Skip to content

Home Topics Email Compliance HIPAA-compliant email

Email Compliance · HIPAA-compliant email

HIPAA-compliant email glossary: key terms explained

Short answer

HIPAA-compliant email: HIPAA-compliant email protects electronic protected health information (ePHI) in transit and at rest, with access controls, audit logs, and a Business Associate Agreement (BAA) with any vendor that handles the mail.

Terms below appear throughout guides on HIPAA-compliant email. Each definition is one or two sentences; follow the links in the sidebar for the full guides.

Core terms#

HIPAA-compliant email

HIPAA-compliant email protects electronic protected health information (ePHI) in transit and at rest, with access controls, audit logs, and a Business Associate Agreement (BAA) with any vendor that handles the mail.

SPF

A DNS record listing servers authorized to send for a domain. Checked against the connecting IP.

DKIM

A cryptographic signature on each message, verified with a public key in DNS.

DMARC

A policy record telling receivers what to do when SPF and DKIM fail alignment, plus reporting.

Alignment

Agreement between the visible From domain and the domain that passed SPF or DKIM.

Sender reputation

A provider's running assessment of a domain or IP based on complaints, bounces, engagement, and authentication.

Inbox placement

Share of accepted mail that lands in the inbox rather than spam.

Spam trap

An address that never opted in, used to catch senders with poor list practices.

BIMI

A DNS record pointing to a brand logo displayed next to authenticated mail; requires DMARC enforcement.

Feedback loop

A provider program that reports recipient spam complaints back to the sender.

Frequently asked questions#

Is Gmail HIPAA compliant?

Google Workspace can be, with a signed BAA and proper configuration. Consumer Gmail is not.

Keep reading on HIPAA-compliant email