HIPAA Compliant Email: Requirements for Telehealth Businesses
HIPPA
Telehealth
Healthcare Technology

HIPAA Compliant Email: Requirements for Telehealth Businesses

Learn HIPAA compliant email requirements for telehealth, including encryption, BAAs, access controls, audit logs, and secure communication.

Bask Health Team
Bask Health Team
08/14/2026

Email is one of the most common communication tools in any business and one of the most common sources of HIPAA violations in healthcare. The combination is not coincidental. Email feels familiar and low-risk. It is fast, convenient, and already in use across the entire organization. And, without specific technical safeguards and contractual controls in place, it is also one of the highest-risk channels a telehealth business can use for patient communication.

For telehealth businesses, HIPAA-compliant email is not optional. Every email that contains protected health information, or that is sent to a patient in a context involving PHI, must meet specific technical, administrative, and contractual requirements. At Bask Health, our HIPAA-compliant security infrastructure is built to handle patient communication within a compliant platform, and our virtual clinic framework keeps clinical interactions inside a compliant system rather than routing them through standard email channels.

The Health Resources and Services Administration (HRSA) recognizes HIPAA compliance as a foundational requirement for all telehealth operations. This guide covers what HIPAA-compliant email actually requires, which common tools do and do not meet the standard, and what telehealth businesses need to do to bring their email communications into compliance.

Key Takeaways

  • Email containing protected health information must be encrypted in transit using TLS 1.2 or higher, per HHS guidance citing NIST standards.
  • Any email service provider whose infrastructure transmits or stores PHI is a HIPAA business associate and must sign a Business Associate Agreement before PHI flows through their system.
  • Standard Gmail, Outlook, and Yahoo accounts do not provide BAAs and are not HIPAA compliant for communications containing PHI.
  • Google Workspace and Microsoft 365 offer BAAs on eligible business plans, but signing the BAA alone is not sufficient. The email environment must also be configured correctly to enforce compliance.
  • According to HHS, email is a permissible channel for communicating PHI with patients when proper safeguards are in place and the patient has been warned of the risks.
  • Email is the leading attack vector for healthcare data breaches. One in three HIPAA breaches reported to HHS involved email as the primary attack vector.
  • Telehealth businesses should route clinical communications through their patient management platform rather than standard email wherever possible.

What Makes an Email HIPAA Compliant

HIPAA does not ban email. It does not require healthcare organizations to avoid email communication with patients. What it requires is that when email is used to transmit or store protected health information, specific safeguards must be in place.

According to HHS.gov's HIPAA guidance, covered entities may communicate with patients by email about health issues, but proper safeguards must be in place, and patients should be warned of the risks of communicating PHI by email. That framing captures the compliance obligation precisely: email is permitted, but the safeguards that make it compliant are not optional.

The three pillars of HIPAA compliant email are encryption, business associate agreements, and access controls. Each is required. None is sufficient on its own.

Encryption in Transit and at Rest

HHS guidance, citing NIST standards, specifies that PHI transmitted by email must be encrypted using a process that complies with NIST SP 800-52 for data in motion, which means TLS 1.2 or higher. For PHI stored in email inboxes, at-rest encryption should meet NIST SP 800-111 standards, which means AES-128 or higher. The full technical specifications are documented in HHS's HIPAA Security Rule guidance.

The current HIPAA Security Rule describes encryption as an "addressable" rather than "required" specification, which means covered entities that do not implement encryption must document why an alternative measure provides equivalent protection. In practice, HHS and state enforcement agencies treat unencrypted email containing PHI as a violation. The 2025 proposed Security Rule update from HHS, for which comments closed in March 2025, would remove the addressable classification and make encryption of ePHI at rest and in transit a mandatory specification. That rulemaking is not yet final, but the regulatory direction is clear. Telehealth businesses should treat encryption as a baseline requirement, not an optional safeguard.

Business Associate Agreements

Any email service provider whose infrastructure transmits, stores, or provides access to PHI is a HIPAA business associate. This includes any email platform where patient emails sit in an inbox, regardless of whether the emails are encrypted. The email service provider has persistent access to the data, which meets the definition of a business associate under HIPAA.

A Business Associate Agreement must be signed with the email provider before any PHI flows through their system. The BAA must specify the permitted uses and disclosures of PHI, require the business associate to implement appropriate safeguards, mandate breach reporting, and grant the covered entity access to the information for compliance purposes.

