Skip to content

Home Topics Email Compliance HIPAA-compliant email

Email Compliance · HIPAA-compliant email

HIPAA-compliant email checklist for 2026

Short answer

A complete HIPAA-compliant email checklist has 4 setup items and 2 things to audit against. Work through setup in order, then schedule a quarterly review.

Setup checklist#

  • ☐ Sign a BAA with your email provider and any AI or automation vendor touching mailbox content.
  • ☐ Enforce TLS and use encryption for messages containing ePHI.
  • ☐ Enable audit logging and retention appropriate to your policy.
  • ☐ Train staff on what may and may not go in an email body or subject.

Audit checklist#

  • ☐ Confirm you are not: putting patient identifiers in subject lines.
  • ☐ Confirm you are not: using marketing tools for appointment reminders without a BAA.

Ongoing monitoring#

  • ☐ Weekly: review provider dashboards (Postmaster Tools, SNDS) and bounce logs
  • ☐ Monthly: re-run the setup verification after any vendor or DNS change
  • ☐ Quarterly: full audit against this checklist

Frequently asked questions#

Is Gmail HIPAA compliant?

Google Workspace can be, with a signed BAA and proper configuration. Consumer Gmail is not.

Keep reading on HIPAA-compliant email