HIPAA-compliant email means an email setup that meets the HIPAA Security Rule’s requirements for electronic protected health information (PHI, the patient information a practice creates, receives or stores) and is covered by a business associate agreement (BAA) with every vendor that stores or handles the PHI. Audit controls are required, encryption is addressable (the practice must assess it and document its decision), and encrypted PHI that is lost or stolen does not trigger breach notification. The questions below are the ones small and specialty practices ask most.
Can a practice send PHI by email under HIPAA?
Yes. HHS states that “the Security Rule does not expressly prohibit the use of email for sending e-PHI.” A practice must still protect PHI in transit and at rest, which means assessing the risks of email in its risk analysis, choosing safeguards such as encryption, documenting that decision, and signing a BAA with its email vendor.
The HHS answer directs practices to assess transmission risks, identify protective measures, select a solution and document the decision. The Security Rule’s risk analysis requirement, 164.308(a)(1)(ii)(A), is where that assessment lives. It is required and calls for “an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information.”
What makes email HIPAA compliant?
Email is HIPAA compliant when the practice’s setup meets the Security Rule for the PHI it carries. That includes required audit controls, unique user IDs, a risk analysis that addresses email, a documented decision on encryption, activity review, workforce training and a BAA with each vendor. No product achieves this alone; the practice’s policies complete it.
| Requirement | Citation | Required/addressable | How PreVeil supports it |
|---|---|---|---|
| Risk analysis | 164.308(a)(1)(ii)(A) | Required | Practice responsibility; PreVeil’s controls are inputs to it |
| Information system activity review | 164.308(a)(1)(ii)(D) | Required | System logs give the security official a record to review |
| Business associate contracts | 164.308(b)(1), (b)(3) | Written contract required | PreVeil signs a BAA |
| Unique user identification | 164.312(a)(2)(i) | Required | Individual accounts with keys generated on each user’s devices |
| Encryption of stored ePHI | 164.312(a)(2)(iv) | Addressable | Message contents, attachments and Drive files encrypted end to end |
| Audit controls | 164.312(b) | Required | Admin console and system logs on the Business plan |
| Transmission encryption | 164.312(e)(2)(ii) | Addressable | Encrypted on the sender’s device, still encrypted in the recipient’s mailbox |
| Documentation retention | 164.316(b)(2)(i) | Required | Practice keeps its policies and decisions for 6 years |
Does HIPAA require email encryption?
Under HIPAA, email encryption is addressable, not required. Sections 164.312(a)(2)(iv) and 164.312(e)(2)(ii) let a practice assess whether encryption is reasonable and appropriate, and if it decides not to encrypt, it must document why and adopt an equivalent alternative (164.306(d)(3)). For PHI sent outside the practice, that alternative is hard to justify.
Encryption also changes what happens after an incident. Section 164.402 defines unsecured PHI as PHI not rendered “unusable, unreadable, or indecipherable to unauthorized persons” by a method in HHS guidance, and encryption is one of those methods. The HIPAA encryption requirements guide covers the full required-versus-addressable picture.
Does an email vendor need to sign a BAA?
Yes, an email vendor must sign a BAA if it creates, receives, maintains or transmits PHI for the practice. HHS guidance says a cloud provider that stores electronic PHI is a business associate “even if it does not hold a decryption key and therefore cannot view the information.” The conduit exception covers only transmission-only services with transient access, not a service that stores mail.
That means an encrypted email vendor is still a business associate, and the practice must obtain “satisfactory assurances” through a written contract under 164.308(b)(1). PreVeil signs a BAA with customers that need to protect PHI.
What must a BAA with an email vendor include?
Under 164.504(e)(2), a BAA must set the vendor’s permitted uses and disclosures, bar other uses, require safeguards and compliance with the Security Rule for electronic PHI, require reporting of breaches of unsecured PHI, flow the same terms to subcontractors, and require return or destruction of PHI at termination. Section 164.314(a)(2)(i) adds security-incident reporting.

HHS publishes sample BAA provisions a practice can compare against a vendor’s paper, including that the business associate will “use appropriate safeguards, and comply with Subpart C of 45 CFR Part 164 with respect to electronic protected health information.”
The BAA does not transfer the practice’s own obligations. A vendor that cannot read PHI has less PHI it can expose, but the practice still decides which vendors to use and keeps its own vendor oversight under 164.308(b).