Consumer email accounts, including personal Gmail, Yahoo, and Hotmail, do not provide BAAs. Using any of these accounts to send or receive emails containing PHI is a HIPAA violation regardless of whether the emails are encrypted.

Access Controls and Audit Logging

HIPAA requires that access to ePHI be limited to authorized users, and that access events be logged for audit purposes. In an email context, this means the email environment must support role-based access controls, multi-factor authentication, and audit logs that record who accessed which emails containing PHI and when.

An email environment that does not enforce MFA, does not restrict access to patient emails based on user role, or does not maintain auditable access logs does not meet HIPAA's technical safeguard requirements regardless of encryption status.

Which Common Email Tools Are and Are Not HIPAA Compliant

Standard Consumer Email: Not Compliant

Personal Gmail, Yahoo Mail, Hotmail, and standard consumer accounts from any major email provider are not HIPAA-compliant for communications containing PHI. None of them provide BAAs. None of them are configured to enforce the technical safeguards HIPAA requires. Using them for patient communication involving PHI is a violation.

Google Workspace: Compliant When Configured Correctly

Google Workspace (the paid business version of Gmail) offers a HIPAA BAA on eligible plans. The BAA covers Gmail, Google Calendar, Google Drive, Google Meet, and other core Workspace services. Signing the BAA through the Google Workspace admin console is a required first step, but it is not sufficient on its own.

Once the BAA is signed, the Workspace environment must be configured to meet HIPAA's technical safeguards: email encryption must be enforced, MFA must be required for all users with access to PHI, audit logging must be enabled and retained, and sharing and access settings must be reviewed to ensure PHI cannot be inadvertently exposed through Drive or Calendar integrations.

Microsoft 365: Compliant When Configured Correctly

Microsoft 365 offers a HIPAA BAA for eligible business and enterprise plans through the Microsoft 365 admin center or the Service Trust Portal. The BAA covers Exchange Online, SharePoint, Teams, and Purview Message Encryption on covered plans. As with Google Workspace, signing the BAA is necessary but not sufficient. The environment must be configured to enforce encryption, MFA, audit logging, and appropriate access controls.

One important detail for Microsoft 365 users: Purview Message Encryption (formerly Office Message Encryption) provides end-to-end encryption for emails sent outside the organization, including to patients who use non-Microsoft email accounts. Without this feature enabled, emails containing PHI sent to patients outside the Microsoft ecosystem may not meet the encryption standard.

Direct Answer: Is Gmail HIPAA Compliant?

Standard personal Gmail accounts are not HIPAA-compliant. Google Workspace (the paid business plan) can be made HIPAA compliant if the organization signs the BAA through the admin console and configures the environment to enforce encryption, MFA, audit logging, and appropriate access controls. Signing the BAA without correctly configuring the environment does not make the email system compliant.

What Emails Require HIPAA Compliance in Telehealth

Not every email a telehealth business sends requires HIPAA safeguards. The rules apply specifically when the email contains or relates to protected health information. Understanding which emails trigger the requirement helps operators prioritize their compliance efforts correctly.

Emails that require HIPAA compliance include any email that contains clinical information tied to an identifiable patient, prescription notifications or refill reminders that reference the patient's medication or condition (for telehealth businesses using Bask Health's EMR and e-prescribing tools, prescription routing happens within the platform rather than through email, which removes this compliance burden entirely), appointment or visit confirmations that include clinical context, billing communications that reference the patient's treatment or diagnosis, and any response to a patient inquiry that involves their health status or care plan.

Emails that do not trigger HIPAA requirements include general marketing communications that do not reference individual patient health information, appointment reminders that contain only a date and time with no clinical context, and administrative communications that contain no patient-identifying information.

The safest operational policy, and the one most consistent with how HHS enforcement actually works, is to treat all communications with patients as HIPAA-regulated and apply the same safeguards across the board. Relying on staff to make case-by-case determinations about which emails contain PHI creates a compliance risk due to inconsistent execution.

Patient Consent for Email Communication

HHS guidance states that if a patient provides a healthcare provider with an email address or initiates communication by email, consent to receive email communication is implied. However, patients should be informed of the risks of communicating PHI by email, and that warning and the patient's acknowledgment should be documented.

For telehealth businesses that communicate with patients primarily through a patient portal or secure messaging system, the email channel is typically used for administrative notifications rather than clinical communication. That distinction is worth making explicit in the patient intake process so that patients understand which channel contains their clinical information and which is used for operational communication.

