This guide assumes HIPAA-compliant email is already deployed and passing. It covers what breaks at scale and how mature teams operate it.
Edge cases that break a working setup#
- Putting patient identifiers in subject lines.
- Using marketing tools for appointment reminders without a BAA.
- Mail forwarded through mailing lists or personal forwarders, which alters headers and content.
- Acquisitions and rebrands that introduce domains nobody audited.
- Vendors silently changing their sending infrastructure.
Operating it as infrastructure#
- Assign an owner for each sending domain and each vendor relationship.
- Put DNS records under version control or a change-review process.
- Alert on authentication pass rate drops and reputation changes, not just outages.
- Run a quarterly audit against the setup steps below.
- Document runbooks for the three most common failures.
Reference: the baseline setup#
- Sign a BAA with your email provider and any AI or automation vendor touching mailbox content.
- Enforce TLS and use encryption for messages containing ePHI.
- Enable audit logging and retention appropriate to your policy.
- Train staff on what may and may not go in an email body or subject.
Frequently asked questions#
Is Gmail HIPAA compliant?
Google Workspace can be, with a signed BAA and proper configuration. Consumer Gmail is not.