HIPAA doesn’t ban email.
It bans casual email.
Email can carry PHI when encryption, a signed BAA, access controls, and documented patient consent are in place. Most brands are better off keeping PHI out of the inbox entirely. Both setups, explained.
Four controls carry the whole thing.
Encryption, both directions.
TLS on the wire, encryption at rest with the provider. Compliant setups enforce TLS or fall back to a secure pickup link instead of sending in the clear.
A signed BAA with the vendor.
Any service that stores or transmits PHI for you is a business associate. Free consumer accounts do not come with a BAA, which settles the Gmail question.
Access controls and logging.
Named accounts, role-based permissions, a record of who read what. A shared support inbox with one password fails this test by itself.
Consent, documented.
Patients can choose plain email after a clear warning about the risk. The warning and the choice both belong on the record, not in someone’s memory.
The Privacy Rule permits it, with conditions.
OCR guidance is direct: providers may email patients when reasonable safeguards are in place. Patients also have a right to be contacted the way they ask. If a patient requests plain email after a clear warning about the risk, you can honor it. Document the warning, document the choice, and the legal question is settled.
The operational question is harder. Email has no recall, no expiry, and no control over forwarding. So disciplined programs restrict what email is allowed to carry: appointment logistics and secure links in, lab results and diagnoses out. The shorter the list, the fewer ways a Tuesday morning goes wrong.
The classics are boring and repeatable.
Enforcement cases rarely involve clever attacks. They involve a marketing blast with every patient in the CC field instead of BCC. A diagnosis in a subject line. A staff member auto-forwarding the clinic inbox to a personal account. A newsletter segmented by condition, pulled from the clinical database without authorization. And the perennial: PHI moving through a free consumer account that has no BAA and never will.
None of this requires malice. It requires ordinary tools and a normal week. That is the argument for designing the workflow so the mistake is hard to make, instead of training people to be careful forever.
Questions that sort vendors quickly.
Ask four things: whether the vendor signs a BAA before contract and which services it covers; how mail is encrypted in transit and at rest, and what happens when a recipient’s server refuses TLS; what access controls and audit logs exist on the mailbox itself; and how long mail is retained and who can export it. A vendor that hedges on the BAA has answered everything else already.
Then ask the quieter fifth question: which of these messages need to be email at all. The same evaluation applies to every channel PHI touches. We keep parallel pages on HIPAA compliant texting and HIPAA compliant fax, and a wider one on HIPAA compliance software. Channel by channel the pattern holds: fewer vendors holding PHI means fewer BAAs to track, fewer audits to run, and fewer ways to leak.
The platform answer: need less email.
Remedora is a HIPAA compliant telehealth platform for e-commerce health brands: storefront, intake, licensed providers, e-prescribing, pharmacy fulfillment, and payments under one signed BAA. Patient communication happens inside it, so the email that leaves the building never needs to carry PHI.
Patient threads stay in-platform.
Intake follow-up, provider questions, and support run through platform messaging tied to the patient record. Covered by the same BAA as everything else.
Marketing email stays PHI-free.
Lifecycle email runs through the Customer.io integration on non-PHI events. Welcome flows and rebill reminders go out without a diagnosis ever leaving the platform.
Same audit trail.
Messages sit in the same 7-year immutable log as prescribing and intake, queryable from the operations console.
Same access controls.
Role-based permissions decide who sees clinical threads and who sees support threads. No shared inbox password anywhere in the flow.
Compliant email, plainly answered.
Is email HIPAA compliant?
Is Gmail HIPAA compliant?
Do patients need to consent to receiving PHI by email?
What are the most common HIPAA email violations?
How do Remedora brands handle patient email?
A setup that can’t leak what it never holds.
PHI in the platform. Marketing in Customer.io. One BAA.