Is TLS enough for HIPAA-compliant email?
Whether TLS alone is enough for HIPAA-compliant email is a risk analysis decision for the practice. TLS encrypts a message while it travels between mail servers, which addresses transmission, but it does not keep the message encrypted once it reaches each mailbox. End-to-end encryption keeps message contents and attachments encrypted in the inbox too, which bears on whether PHI in a compromised mailbox is unsecured.
This is the difference PreVeil is built around: message contents and attachments are encrypted on the sender’s device and stay encrypted in transit and at rest in both mailboxes. PreVeil can never access or decrypt the practice’s email, because the encryption keys stay on users’ devices.
What happens if a staff mailbox is compromised?
If a compromised staff mailbox holds unsecured PHI, the practice must presume a breach unless a four-factor risk assessment under 164.402 shows a low probability that PHI was compromised, then notify affected individuals within 60 calendar days of discovery (164.404(b)). If the PHI was encrypted consistent with HHS guidance, notification is not required.
The four factors are the nature and extent of the PHI involved, the unauthorized person who used or received it, whether it was actually acquired or viewed, and the extent to which the risk was mitigated. Breaches of 500 or more individuals are also reported to HHS at the same time as individual notices (164.408(b)).
Email was the breach location in about a quarter of the 710 healthcare breaches reported to the HHS Office for Civil Rights in 2025.
Do outside recipients need special software to read encrypted email?
With PreVeil, other providers, payers and business associates read and reply for free from their browser, and their replies stay encrypted end to end. PreVeil works inside your team’s Outlook, Gmail and Apple Mail. You can message external recipients for free.
How do behavioral health and substance use treatment programs handle email?
Programs covered by 42 CFR Part 2 follow the HIPAA breach notification rules for “breaches of unsecured records” under 42 CFR 2.16(b), so encryption carries the same safe harbor. Part 2 does not require encryption. It requires formal security policies, a notice with each disclosure made with consent (2.32), and limits on redisclosure (2.33).
The post on 42 CFR Part 2 and HIPAA covers what has to travel with a Part 2 record sent by email.
Frequently asked questions
Is it a HIPAA violation to email PHI?
No. HHS says the Security Rule does not expressly prohibit sending electronic PHI by email. The practice must assess the risks, apply reasonable safeguards and document its decisions.
Does a practice need a BAA with its email provider?
Yes, if the provider stores or transmits PHI on the practice’s behalf. HHS treats a cloud provider that stores electronic PHI as a business associate even if it cannot view the data. PreVeil signs a BAA.
Is encryption required for HIPAA-compliant email?
No. Encryption is addressable under 164.312(a)(2)(iv) and 164.312(e)(2)(ii). A practice must assess it and document its decision, and properly encrypted PHI does not trigger breach notification if it is lost or stolen.
Are audit logs required for email under HIPAA?
Yes. Audit controls under 164.312(b) are required, and 164.308(a)(1)(ii)(D) requires regular review of records such as audit logs and access reports.
How long must a practice keep HIPAA security documentation?
Six years from the date it was created or last in effect, whichever is later, under 164.316(b)(2)(i).
Sources
- HHS FAQ, sending electronic PHI in an email
- 45 CFR 164.308, administrative safeguards (eCFR)
- 45 CFR 164.312, technical safeguards (eCFR)
- 45 CFR 164.306, general rules (eCFR)
- 45 CFR 164.316, documentation (eCFR)
- 45 CFR 164.402, definitions (eCFR)
- 45 CFR 164.404 and 164.408, notification (eCFR)
- 45 CFR 164.504, business associate contracts (eCFR)
- 45 CFR 164.314, organizational requirements (eCFR)
- HHS, Business associate contracts: sample provisions
- HHS, Guidance on HIPAA and cloud computing
- HHS, Guidance to Render Unsecured PHI Unusable, Unreadable, or Indecipherable
- 42 CFR 2.16, 2.32, 2.33 (eCFR)
- U.S. Department of Health and Human Services, Office for Civil Rights, Breach Portal: Notice to the Secretary of HHS of Breach of Unsecured Protected Health Information, 2025 reports
How can a practice check its email against these requirements?
A demo with PreVeil covers how it fits the practice’s email and file sharing.