At 4:47 on a Friday, your front-desk coordinator forwards a referral packet — imaging report, insurance card scan, and a two-line note about the patient's symptoms — to a specialist's office at a free consumer email address. She used your practice's regular Outlook account. No encryption prompt appeared. Nothing broke. The referral went through.

That is the transaction most practices get wrong, and it is why you're reading this. HIPAA compliant email is not a product you buy and switch on. It's a stack of four things: an encrypted transport path, a signed Business Associate Agreement with whoever runs your mail servers, a documented configuration, and a workflow your staff actually follows. This piece covers who owns each piece, what evidence you need on file, and where the common failure points sit.

What Makes Email HIPAA Compliant? The Short Answer

Email carrying protected health information is HIPAA compliant when all five of the following are true:

  1. The email provider has signed a Business Associate Agreement with your practice, because it stores and transmits PHI on your behalf.
  2. Messages are encrypted in transit and at rest, or you have documented in your risk analysis why an equivalent alternative safeguard is reasonable.
  3. Access is controlled — unique user IDs, multi-factor authentication, and automatic logoff on shared workstations.
  4. Activity is logged and reviewable, so you can reconstruct who sent what to whom during an investigation.
  5. Staff are trained on when email is appropriate, and the practice has a written policy defining minimum necessary content for email.

Missing any one of those and you don't have HIPAA compliant email — you have email that happens to be encrypted. Those are different things when the Office for Civil Rights asks for documentation.

The Encryption Rule Everyone Misreads

Encryption under the Security Rule at 45 CFR 164.312(e) is an addressable implementation specification, not a required one. Practice owners hear "addressable" and conclude "optional." It isn't.

Addressable means you must assess whether the safeguard is reasonable and appropriate for your environment. If it is, you implement it. If it isn't, you document why and implement an equivalent alternative measure. What you cannot do is skip the analysis and leave the field blank. A blank field is the finding.

For email in 2025, there is essentially no defensible argument that encryption is unreasonable. TLS is free, standard, and supported by every major provider. NIST's SP 800-52 Rev. 2 guidelines for TLS implementations gives you the configuration baseline your IT vendor should be meeting — TLS 1.2 minimum, 1.3 preferred, with weak cipher suites disabled.

Worth noting: HHS published a proposed overhaul of the Security Rule in January 2025 that would move encryption from addressable to required, along with mandatory multi-factor authentication and asset inventories. It has not been finalized as of this writing. Practices that treat encryption as mandatory today will have nothing to change if and when it lands.

TLS Opportunistic vs. Enforced — The Distinction That Bites

Standard TLS on most mail platforms is opportunistic. If the receiving server supports encryption, the message is encrypted. If it doesn't, the message goes anyway — in plaintext. Your staff sees no difference.

Ask your IT administrator one question: are outbound connectors configured to enforce TLS, or to attempt it? Enforced TLS means the message bounces rather than transmitting in the clear. That bounce is a feature. It's also the reason you need a documented secondary channel — a portal, a secure file transfer, or a fax — for recipients whose mail servers are stuck in 2009.

Your Email Provider Is a Business Associate — Get the BAA Signed

The conduit exception is narrow. It covers entities that transmit PHI without storing it in any meaningful way — think the postal service or a telecom carrier moving packets. An email platform that holds your mailboxes, indexes your messages, and retains them for years is storing PHI. That's a business associate relationship, full stop.

Both major enterprise email platforms will sign a BAA, but usually only on specific paid tiers and often only after an administrator affirmatively accepts the terms in the admin console. Consumer-grade free accounts are not covered. If your practice manager is running scheduling out of a personal free-tier inbox, you have an unaddressed business associate gap and a likely breach exposure sitting in the same place.

The BAA obligation extends past the mail platform. Walk your actual data path:

  • Email hosting provider
  • Spam and malware filtering gateway (it inspects message bodies)
  • Email archiving or e-discovery vendor
  • Encrypted-message portal, if you use one
  • Any marketing or appointment-reminder tool that pulls from your patient list
  • The managed IT firm with domain admin credentials

Every one of those needs a signed agreement on file with specific breach notification timelines and subcontractor flow-down language. If you're staring at that list realizing three of them never got papered, you can generate a signature-ready Business Associate Agreement through a six-step wizard and export it as PDF or DOCX the same afternoon. One-time purchase, no subscription — useful when you need four agreements this week and none next month.

Date the Agreements, Then Calendar Them

An undated BAA is worth very little in an investigation. Your file needs: the executed agreement, the effective date, the countersignature, and a review date. Set an annual calendar reminder to confirm each vendor still exists, still holds the same scope, and hasn't been acquired by someone who never agreed to your terms.

Patients Can Ask You to Email Them Unencrypted — And You Must Comply

This is the piece that confuses privacy officers most, because it looks like it contradicts everything above.

