HIPAA Compliant Email: Requirements, Solutions, and Best Practices
Quick answer: Email is not “HIPAA compliant” or “non-compliant” as a product — compliance comes from how you configure and govern it. To send protected health information (PHI) by email lawfully you generally need encryption in transit and at rest, access controls and audit logging, a signed Business Associate Agreement (BAA) with the email provider, and workforce training on what may be sent and to whom. The brand on the inbox matters far less than the configuration behind it.
Why standard email is the problem
Ordinary email crosses multiple servers in plain text and is retained on devices and backups you do not control. That is why the question is rarely “is Gmail HIPAA compliant?” and almost always “did we sign a BAA and turn on the right controls?” Consumer tiers — a personal @gmail.com or @outlook.com account — will not sign a BAA, which alone disqualifies them for PHI. The business and enterprise tiers (Google Workspace, Microsoft 365) will sign a BAA and expose the encryption, access, and logging settings you need. Signing the agreement is necessary but not sufficient; the BAA is the floor, and our guide to Business Associate Agreements explains what the document does and does not cover.
The technical requirements that actually matter
Four controls do most of the work. Encryption protects messages in transit (TLS, ideally enforced rather than opportunistic) and at rest on the mail server. Access controls ensure only authorized workforce members reach the mailbox — unique logins, multi-factor authentication, and no shared “frontdesk@” credentials for PHI. Audit logging records who accessed or sent what, which is what you produce after an incident. And minimum necessary discipline keeps PHI out of subject lines and limits what is included in the body. For routine patient communication, many practices use a secure messaging portal instead of open email; the same logic applies to texting, which we cover in HIPAA compliance and text messaging.
The patient-initiated email exception
A point that surprises many practices: a patient may ask to receive communications by ordinary, unencrypted email. Under the right to request confidential communications, you may honor that request after advising the patient of the risk, and you are not liable for the lack of encryption on messages they asked to receive that way. You are still responsible for safeguarding the copy that lives on your systems, and the exception does not extend to emailing other providers or vendors — only to the patient who made the request. Document the request and the warning you gave.
Where email fits in your Security Risk Analysis
Email is one of the most common channels for an accidental disclosure, so it belongs squarely inside your Security Risk Analysis. The Security Rule requires that analysis under 45 CFR § 164.308(a)(1)(ii)(A) — an accurate and thorough assessment of risks to all electronic PHI. A good analysis inventories which mailboxes touch PHI, confirms a BAA is in place with the provider, verifies encryption and MFA settings, and checks that mis-sent-email procedures and audit-log review actually exist. Misdirected email — the right message to the wrong recipient — is a leading cause of reportable breaches, and only the risk analysis surfaces it before OCR does.
The proposed 2026 Security Rule update
In December 2024, the HHS Office for Civil Rights published a Notice of Proposed Rulemaking (NPRM) that would modernize the Security Rule. It is a proposal, not final law, and nothing in it is enforceable today. If finalized as written, several measures that are currently “addressable” — notably encryption and multi-factor authentication — would become effectively mandatory, which maps directly onto how PHI-bearing email should already be configured. Organizations would have roughly a 240-day compliance window after a final rule publishes. Practices that already enforce TLS, MFA, and audit logging on their mail would have little new to do.
How Medcurity helps
Medcurity’s guided Security Risk Analysis helps you document your email environment the way an auditor reads it: which providers hold PHI, whether BAAs are signed, what encryption and access controls are enforced, and where the gaps are — with remediation tracking and audit-ready evidence instead of a stale spreadsheet. Pricing is $499/year (about $42/month) for a single organization; larger or multi-location organizations can request a quote. The result is a clear, defensible answer to “is our email handling of PHI compliant, and can we prove it?”
Frequently Asked Questions
Is Gmail HIPAA compliant?
A personal Gmail account is not, because Google will not sign a Business Associate Agreement for consumer accounts. Google Workspace business and enterprise tiers can be used compliantly because Google will sign a BAA and you can enforce encryption, multi-factor authentication, and audit logging. Compliance depends on the tier and configuration, not the Gmail brand.
Do I need a BAA to use email for PHI?
Yes. The email provider stores and transmits PHI on your behalf, which makes them a business associate. You need a signed Business Associate Agreement before sending PHI through the service, in addition to enabling the technical safeguards.
Can I email a patient who asks me to use regular email?
Yes. Under the right to request confidential communications, you may send PHI by unencrypted email if the patient requests it and you have warned them of the risk. You are not liable for the lack of encryption on messages they asked to receive that way, but you must still protect the copies on your own systems and should document the request.
Is it enough to just turn on encryption?
No. Encryption is one of four pillars. You also need access controls and unique logins, audit logging, a signed BAA with the provider, and workforce training on what may be sent. Encryption protects the message in transit but does nothing about a message sent to the wrong recipient.