HIPAA Security CheckGuides
HIPAA Guide

Is Regular Email HIPAA Compliant?

By Cooper Kelley, Founder, Tailwater Tech · July 15, 2026

Short answer: email is not banned by HIPAA, but sending patient information through a regular, unsecured inbox usually crosses the line. HIPAA does not care that it is email; it cares whether the patient data in that email is protected.

The trap most practices fall into is a personal Gmail or Outlook account, which will never meet the bar. Here is what the rule actually requires, when email is fine, and how to send patient information without turning a routine message into a reportable breach.

What HIPAA actually says about email

The Security Rule requires transmission security (45 CFR 164.312(e)) for electronic protected health information (ePHI) moving across a network. Encryption is “addressable,” which does not mean optional. It means you either implement it or document a legitimate reason you did not and an equivalent safeguard. In practice, for PHI leaving your walls, that means encrypt it.

The consumer-email trap

A free, personal Gmail or Outlook.com account is the single most common email mistake in small practices. Consumer accounts will not sign a Business Associate Agreement (BAA) and are not configured for PHI, so emailing patient information from one is a violation, full stop. To use email for PHI you need a provider that will sign a BAA and be configured for it, which the business tiers of Google Workspace and Microsoft 365 can do. The consumer versions cannot.

Emailing patients vs emailing other businesses

There is an important distinction. A patient can ask you to email their own information in plain email, and you can honor it, that is their right, as long as you warn them it may not be secure and offer a safer option. Emailing PHI to other providers, billing companies, or vendors in the clear is the bigger risk and is where practices get burned. That is where a secure channel is expected.

How to email patient information the right way

  • Use business email with a signed BAA. Google Workspace or Microsoft 365 (business tier), configured for compliance, not a personal account.
  • Encrypt external messages carrying PHI, or use a secure patient portal or an encrypted email service.
  • Get BAAs with your email provider and any service that touches those messages.
  • Keep PHI out of subject lines. Subject lines are often unencrypted and previewed on lock screens.
  • Train staff on what can and cannot go in plain email, and give them the secure option so they actually use it.

Common ways practices slip

  • Using a personal Gmail or Outlook.com account for anything patient-related.
  • Putting a patient name or condition in the subject line.
  • Forwarding patient messages to a personal or unsecured account to “work from home.”
  • Texting patient information: standard SMS is not secure and is not a compliant channel for PHI.

Is your email actually set up for patient data?

The HIPAA Security Check looks at secure transmission and the other safeguards OCR checks first, scores your exposure in a few minutes, and emails a plain-English report of your biggest gaps. No sales call required to see your score.

Take the free HIPAA Security Check  →

Frequently asked questions

Is Gmail HIPAA compliant?
Consumer Gmail is not: it will not sign a Business Associate Agreement. Google Workspace (the paid business version) can be, if you sign Google's BAA and configure it correctly. The account type and configuration are what matter, not the Gmail name.
Can I email a patient their test results?
Yes, if the patient asks to receive information by email and you have warned them it may not be secure. That is their right of access. A secure patient portal is the better default, but you can honor a clear patient request for plain email.
Is texting patient information a HIPAA violation?
Standard SMS text messaging is not secure and is not a compliant channel for PHI. Texting patient information without proper safeguards is a real violation risk. Use a secure messaging tool or portal instead.
Does HIPAA require encrypted email?
Encryption is “addressable,” meaning you implement it or document a legitimate reason you did not plus an equivalent safeguard. For PHI leaving your practice, encryption is the practical expectation, and it is often the line between a non-event and a reportable breach.

Keep reading