Violations carry significant penalties, and healthcare senders cannot use consumer email tools without a BAA.
How to implement HIPAA-compliant email#
- Sign a BAA with your email provider and any AI or automation vendor touching mailbox content.
- Enforce TLS and use encryption for messages containing ePHI.
- Enable audit logging and retention appropriate to your policy.
- Train staff on what may and may not go in an email body or subject.
How to verify it worked#
Send a test message to seed mailboxes at Gmail, Outlook, and Yahoo, then inspect the Authentication-Results and delivery headers. Repeat after any DNS or sending-platform change.
Common mistakes#
- Putting patient identifiers in subject lines.
- Using marketing tools for appointment reminders without a BAA.
Frequently asked questions#
Is Gmail HIPAA compliant?
Google Workspace can be, with a signed BAA and proper configuration. Consumer Gmail is not.