CJIS and Faxing Criminal Justice Information — What You Need to Verify
The FBI CJIS Security Policy governs how criminal justice information (CJI), including criminal history record information, is stored and transmitted. Send FAX Mail offers AES-256 encryption, multi-factor authentication, and audit logging that map to several CJIS technical controls — but CJIS also imposes personnel and facility requirements a fax vendor must be vetted against.
CJIS Requirements for Fax
- Encryption of CJI in transit and at rest using FIPS 140-validated, AES 256-bit cryptography
- Advanced (multi-factor) authentication for access to CJI
- Personnel security screening — including fingerprint-based background checks — for anyone with access to unencrypted CJI
- Physical protection of facilities where CJI is processed or stored
- Detailed audit logging of access to and transmission of CJI
- A signed CJIS Security Addendum with any vendor that can access unencrypted CJI
How Send FAX Mail Meets CJIS
- AES-256 encryption of faxes in transit and at rest, aligning with the CJIS cryptographic strength requirement
- Multi-factor authentication (TOTP) and SSO options for advanced authentication on account access
- Per-user access controls so only authorized staff open received faxes
- A per-fax audit trail (who sent, recipient, timestamp, delivery status) to support CJIS audit logging
- Configurable retention and secure purge of stored faxes
- Honest scoping: we do not by default provide a signed CJIS Security Addendum, fingerprint-screened personnel, or a CJIS-audited data center — confirm any vendor arrangement with your CJIS Systems Agency
Industries Affected
Starter
- 600 fax pages per month
- 1 dedicated fax number
- Send & receive faxes
- Fax to email delivery
- Fax history & downloads
- No per-page overage charges
Professional
- 2,000 fax pages per month
- 3 dedicated fax numbers
- HIPAA compliance + self-serve BAA
- Sign documents before sending
- Priority delivery
- No per-page overage charges
Business
- 5,000 fax pages per month
- 5 dedicated fax numbers
- HIPAA compliance + self-serve BAA
- Public API & webhooks
- Audit logs
- Team roles & permissions
- Priority support
Enterprise
- 8,000 fax pages per month
- 10 dedicated fax numbers
- Everything in Business
- Public API & signed webhooks
- Dedicated support
- Custom integrations
No per-page overage. No activation fees. No contracts. Cancel anytime.
What’s current · as of August 2026
- HIPAA large-breach reporting threshold
- 500+ individuals — reported to HHS OCR without unreasonable delay Source: HHS Office for Civil Rights
- HIPAA documentation retention period
- 6 years from creation or last-effective date Source: HHS — HIPAA Administrative Requirements (45 CFR 164.316)
Recent updates
Federal interoperability rules keep pushing healthcare past the fax machine
CMS has advanced a series of interoperability rules that press hospitals, payers, and providers toward electronic data exchange and standardized claims attachments. The direction of travel is clear: paper and analog fax workflows are being replaced by digital transmission that carries an auditable record — which is exactly what a cloud fax with delivery confirmation provides for offices not yet on a full EHR pipeline.
CMS →Federal agencies still write fax into new rules and notices
The Federal Register — the daily journal of U.S. federal rulemaking — regularly publishes rules and notices that reference fax as an accepted or required submission channel for filings with agencies like the IRS, SSA, and CMS. That is why fax remains a live requirement for many official forms even as electronic portals expand.
Federal Register →Healthcare breach reporting keeps document handling under scrutiny
Ongoing reporting on HIPAA breaches and OCR settlements underscores how much scrutiny falls on how medical documents are stored, sent, and received. Sending records through a controlled, access-logged channel rather than an unmanaged machine reduces the mishandling risks that show up repeatedly in breach analyses.
HIPAA Journal →
CJIS Fax Compliance — FAQ
CJIS compliance is assessed against your whole environment and your CJIS Systems Agency (CSA), not granted by a single vendor. Send FAX Mail provides AES-256 encryption, MFA, and audit logging that align with CJIS technical controls, but we do not claim a CJIS-certified facility or fingerprint-screened staff. Verify any tool with your CSA before transmitting CJI.
CJIS also requires background-screened personnel, physical facility protections, and typically a signed CJIS Security Addendum with vendors who can access unencrypted CJI. Send FAX Mail does not provide those by default, so it should not be treated as a turnkey CJIS solution for unencrypted CJI access.
Technically the transmission is encrypted with AES-256, which supports the confidentiality requirement. Whether your agency may use it depends on your CSA's determination and your Security Addendum obligations. Treat the encrypted transport as one supporting control, not a compliance guarantee.
CJIS requires advanced authentication for access to CJI. Send FAX Mail supports TOTP-based MFA and SSO on account login, which maps to that control for access to the fax application. Your agency still owns endpoint, network, and personnel controls that CJIS also mandates.
CJIS-compliant faxing starts at $39.99/mo
Encrypted transmission, audit logs, secure storage. No enterprise contract needed.
7-day free trial · No credit card required