Are All Emails HIPAA Compliant?

All emails are not HIPAA compliant because only emails containing Protected Health Information (PHI) are required to be HIPAA compliant when they originate from a member of a HIPAA covered entity’s or business associate’s workforce. Emails that do not contain PHI or that do not originate from an organization that does not qualify as a HIPAA covered entity or business associate are not required to be HIPAA compliant.

Members of HIPAA covered entities’ and business associates’ workforces send emails within and outside their organizations for multiple purposes. Most of these purposes are beyond the scope of HIPAA because HIPAA only applies to emails that contain PHI. Any emails that do not contain PHI are not required to be HIPAA compliant when they originate from a HIPAA-regulated organization, even if they are sent via the same email service as emails containing PHI.

Therefore, if an organization subscribes to a (for example) Microsoft Office service that supports HIPAA compliance, all the organization’s emails can originate from the Microsoft Outlook service whether the emails are required to be HIPAA compliant or not. In addition, emails received from other organizations that qualify as HIPAA covered entities or business associates and that contain electronic PHI can be maintained compliantly in email inboxes.

When Are Emails HIPAA Compliant?

Emails containing PHI are HIPAA compliant when they are created, received, transmitted, or maintained for a purpose required or permitted by the HIPAA Privacy Rule. In some cases, the amount of PHI contained in the content of emails may be subject to limitations, it may be necessary to obtain an attestation that the content of the email will not be further disclosed by the recipient of the email, or it may be necessary to obtain the patient’s authorization.

In most cases, emails containing PHI may only be sent via email services that support HIPAA compliance. This means the email service must comply with applicable Administrative, Physical, and Technical Safeguards, and – if an organization subscribes to a third party email service (i.e., Microsoft Outlook) – a Business Associate Agreement is in place that describes which party is responsible for complying with which compliance requirements.

Even when a shared responsibility Agreement exists, all HIPAA covered entities and business associates are responsible for configuring the email service to be used in compliance with HIPAA, training members of the workforce on how to use the email service in compliance with HIPAA, and monitoring workforce compliance via user logs and audit controls. The best solution for medical practices is to use a HIPAA-compliant email provider like Paubox, which has the best HIPAA-compliant email solution.

HIPAA
Compliance
Checklist

Simple Guidelines
Immediate PDF Download

Immediate Access

Privacy Policy

Download Free Checklist

Points to Note Regarding HIPAA and Emails

Because the HIPAA Privacy Rule and HIPAA Security Rule are designed to cover many different types of organizations and covered activities, there is no one-size-fits-all set of guidelines for making emails HIPAA compliant. However, there are some important points to note regarding HIPAA and emails that can influence how HIPAA-regulated entities interpret and apply the HIPAA Privacy and Security Rules. These include (but are not limited to):

  • Personally identifiable information (i.e., names, email addresses, etc.) maintained separately from health, treatment, and payment information is not considered PHI under HIPAA.
  • PHI can be emailed via email services that do not support HIPAA compliance under certain circumstances – i.e., when a patient exercises their HIPAA rights to request PHI by email.
  • Sending emails to the wrong recipients accounts for approximately 8% of data breaches notified to HHS’ Office Civil Rights each year. 64,592 data breaches were notified in 2022.
  • PHI should not be included in the subject line of an email – even when an email is sent via a HIPAA compliant email service – because subject lines are often not encrypted in transit.
  • When HIPAA does not apply, the privacy and/or security of personally identifiable information may be subject to state regulations – some of which apply across state borders.

HIPAA-regulated organizations can adopt measures to make all emails HIPAA compliant without securing non-PHI data behind excessive access permissions that affects the flow of data and workplace operations. To find out more about assigning appropriate access permissions, HIPAA covered entities and business associates should seek advice from a compliance specialist with experience in email security.

About Liam Johnson

Liam Johnson has produced articles about HIPAA for several years. He has extensive experience in healthcare privacy and security. With a deep understanding of the complex legal and regulatory landscape surrounding patient data protection, Liam has dedicated his career to helping organizations navigate the intricacies of HIPAA compliance. Liam focusses on the challenges faced by healthcare providers, insurance companies, and business associates in complying with HIPAA regulations. Liam has been published in leading healthcare publications, including The HIPAA Journal. Liam was appointed Editor-in-Chief of The HIPAA Guide in 2023. Contact Liam via LinkedIn: https://www.linkedin.com/in/liamhipaa/