HIPAA BAA for Email: Who Signs, When, and What Proves It
A front-desk coordinator forwards a referral packet from the practice's shared inbox to an orthopedic group across town. Patient name, DOB, imaging notes. Routine. Nobody thinks twice.
Three weeks later a records request turns adversarial, a lawyer asks who has access to that mailbox, and your privacy officer discovers the practice never signed a HIPAA BAA for email with the company hosting it. That single missing signature turns an ordinary business function into an unauthorized disclosure to a business associate — a documentable, citable finding.
This article is for the person who has to fix that. It covers which email-adjacent vendors require a business associate agreement, which genuinely don't, what to look for in the vendor's paper, and what the file should contain when someone asks you to prove it.
The Conduit Exception Is Narrower Than Your Staff Thinks
The most common misread in a small practice: "email is just a pipe, like the post office, so no BAA needed."
HHS has addressed this directly. The conduit exception applies to entities that transmit protected health information and have only transient access to it — the classic examples are the U.S. Postal Service, couriers, and internet service providers acting purely as transmission channels. It is a narrow exception, and HHS says so explicitly in its guidance on business associates.
Your email host is not a conduit. It stores messages. It indexes them. It keeps backups, runs spam filtering across message bodies, and retains data after deletion for a defined window. That is persistent access to PHI on behalf of a covered entity. It requires a BAA.
The practical test your privacy officer should apply: does the vendor hold the message at rest, even briefly, on infrastructure it controls? If yes, get a BAA. If the vendor genuinely never stores anything — a rare case for anything email-related — document your reasoning in writing and move on.
Do You Need a HIPAA BAA for Email With Google Workspace or Microsoft 365?
Yes — and the BAA is not automatic. Both providers make a HIPAA business associate agreement available to eligible paid business and enterprise customers, but coverage does not attach by default. With Google Workspace, an administrator must review and accept the BAA inside the Admin console, and the agreement covers only the specific services Google designates as "included functionality." With Microsoft 365, the HIPAA BAA terms are incorporated into Microsoft's Product Terms for customers on qualifying volume licensing or online subscription agreements, and coverage likewise extends only to listed services.
Free consumer accounts — a personal Gmail address, an Outlook.com address, a webmail account bundled with your domain registrar — are not covered by any BAA. If a provider or biller is using one for patient communication, that is an active finding, not a future project.
Two things to verify this week, in writing:
- Is the BAA actually executed? Log into the admin console and screenshot the acceptance record with the date and the accepting administrator's name.
- Which services does it cover? Both vendors publish a list. Services outside that list — third-party marketplace add-ons, certain AI features, some collaboration tools — may fall outside the agreement even though they live in the same tenant.
That second point catches practices constantly. The mail service is covered; the note-taking add-on your practice manager installed from the marketplace is not.
The Vendor List You Actually Have to Build
"Email" in a clinic is rarely one vendor. Walk the actual path a message takes and you will usually find four to seven companies touching PHI.
Email hosting and archiving
The mailbox provider, plus any separate archiving or journaling service your IT vendor bolted on for retention. Both need a BAA. Archiving vendors are frequently missed because they were configured once, years ago, by someone who no longer works there.
Encryption gateways and secure-message portals
Any service that intercepts outbound mail, encrypts it, and hosts a pickup portal is storing PHI. BAA required. Ask specifically whether decrypted content is retained for troubleshooting and for how long.
E-fax and fax-to-email services
Inbound faxes converted to PDFs and dropped in a mailbox are among the highest-volume PHI flows in most primary care practices. The e-fax vendor holds those images. BAA required, and check whether the consumer tier of the same product — which many practices signed up for on a credit card — is excluded from the vendor's HIPAA offering.
Web forms, scheduling widgets, and intake tools that email results
If a patient types symptoms into a form on your website and the submission lands in your inbox, the form vendor processed PHI. So did any embedded analytics or chat script on that page. HHS has been public about tracking technologies on pages that collect health information; treat the form platform as a business associate.
Transcription, answering services, and virtual receptionists
These often email summaries or voicemail audio to the practice. They are business associates by any reading.
Marketing and newsletter platforms
A generic wellness newsletter to a purchased list is not PHI. A recall campaign to your diabetic patients is. If the list is derived from your patient records, the platform is handling PHI, and most general-purpose marketing tools will not sign a BAA at all — which is your answer about whether to use them.
When the Vendor Won't Hand You Paper
Large providers publish standardized BAAs and you take them as written. Smaller vendors — the local transcriptionist, the two-person marketing shop that manages your recall emails, the contractor who administers your mail server — often have nothing to offer. They will ask you to send something.
