NIST 800-171 and Faxing Controlled Unclassified Information
NIST SP 800-171 defines 110 controls across 14 families for protecting Controlled Unclassified Information (CUI) in nonfederal systems, and underpins DFARS 252.204-7012 and CMMC Level 2. Send FAX Mail's encryption, MFA, access controls, and audit logging map to several of those controls — but a full 800-171 assessment and a compliant boundary are yours to own.
NIST 800-171 Requirements for Fax
- Implementation of the 110 controls across the 14 NIST 800-171 families where CUI is handled
- Encryption of CUI using FIPS-validated cryptographic modules
- Multi-factor authentication for access to systems processing CUI
- Audit and accountability logging of user actions on CUI
- Least-privilege access control over CUI
- Incident reporting to the DoD within 72 hours under DFARS 252.204-7012, and a self-attested SPRS score
How Send FAX Mail Meets NIST 800-171
- AES-256 encryption of faxes in transit and at rest, supporting the system-and-communications-protection controls
- Multi-factor authentication (TOTP) and SSO for the identification-and-authentication family
- Per-user, role-based access on the fax application for the access-control family
- A per-fax audit trail (sender, recipient, timestamp, delivery status) for the audit-and-accountability family
- Configurable retention and secure purge supporting media-protection controls
- Honest scoping: we do not attest FIPS-140 module validation or provide a GovCloud/FedRAMP boundary — your CUI boundary and full 110-control assessment remain your responsibility
Industries Affected
Starter
- 600 fax pages per month
- 1 dedicated fax number
- Send & receive faxes
- Fax to email delivery
- Fax history & downloads
- No per-page overage charges
Professional
- 2,000 fax pages per month
- 3 dedicated fax numbers
- HIPAA compliance + self-serve BAA
- Sign documents before sending
- Priority delivery
- No per-page overage charges
Business
- 5,000 fax pages per month
- 5 dedicated fax numbers
- HIPAA compliance + self-serve BAA
- Public API & webhooks
- Audit logs
- Team roles & permissions
- Priority support
Enterprise
- 8,000 fax pages per month
- 10 dedicated fax numbers
- Everything in Business
- Public API & signed webhooks
- Dedicated support
- Custom integrations
No per-page overage. No activation fees. No contracts. Cancel anytime.
What’s current · as of August 2026
- HIPAA large-breach reporting threshold
- 500+ individuals — reported to HHS OCR without unreasonable delay Source: HHS Office for Civil Rights
- HIPAA documentation retention period
- 6 years from creation or last-effective date Source: HHS — HIPAA Administrative Requirements (45 CFR 164.316)
Recent updates
Federal interoperability rules keep pushing healthcare past the fax machine
CMS has advanced a series of interoperability rules that press hospitals, payers, and providers toward electronic data exchange and standardized claims attachments. The direction of travel is clear: paper and analog fax workflows are being replaced by digital transmission that carries an auditable record — which is exactly what a cloud fax with delivery confirmation provides for offices not yet on a full EHR pipeline.
CMS →Federal agencies still write fax into new rules and notices
The Federal Register — the daily journal of U.S. federal rulemaking — regularly publishes rules and notices that reference fax as an accepted or required submission channel for filings with agencies like the IRS, SSA, and CMS. That is why fax remains a live requirement for many official forms even as electronic portals expand.
Federal Register →Healthcare breach reporting keeps document handling under scrutiny
Ongoing reporting on HIPAA breaches and OCR settlements underscores how much scrutiny falls on how medical documents are stored, sent, and received. Sending records through a controlled, access-logged channel rather than an unmanaged machine reduces the mishandling risks that show up repeatedly in breach analyses.
HIPAA Journal →
NIST 800-171 Fax Compliance — FAQ
NIST 800-171 is the set of 110 controls for protecting CUI, historically self-attested via a SPRS score. CMMC adds a verification layer — often a third-party assessment — that you meet those controls. Send FAX Mail supports controls under either framework but certifies neither for you.
Its AES-256 encryption, MFA, role-based access, and audit logging map to objectives in the access-control, identification-and-authentication, audit-and-accountability, media-protection, and system-and-communications-protection families for the fax application — a subset of the full 110 controls your assessment must cover.
Only after you confirm scoping. DFARS 252.204-7012 expects CUI in cloud services to sit in a FedRAMP-Moderate-equivalent boundary, and 800-171 expects FIPS-validated crypto modules. Send FAX Mail does not claim a GovCloud/FedRAMP boundary or FIPS-140 module validation, so verify with your assessor before routing CUI.
Its encryption, MFA, access control, and audit logging can support the implementation status of specific controls for the fax application, which factor into your self-assessed SPRS score. The score reflects your entire in-scope environment, so the tool is one input, not the whole picture.
NIST 800-171-compliant faxing starts at $39.99/mo
Encrypted transmission, audit logs, secure storage. No enterprise contract needed.
7-day free trial · No credit card required