Skip to content

Home Topics Email Compliance HIPAA-compliant email

Email Compliance · HIPAA-compliant email

HIPAA-compliant email examples: what good and bad look like

Short answer

A good HIPAA-compliant email implementation follows these steps: Sign a BAA with your email provider and any AI or automation vendor touching mailbox content; Enforce TLS and use encryption for messages containing ePHI. A bad one typically putting patient identifiers in subject lines.

HIPAA-compliant email protects electronic protected health information (ePHI) in transit and at rest, with access controls, audit logs, and a Business Associate Agreement (BAA) with any vendor that handles the mail.

What good looks like#

  • Done: Sign a BAA with your email provider and any AI or automation vendor touching mailbox content.
  • Done: Enforce TLS and use encryption for messages containing ePHI.
  • Done: Enable audit logging and retention appropriate to your policy.
  • Done: Train staff on what may and may not go in an email body or subject.

What bad looks like#

  • Seen in audits: Putting patient identifiers in subject lines.
  • Seen in audits: Using marketing tools for appointment reminders without a BAA.

How to move from bad to good#

Work through the good list in order and re-verify after each change. Most teams find one or two items from the bad list already present; fixing those usually produces the largest improvement.

Frequently asked questions#

Is Gmail HIPAA compliant?

Google Workspace can be, with a signed BAA and proper configuration. Consumer Gmail is not.

Keep reading on HIPAA-compliant email