That is where practices stall for months. Don't. The obligation is yours regardless of who drafts the document, and a vendor without a BAA is a vendor you cannot lawfully send PHI to. If you need a clean, signature-ready agreement without waiting on outside counsel for a routine engagement, you can generate a business associate agreement through a six-step wizard and export it as PDF or DOCX for signature — one-time purchase, no subscription. Use it for the vendors who need your paper, and reserve legal review for the genuinely unusual arrangements.
Five Clauses to Read Before You Sign an Email Vendor's BAA
Vendor-drafted BAAs are not neutral. Read for these, and negotiate where you have leverage.
1. Breach notification timing
The regulation gives a business associate up to 60 days to notify you of a breach. Your own 60-day clock to notify patients runs from discovery — and a BA's discovery can be imputed to you. Push for notification within 5 to 10 business days. Many vendors will agree; the ones that won't at least tell you something about how they operate. HHS lays out the underlying obligations in its breach notification rule materials.
2. Subcontractor flow-down
Your email vendor uses cloud infrastructure, spam filtering, and probably an offshore support desk. The BAA must obligate the vendor to bind each subcontractor to equivalent terms. Ask for the list, or at minimum for the vendor's commitment to maintain one.
3. Permitted uses — especially scanning and model training
This clause has become the live issue. Read whether the vendor may use message content for product improvement, machine learning, or advertising. "Aggregated and de-identified" language deserves scrutiny: ask which de-identification method, expert determination or safe harbor. If the contract is silent on AI features, get written confirmation before enabling them.
4. Return or destruction at termination
What happens to twelve years of archived mail when you switch providers? Get the export format, the retention window after termination, and the certificate-of-destruction commitment in writing. Then calendar the verification step for 30 days after your migration.
5. Cooperation with individual access requests
If PHI lives only in the vendor's system, you need a contractual path to retrieve it inside the 30-day access window. Do not assume the export button will be there when you need it.
The Patient Who Asks You to Email Unencrypted
A BAA covers your vendor relationship. It does not resolve the separate question your front desk faces every week: a patient wants their results sent to a regular email address, and the portal is a hassle.
HHS's right of access guidance is clear that individuals may request delivery by unencrypted email. You must warn the patient of the risk, and if they still want it that way, you send it. You are not liable for interception in transit after that warning.
Operationalize it. Build a one-line field in your intake or communication-preference form: "I have been advised of the risks of unencrypted email and request my health information be sent to [address]." Date it, store it in the chart, and re-confirm the address annually. Train staff that the warning is required, the patient's choice is honored, and neither is optional.
What the Evidence File Looks Like
An investigator or an auditor is not persuaded by "we have BAAs with everyone." They want a document set. Build it once and maintain it quarterly.
- A vendor inventory listing every service that stores, transmits, or accesses PHI, with the business owner's name, the data type, and the BAA status.
- The executed BAA itself — countersigned, dated, with the effective date and the covered services identified. For click-through acceptances, a dated screenshot of the admin console record.
- Configuration evidence showing the covered services are the ones actually in use: TLS enforcement settings, retention policy, mailbox audit logging enabled, admin access list.
- A dated review record — who checked the vendor list, when, and what changed.
- Your risk analysis, which should name email as a specific system and document the safeguards applied. This is the item most often missing entirely; if you don't have a current one, the automated HIPAA risk analysis and policy set gets you a defensible baseline faster than a spreadsheet rebuild.
Worth noting: the Security Rule update HHS proposed in January 2025 would, if finalized as written, require business associates to provide written verification of their technical safeguards on a recurring basis. That rule is not final as of today. But the direction is unmistakable — the era of a signed BAA sitting in a drawer as sufficient proof is closing. Practices that already collect configuration evidence alongside signatures will have less work when the requirement lands.
A 90-Minute Version of This Project
- Minutes 0–20: List every email-related vendor. Pull the last 12 months of card statements and AP records — that finds the ones nobody remembers.
- Minutes 20–40: Mark each as BAA on file / BAA needed / no PHI. Be honest about the gray ones.
- Minutes 40–60: Verify the two or three largest. Log into the admin console. Screenshot the BAA acceptance and the covered-services list.
- Minutes 60–80: Send BAA requests to every vendor in the "needed" column, with a 15-business-day response deadline and a named internal owner.
- Minutes 80–90: Calendar the follow-up, and calendar a quarterly review of the inventory itself.
Anything still unsigned after 30 days becomes a decision, not a to-do: either the vendor signs, or PHI stops flowing to them. Document which one you chose.
Close the Gap This Week
The missing BAA is one of the cheapest findings to fix before an incident and one of the most expensive to explain afterward — the OCR breach portal is full of email-related incidents at practices that never mapped their vendors. Start with the inventory, verify your mailbox provider's agreement is actually executed, and get signature-ready paper in front of the smaller vendors who have none. If you need that document today, build a business associate agreement and export it for signature — then file it with the configuration evidence that proves it means something.