Skip to content

Home Topics Email Compliance HIPAA-compliant email

Email Compliance · HIPAA-compliant email

How to set up HIPAA-compliant email: step-by-step guide (2026)

Short answer

To set up HIPAA-compliant email: Sign a BAA with your email provider and any AI or automation vendor touching mailbox content; Enforce TLS and use encryption for messages containing ePHI; Enable audit logging and retention appropriate to your policy. Then train staff on what may and may not go in an email body or subject.

Violations carry significant penalties, and healthcare senders cannot use consumer email tools without a BAA.

How to implement HIPAA-compliant email#

  1. Sign a BAA with your email provider and any AI or automation vendor touching mailbox content.
  2. Enforce TLS and use encryption for messages containing ePHI.
  3. Enable audit logging and retention appropriate to your policy.
  4. Train staff on what may and may not go in an email body or subject.

How to verify it worked#

Send a test message to seed mailboxes at Gmail, Outlook, and Yahoo, then inspect the Authentication-Results and delivery headers. Repeat after any DNS or sending-platform change.

Common mistakes#

  • Putting patient identifiers in subject lines.
  • Using marketing tools for appointment reminders without a BAA.

Frequently asked questions#

Is Gmail HIPAA compliant?

Google Workspace can be, with a signed BAA and proper configuration. Consumer Gmail is not.

Keep reading on HIPAA-compliant email