The Bigger Risk: Email as an Attack Vector

HIPAA compliance for email is not just about regulatory obligation. Email is the leading attack vector for healthcare data breaches. According to published HHS breach data, one in three HIPAA breaches reported to HHS involved email as the primary attack vector. The average cost of a healthcare data breach involving email is in the range of several million dollars, including regulatory penalties, remediation costs, and reputational impact.

The most common email-related breach scenarios in healthcare are phishing attacks that compromise provider credentials, misconfigured email forwarding that routes PHI to unintended recipients, and unencrypted emails containing PHI that are intercepted in transit. All three are preventable with correct configuration and access controls.

For telehealth businesses, the practical implication is that email security is a patient safety and business continuity issue as much as a compliance requirement. A breach involving patient PHI creates regulatory exposure, patient notification obligations, and reputational damage that is difficult and expensive to recover from.

Why Patient Communication Belongs in the Platform, Not Email

The most robust approach to email compliance for telehealth businesses is to minimize the use of standard email for clinical communication and route as much patient interaction as possible through the clinical platform's secure messaging function.

A secure messaging system within the patient management platform is HIPAA-compliant by design. It is encrypted, access-controlled, and auditable as part of the platform's core architecture. There is no BAA to sign separately, no encryption configuration to maintain independently, and no risk of PHI being sent to the wrong address through a standard email client.

According to Telehealth.HHS.gov, all telehealth platforms must meet HIPAA requirements, and providers should use platforms that include appropriate safeguards for protected health information. Routing clinical patient communication through the platform rather than standard email is the most straightforward way to meet that standard.

Bask Health's patient management tools support patient communication within the platform's HIPAA-compliant infrastructure, so clinical messages, prescription notifications, and care coordination communication happen within a compliant system rather than through email channels that require separate configuration and BAA management.

Email then serves its most appropriate role in telehealth: operational notifications that do not contain PHI, such as a general reminder that something is available to view in the patient portal, rather than clinical communication that directly involves protected health information.

Direct Answer: What Email Service Should a Telehealth Business Use?

For emails that must contain PHI, a telehealth business needs an email service that provides a signed BAA and supports TLS 1.2 or higher for in-transit encryption and AES-128 or higher at rest. Google Workspace and Microsoft 365 on eligible plans both offer BAAs and can be configured to meet HIPAA requirements. Purpose-built HIPAA-compliant email services are also available and offer BAAs as part of their standard offering. For clinical communication with patients, the better practice is to use the patient management platform's secure messaging function rather than email, and reserve email for administrative notifications that do not contain PHI.

A Note From the Field

The email compliance gaps that create the most regulatory exposure for telehealth businesses are almost always the ones that developed before anyone thought carefully about email as a HIPAA risk. A practice that started with a team of two people using personal Gmail addresses and grew to fifty patients before anyone reviewed the communication setup is operating with a compliance gap that gets more expensive to close the longer it exists. Getting the email infrastructure right early costs far less than responding to a breach or an OCR investigation after the fact.

Conclusion

HIPAA-compliant email for telehealth businesses requires encryption in transit and at rest, a signed Business Associate Agreement with the email service provider, and access controls, including multi-factor authentication and audit logging. Standard consumer email accounts are not compliant. Business email platforms,s including Google Workspace and Microsoft 36,5 can be made compliant with the appropriate plan, a signed BAA, and appropriate configuration.

The stronger operational practice is to route clinical patient communication through the patient management platform's secure messaging system rather than standard email, reserving email for administrative notifications that do not contain PHI. Bask Health's infrastructure supports this model, keeping patient communication within a HIPAA-compliant platform to minimize the email compliance burden for clinical communication.

This article is for informational purposes only and does not constitute legal or compliance advice. Healthcare operators should consult qualified legal counsel regarding their specific HIPAA obligations.

References

  1. U.S. Department of Health & Human Services, Office for the Advancement of Telehealth. (n.d.). Getting started with telehealth. https://telehealth.hhs.gov/providers/getting-started
  2. U.S. Department of Health & Human Services. (n.d.). HIPAA Security Rule guidance material. https://www.hhs.gov/hipaa/for-professionals/security/guidance/index.html
  3. U.S. Department of Health & Human Services. (n.d.). HIPAA Privacy Rule guidance materials. https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/index.html
  4. Health Resources and Services Administration (HRSA). (n.d.). What is telehealth? https://www.hrsa.gov/telehealth/what-is-telehealth
Schedule a Demo

Talk to an expert about your data security needs. Discuss your requirements, learn about custom pricing, or request a product demo.

Sales

Speak to our sales team about plans, pricing, enterprise contracts, and more.