Skip to content

Home Topics Email Compliance HIPAA-compliant email

Email Compliance · HIPAA-compliant email

What is HIPAA-compliant email? Definition, how it works, and why it matters

Short answer

HIPAA-compliant email protects electronic protected health information (ePHI) in transit and at rest, with access controls, audit logs, and a Business Associate Agreement (BAA) with any vendor that handles the mail.

What HIPAA-compliant email is#

HIPAA-compliant email protects electronic protected health information (ePHI) in transit and at rest, with access controls, audit logs, and a Business Associate Agreement (BAA) with any vendor that handles the mail.

Why it matters#

Violations carry significant penalties, and healthcare senders cannot use consumer email tools without a BAA.

Getting started#

  1. Sign a BAA with your email provider and any AI or automation vendor touching mailbox content.
  2. Enforce TLS and use encryption for messages containing ePHI.
  3. Enable audit logging and retention appropriate to your policy.
  4. Train staff on what may and may not go in an email body or subject.

Common mistakes#

  • Putting patient identifiers in subject lines.
  • Using marketing tools for appointment reminders without a BAA.

Frequently asked questions#

Is Gmail HIPAA compliant?

Google Workspace can be, with a signed BAA and proper configuration. Consumer Gmail is not.

Keep reading on HIPAA-compliant email