> What's the attack surface of an email vs fax?

I believe the primary concern has been while the message is in transit, unencrypted routing over the internet vs. unencrypted over the phone line.

Additionally the storage of email was cited as a concern, making mass data breaches much simpler.

Note that there is a HIPAA approved email service called Direct, as in Direct Messaging / Direct Exchange / Direct Connect.