes the right of every person receiving care to respect for their private life and for the confidentiality of information concerning them. Breach of professional secrecy is further punished under Article 226-13 of the Criminal Code: one year's imprisonment and a €15,000 fine.
Sharing between professionals is tightly framed: it must be strictly necessary for the coordination or continuity of care, and the patient must be informed of their right to object. Sending a complete file when a single page would have sufficed is not an administrative slip, it is excessive sharing.
What the CNIL has actually said about faxes
The CNIL has never issued a blanket ban on faxes in healthcare. It has, however, sanctioned and formally warned organisations over poorly controlled transmissions of medical data, and its reference framework on the processing of personal data for the management of medical and paramedical practices insists on two constant points:
- minimisation: transmit only the data necessary for the purpose pursued;
- confidentiality on receipt: the receiving equipment must be located in premises with controlled access.
The second point is the one that causes trouble in real life. A fax machine sitting in a reception corridor, or in a room where delivery drivers and visitors walk through, turns every incoming page into a public notice. The technology is not the problem: the location of the output tray is.
And what about data hosting?
As soon as a provider stores, on behalf of a healthcare professional, personal health data collected in connection with prevention, diagnosis or care activities, it falls within the scope of HDS certification (health data host), provided for by Article L. 1111-8 of the Public Health Code and overseen by the ANS.
This distinction matters for online fax services. A service that transmits a document and then deletes it within a short period is not in the same legal position as a service that archives sent documents on a lasting basis. As soon as there is storage on behalf of the care provider, the HDS question arises. That is the first question to put to a provider, even before pricing.
The six most common mistakes
| Mistake | Consequence | Fix |
|---|---|---|
| One digit too many or too few in the number | The file lands with an unknown third party | Read the number aloud twice before sending |
| Diagnosis written on the cover page | Readable by anyone walking past the tray | Neutral cover page, data on page 2 |
| Fax machine in a thoroughfare | Viewed by non-care staff | Locked room, supervised output |
| Stored numbers never checked | Sent to a closed or taken-over practice | Annual review of the directory |
| No defined retention period | Unlimited build-up of receipts | Written policy, periodic purge |
| No procedure for errors | Breach not notified within 72 hours | Quick-reference sheet posted near the machine |
The last line deserves elaboration. A medical fax sent to the wrong number constitutes a personal data breach within the meaning of Article 4(12) of the GDPR. If it is likely to result in a risk to the rights and freedoms of individuals, it must be notified to the CNIL within 72 hours via the dedicated online service, and, where the risk is high, the data subject must be informed. Since health data is sensitive by nature, the high-risk threshold is reached very quickly.

Fax, secure messaging, post: how to choose
There is no universally superior channel. There are situations.
Use secure health messaging (MSSanté) when the recipient is connected to it and the exchange is professional to professional. It is the channel recommended by the ANS: strong identification of correspondents through the health directory, encryption in transit, growing integration into practice-management software. For a hospital discharge summary sent to a family doctor, it is the default choice.
Use fax when the recipient has no usable secure mailbox, when delivery must be evidenced within the hour, or when the recipient is a service — the front desk of a diagnostic unit, a laboratory switchboard — rather than a named individual. Fax also remains the format expected by certain administrative forms and certain insurance funds.
Use registered post when the evidentiary value of the posting date outweighs speed: appeals, complaints, submission of a file to a review board.
Never use ordinary email for named medical content. An unencrypted email travels through intermediate servers that are neither identified nor under contract. It is the only case where the answer is a flat no.
The case of online fax services
An online fax is not inherently less secure than a desktop fax machine — it simply shifts the risk. The "telephone line" leg of the journey is identical. The difference lies upstream: your document passes through a gateway.
The questions to ask the provider, in order:
- Is the document encrypted in transit (HTTPS/TLS) between your browser and the gateway?
- How long is the file kept after sending? Is that documented?
- Where are the servers located? Hosting within the European Union avoids questions about transfers outside the EU.
- Is the provider HDS-certified, or does it undertake not to retain documents?
- Is a processing agreement within the meaning of Article 28 of the GDPR offered for professional use?