Under the right of access at 45 CFR 164.524, a patient may request their records in the form and format they prefer, including unencrypted email. HHS has been explicit that you cannot refuse. OCR's guidance on email and PHI confirms that providers may communicate by email with patients who request it, provided reasonable safeguards are applied.

What you owe the patient is a light warning — a plain-language statement that unencrypted email carries a risk of interception, and confirmation that they still want it that way. What you owe yourself is documentation of that exchange.

Build it into your intake and records-request forms as a checkbox with a signature line: "I request that my records be sent to the email address below. I understand this method is not encrypted and carries a risk of unauthorized access." Scan it into the chart. That single artifact converts a potential breach into a documented patient choice.

Two guardrails: the warning must be given before you send, not after, and it applies to the patient's own records going to the patient. It does not authorize you to email a referral packet to another provider's insecure inbox. See the HHS right of access guidance for the full boundary.

The Five Settings Your IT Vendor Should Confirm in Writing

Send this list to whoever administers your tenant and ask for a screenshot or export of each. Put the responses in your compliance binder with a date.

  1. Enforced TLS on outbound connectors for domains you exchange PHI with regularly — referral partners, labs, billing companies.
  2. Multi-factor authentication on 100% of accounts, including the shared front-desk mailbox and every service account. Credential theft through phishing remains the single most common entry point in reported healthcare breaches.
  3. Auto-forwarding to external domains disabled at the tenant level. Attackers who compromise a mailbox routinely set a silent forwarding rule; this one setting shuts down months of undetected exfiltration.
  4. Audit logging enabled with a defined retention period — long enough to investigate an incident discovered six months late. Mailbox audit logging is off by default in more configurations than administrators expect.
  5. A data loss prevention rule that flags outbound messages containing SSN patterns, MRN formats, or large attachment volumes to external recipients.

A Worked Example: The Friday Referral, Done Correctly

Same scenario, corrected workflow:

Your coordinator opens the referral template. The template's first field is the recipient's organizational email domain, not a personal address — because your policy says PHI goes to practice domains only, and your DLP rule blocks the consumer domains outright.

She attaches the imaging report and types only what the specialist needs to triage: name, DOB, reason for referral, and the ordering provider. Minimum necessary applies to email exactly as it applies to a fax cover sheet. The full chart narrative stays in the record.

The message hits your outbound connector. The specialist's domain is on your enforced-TLS list because you added it after the last quarterly vendor review. It transmits encrypted. The event lands in your audit log with sender, recipient, timestamp, and attachment name.

If the specialist's server had rejected TLS, the message would have bounced with a clear NDR, and your coordinator would have used the documented fallback — the secure portal link, or a phone call to get a working address. Ninety seconds of friction, zero reportable events.

When Email Becomes a Breach: The 60-Day Clock

An email sent to the wrong recipient containing unsecured PHI is a presumed breach. You have four factors to assess under the risk-of-compromise analysis, and you must document the assessment whether or not you conclude notification is required.

If notification is required, individuals must be notified without unreasonable delay and no later than 60 calendar days from discovery. Breaches affecting 500 or more individuals also require notice to HHS and prominent media within that same 60 days. Smaller incidents go on your annual log, submitted within 60 days of the end of the calendar year. The OCR breach reporting portal is where those filings land, and the public list of reported incidents is instructive reading for anyone building an email policy — email-related and network-server incidents dominate it.

Discovery starts when any workforce member knows, or reasonably should have known. Your coordinator noticing the typo at 4:48 starts the clock — not the Monday morning when she tells her supervisor. Train to that.

The Evidence File Your Privacy Officer Should Be Able to Produce

If an investigator asked tomorrow, could you hand over these six items in under an hour?

  • Signed, dated BAA with your email provider and every downstream vendor touching mail
  • Written email policy specifying approved platforms, minimum necessary content, and prohibited uses
  • Risk analysis entry addressing email transmission, with the encryption decision documented
  • Configuration evidence — TLS enforcement, MFA coverage, forwarding restrictions, audit log settings
  • Training records showing staff completed email-specific instruction, with dates and signatures
  • Patient consent forms for any unencrypted communication you've agreed to

Practices that maintain those six artifacts have HIPAA compliant email. Practices that only bought an encryption add-on have a partial answer to one of six questions. If your risk analysis and policy set are the gap, tools that automate HIPAA risk analysis reports and the supporting policy documents will get you to a defensible baseline faster than rebuilding templates from scratch.

Start With the Vendor Gap

Configuration takes an IT ticket. Training takes a staff meeting. The item that takes longest — and that most often turns up missing during an incident — is the signed agreement with the vendor whose servers hold your mail.

Pull your vendor list this week, identify every party that touches email carrying PHI, and check which ones have a current, dated BAA in the file. For the gaps, build and export a signature-ready agreement and get it in front of the vendor before your next quarterly review. It's the cheapest hour of compliance work on your list, and the one an investigator asks about first.