Violations carry significant penalties, and healthcare senders cannot use consumer email tools without a BAA.
Mistake 1: Putting patient identifiers in subject lines#
Why it hurts: this undermines HIPAA-compliant email at the point where mailbox providers make their decision, and it is rarely surfaced by your own tooling until placement drops.
Fix: Sign a BAA with your email provider and any AI or automation vendor touching mailbox content.
Mistake 2: Using marketing tools for appointment reminders without a BAA#
Why it hurts: this undermines HIPAA-compliant email at the point where mailbox providers make their decision, and it is rarely surfaced by your own tooling until placement drops.
Fix: Enforce TLS and use encryption for messages containing ePHI.
Frequently asked questions#
Is Gmail HIPAA compliant?
Google Workspace can be, with a signed BAA and proper configuration. Consumer Gmail is not.