HIPAA Compliant Email Providers

HIPAA compliant email providers are email service vendors that will sign a Business Associate Agreement and provide administrative, technical, and physical capabilities that support compliance with the HIPAA Privacy Rule and HIPAA Security Rule when protected health information is sent, received, or stored in email.

HIPAA Email Requirements

Email that contains protected health information must be protected with safeguards that preserve confidentiality, integrity, and availability. Safeguards include access controls, audit controls, and security measures for protected health information at rest and in transit. Controls also address improper modification and improper disposal of protected health information in messages and attachments.

Anti spam and anti phishing controls support workforce protection against credential theft and malicious content that can lead to unauthorized access to protected health information.

Business Associate Agreement And Service Scope

An email platform supports HIPAA compliance only when the vendor will sign a Business Associate Agreement and the email related services used for protected health information are included within the agreement scope. The agreement does not replace organizational responsibilities for configuration, monitoring, and workforce oversight.

Organizations should confirm whether the agreement covers storage locations and adjacent services that process email content, including archiving, journaling, mobile device access, and any web portals used to read encrypted messages.

Encryption And Transmission Controls

Email safeguards address protected health information in transit and at rest. Transport encryption protects the connection between mail servers. Content encryption protects the body and attachments of the email itself.

Transport based encryption can fail when a recipient system does not support the negotiated protocol or when configuration permits downgrade paths. Content encryption methods such as S MIME introduce operational overhead for certificate management and can limit functions that depend on scanning message content.

Access Controls And Audit Controls

HIPAA compliant email configurations require unique user authentication, role aligned access provisioning, and automatic session termination controls. Audit controls support tracking of access and changes to messages and mailboxes, including modification and deletion actions.

Event logging and mailbox activity reporting support security incident review and support investigations of suspected impermissible disclosures.

Archiving And Retention Considerations

Email retention and archiving affect compliance operations. Immutable or write once archiving models support preservation of message history when required for internal investigations, patient access requests, and accounting of disclosures workflows. Retention settings should align with organizational record retention practices and legal hold processes when applicable.

Provider Models Used For HIPAA Compliant Email

Some providers deliver a full email environment with built in encryption and compliance controls. Others provide an encryption layer or gateway that operates alongside an existing email service. Gateway models can reduce disruption for organizations that want to keep an established email platform while adding encryption and policy controls.

Secure portal delivery is used by some vendors for messages sent to recipients outside the protected domain. Portal workflows add friction for recipients and require controls for identity verification and access expiration.

Examples Of HIPAA Compliant Email Providers

Microsoft and Google can support HIPAA compliant email when an organization uses a qualifying Microsoft Office 365 subscription or enterprise Google Workspace subscription and signs the applicable Business Associate Agreement. Email security behavior depends on administrative configuration and on interoperability with external recipient systems.

LuxSci offers hosted email and encryption capabilities designed for regulated healthcare communications, including options for encrypting outbound messages and controlling message handling.

Paubox offers encryption services that can be deployed as a standalone email environment or alongside an existing email service, with encryption designed to operate without separate user actions for routine protected health information messages.

Proton Mail provides encrypted email, with different handling when sending messages to recipients outside the same encrypted ecosystem, including password protected workflows.

Hushmail provides encrypted email with automatic encryption between Hushmail users and a portal based option for sending encrypted messages to non Hushmail recipients.

MailHippo provides encrypted email with a portal delivery method and limited integration options relative to broader productivity suites.

Aspida Mail provides a web based email approach with encryption triggers that depend on user actions within the message composition process.

Implementation Controls Required Within The Organization

A HIPAA Covered Entity or Business Associate remains responsible for system configuration and ongoing monitoring. Administrative controls should address account provisioning, termination of access, authentication requirements, remote access governance, and mobile device controls for any device that can access protected health information through email.

Security incident procedures should include response steps for misdirected emails, compromised accounts, unauthorized mailbox access, and improper disclosures through attachments or forwarding.

The HIPAA Minimum Necessary Rule applies to uses, disclosures, and requests for protected health information when the rule applies. Email practices should limit identifiers and attachments to the minimum necessary to accomplish the intended purpose.

Daniel Lopez

Daniel Lopez is the HIPAA expert behind HIPAA Coach. Daniel has over 10 years experience as a HIPAA trainer and has developed deep experience in teaching HIPAA to healthcare professionals. Daniel has contributed to numerous publications including expert articles on The HIPAA Guide. Daniel is currently a staff writer on HIPAA at the Healthcare IT Journal. Daniel was a subject matter expert for ComplianceJunction's online HIPAA training. Daniel's academic background in Health Information Management is the foundation of his HIPAA expertise. Daniel's primary professional interest is protecting patient privacy, which he believes is the core of the HIPAA regulations and the best route to HIPAA compliance. You can reach Daniel on the contact page of HIPAA Coach and follow him on Twitter https://twitter.com/DanielLHIPAA