HIPAA-compliant email protects electronic protected health information (ePHI) in transit and at rest, with access controls, audit logs, and a Business Associate Agreement (BAA) with any vendor that handles the mail.
What good looks like#
- Done: Sign a BAA with your email provider and any AI or automation vendor touching mailbox content.
- Done: Enforce TLS and use encryption for messages containing ePHI.
- Done: Enable audit logging and retention appropriate to your policy.
- Done: Train staff on what may and may not go in an email body or subject.
What bad looks like#
- Seen in audits: Putting patient identifiers in subject lines.
- Seen in audits: Using marketing tools for appointment reminders without a BAA.
How to move from bad to good#
Work through the good list in order and re-verify after each change. Most teams find one or two items from the bad list already present; fixing those usually produces the largest improvement.
Frequently asked questions#
Is Gmail HIPAA compliant?
Google Workspace can be, with a signed BAA and proper configuration. Consumer Gmail is not.