What HIPAA-compliant email is#
HIPAA-compliant email protects electronic protected health information (ePHI) in transit and at rest, with access controls, audit logs, and a Business Associate Agreement (BAA) with any vendor that handles the mail.
Why it matters#
Violations carry significant penalties, and healthcare senders cannot use consumer email tools without a BAA.
What Amazon SES handles#
Most platforms, including Amazon SES, generate the records or settings you need under a domain authentication or sending settings page, and expose bounce and complaint data in reports. Confirm the exact location in Amazon SES's current documentation.
What you still own#
- Sign a BAA with your email provider and any AI or automation vendor touching mailbox content.
- Enforce TLS and use encryption for messages containing ePHI.
- Enable audit logging and retention appropriate to your policy.
- Train staff on what may and may not go in an email body or subject.
Common mistakes#
- Putting patient identifiers in subject lines.
- Using marketing tools for appointment reminders without a BAA.
Frequently asked questions#
Is Gmail HIPAA compliant?
Google Workspace can be, with a signed BAA and proper configuration. Consumer Gmail is not.
Does Amazon SES set up HIPAA-compliant email automatically?
Amazon SES provides the values and some checks, but publishing DNS, aligning domains, and monitoring results remain your responsibility.