Remedora
Start building
HIPAA Compliant Email

HIPAA doesn’t ban email.
It bans casual email.

Email can carry PHI when encryption, a signed BAA, access controls, and documented patient consent are in place. Most brands are better off keeping PHI out of the inbox entirely. Both setups, explained.

EncryptionIn transit · at rest
BAASigned, every vendor
ConsentWarned · documented
i. What compliance requires

Four controls carry the whole thing.

i.

Encryption, both directions.

TLS on the wire, encryption at rest with the provider. Compliant setups enforce TLS or fall back to a secure pickup link instead of sending in the clear.

ii.

A signed BAA with the vendor.

Any service that stores or transmits PHI for you is a business associate. Free consumer accounts do not come with a BAA, which settles the Gmail question.

iii.

Access controls and logging.

Named accounts, role-based permissions, a record of who read what. A shared support inbox with one password fails this test by itself.

iv.

Consent, documented.

Patients can choose plain email after a clear warning about the risk. The warning and the choice both belong on the record, not in someone’s memory.

ii. When PHI in email is allowed

The Privacy Rule permits it, with conditions.

OCR guidance is direct: providers may email patients when reasonable safeguards are in place. Patients also have a right to be contacted the way they ask. If a patient requests plain email after a clear warning about the risk, you can honor it. Document the warning, document the choice, and the legal question is settled.

The operational question is harder. Email has no recall, no expiry, and no control over forwarding. So disciplined programs restrict what email is allowed to carry: appointment logistics and secure links in, lab results and diagnoses out. The shorter the list, the fewer ways a Tuesday morning goes wrong.

iii. Where violations happen

The classics are boring and repeatable.

Enforcement cases rarely involve clever attacks. They involve a marketing blast with every patient in the CC field instead of BCC. A diagnosis in a subject line. A staff member auto-forwarding the clinic inbox to a personal account. A newsletter segmented by condition, pulled from the clinical database without authorization. And the perennial: PHI moving through a free consumer account that has no BAA and never will.

None of this requires malice. It requires ordinary tools and a normal week. That is the argument for designing the workflow so the mistake is hard to make, instead of training people to be careful forever.

iv. Evaluating providers

Questions that sort vendors quickly.

Ask four things: whether the vendor signs a BAA before contract and which services it covers; how mail is encrypted in transit and at rest, and what happens when a recipient’s server refuses TLS; what access controls and audit logs exist on the mailbox itself; and how long mail is retained and who can export it. A vendor that hedges on the BAA has answered everything else already.

Then ask the quieter fifth question: which of these messages need to be email at all. The same evaluation applies to every channel PHI touches. We keep parallel pages on HIPAA compliant texting and HIPAA compliant fax, and a wider one on HIPAA compliance software. Channel by channel the pattern holds: fewer vendors holding PHI means fewer BAAs to track, fewer audits to run, and fewer ways to leak.

v. How Remedora brands handle it

The platform answer: need less email.

Remedora is a HIPAA compliant telehealth platform for e-commerce health brands: storefront, intake, licensed providers, e-prescribing, pharmacy fulfillment, and payments under one signed BAA. Patient communication happens inside it, so the email that leaves the building never needs to carry PHI.

i.

Patient threads stay in-platform.

Intake follow-up, provider questions, and support run through platform messaging tied to the patient record. Covered by the same BAA as everything else.

ii.

Marketing email stays PHI-free.

Lifecycle email runs through the Customer.io integration on non-PHI events. Welcome flows and rebill reminders go out without a diagnosis ever leaving the platform.

iii.

Same audit trail.

Messages sit in the same 7-year immutable log as prescribing and intake, queryable from the operations console.

iv.

Same access controls.

Role-based permissions decide who sees clinical threads and who sees support threads. No shared inbox password anywhere in the flow.

vi. FAQ

Compliant email, plainly answered.

Is email HIPAA compliant?
Email can be used in compliance with HIPAA when the provider signs a BAA, messages are encrypted in transit and at rest, access is controlled and logged, and patients who choose unsecured email were warned first. No email service is compliant on its own. The workflow around it decides.
Is Gmail HIPAA compliant?
Free consumer Gmail is not, because Google does not sign a BAA for it. Paid Google Workspace plans include a BAA that covers Gmail, so a properly configured Workspace account can carry PHI. Configuration and staff habits still decide the real outcome.
Do patients need to consent to receiving PHI by email?
Providers may email patients with reasonable safeguards in place. If the channel is unencrypted, OCR expects the patient to get a plain warning about the risk first, and the choice should be documented. Marketing email that uses PHI needs written authorization, which is a separate and stricter bar.
What are the most common HIPAA email violations?
Misdirected messages, patient lists exposed in CC fields, diagnoses in subject lines, staff auto-forwarding work mail to personal accounts, and marketing sent from clinical data without authorization. Almost all of them involve ordinary tools used casually rather than an actual attack.
How do Remedora brands handle patient email?
Patient communication runs inside the platform under one signed BAA, tied to the patient record with role-based access and a 7-year immutable audit log. Lifecycle and marketing email run through the Customer.io integration on non-PHI events, so nothing in the newsletter stack ever needs to touch PHI.
vii. Begin

A setup that can’t leak what it never holds.

PHI in the platform. Marketing in Customer.io. One BAA.

Live in hoursReply within 24 hours
Remedora pill mascot

Launch your telehealth brand
this week.

Storefront, doctors, pharmacy, payments, and compliance, included and ready. The only thing missing is your brand.

LegitScript Certified
HIPAA COMPLIANT · BAA
© 2026 Remedora Inc.