For occasional, non-professional use — a patient sending a treatment claim form or a supporting document to their insurance fund — these requirements are lighter: the individual owns their own data and freely chooses the channel. The common-sense rule still applies: prefer a service that states files are deleted promptly, and check the list of supported destinations on the available countries page before dialling an international number.

A seven-step sending procedure
This protocol fits on an A5 sheet to be pinned up next to the machine. There is nothing theoretical about it: most documented incidents stem from skipping one of these steps.
- Check the necessity. Is the data being sent strictly useful to the recipient? If not, remove the superfluous pages.
- Anonymise whatever can be anonymised. An internal file number is sometimes enough where a full name and date of birth used to be written.
- Draft a neutral cover page. Sender, named recipient, page count, confidentiality notice. No clinical information whatsoever.
- Read the number twice, aloud if possible, checking the dialling code.
- Warn the recipient by phone when the document is sensitive or urgent, so that someone is there when it arrives.
- Keep the transmission report in the file or in a dated register, with a retention period defined in advance.
- In case of error, call the receiving party immediately, ask for the document to be destroyed, log the incident and start the notification assessment.
The confidentiality notice on the cover page has no binding force in itself, but it has practical value: it tells any third party who comes across the page that they should stop reading, and it documents your diligence in the event of an audit.
How long should a transmission report be kept?
There is no single statutory retention period for fax reports. The reasoning is done purpose by purpose:
- Evidence of an act of care or of a transmission to the patient file: the period aligns with that of the medical record. For healthcare establishments, Article R. 1112-7 of the Public Health Code sets retention at 20 years from the last stay, with specific rules for minors and deceased persons.
- Evidence of an administrative submission (insurance fund, complementary insurer, employer): the applicable appeal period, generally two years, is sufficient.
- Technical logs of an online service: a few months at most, and metadata only — never the content.
Writing this policy down somewhere matters more than the figure you settle on. A CNIL inspection rarely starts with "how long"; it starts with "where is that written down".
Frequently asked questions
Is fax prohibited for health data in France?
No. No text prohibits faxing in healthcare. The GDPR and the Public Health Code require appropriate measures and respect for secrecy, not a particular channel. Secure health messaging is recommended, and fax remains lawful when used with the precautions described above.
Is a fax encrypted?
No, not in the IT sense. A Group 3 transmission travels in the clear over the telephone network. Its security rests on the point-to-point nature of the link and on the practical difficulty of interception, not on encryption. That is why protecting the place of receipt counts just as much as protecting the content.
What should I do if I sent a medical fax to the wrong number?
Three actions within the hour: call the number dialled to ask for the document to be destroyed, log the incident in a breach register, then assess the risk to the individual concerned. If the risk is real, notify the CNIL within 72 hours and inform the patient if the risk is high.
Can a patient fax their own documents to their insurance fund?
Yes. A person transmitting their own health data is not subject to a professional's obligations. It is still wise to check the number with the organisation and to keep the transmission report. The arrangements for sending supporting documents are set out by each fund, notably on Ameli for the Assurance Maladie.
Does an online fax service have to be HDS-certified?
Only if it stores health data on behalf of a professional or an establishment. A service that merely transmits and deletes the file after sending is not carrying out a hosting activity within the meaning of Article L. 1111-8. The answer therefore depends on the retention policy, which must be set out in black and white.
Does a transmission report have legal value?
It amounts to prima facie evidence assessed by the judge, not conclusive proof. Its strength comes from the body of evidence: a time-stamped report, the fax machine's log, consistency with the patient file and, ideally, confirmation from the recipient. Other questions of this kind are covered in the site FAQ.
In summary
- Health data is sensitive data within the meaning of Article 9 of the GDPR: the lawfulness of exchanges between care providers rests on continuity of care, not on specific written consent.
- Fax is not prohibited in healthcare; it is regulated. MSSanté secure messaging remains the reference channel when the recipient is connected to it.
- A fax is not encrypted: security is decided at the receiving end, in premises with controlled access.
- Minimising pages, keeping the cover page neutral, reading the number twice and warning the recipient prevent almost all incidents.
- A wrong number is a data breach: register it, assess the risk, and notify the CNIL within 72 hours if necessary.
- Before choosing an online fax service for professional use, insist on a written answer about retention periods, server locations and the processing agreement.
