Setup checklist#
- ☐ Sign a BAA with your email provider and any AI or automation vendor touching mailbox content.
- ☐ Enforce TLS and use encryption for messages containing ePHI.
- ☐ Enable audit logging and retention appropriate to your policy.
- ☐ Train staff on what may and may not go in an email body or subject.
Audit checklist#
- ☐ Confirm you are not: putting patient identifiers in subject lines.
- ☐ Confirm you are not: using marketing tools for appointment reminders without a BAA.
Ongoing monitoring#
- ☐ Weekly: review provider dashboards (Postmaster Tools, SNDS) and bounce logs
- ☐ Monthly: re-run the setup verification after any vendor or DNS change
- ☐ Quarterly: full audit against this checklist
Frequently asked questions#
Is Gmail HIPAA compliant?
Google Workspace can be, with a signed BAA and proper configuration. Consumer Gmail is not.