Yes, the body of a shipment notification can name the medication, provided the message is sent through a secure channel handled only by vendors under a business associate agreement (BAA). The subject line, preview text and tracking page should not name it.
HIPAA does not prohibit telling a patient what is in their package. It regulates how that information travels and who handles it on the way. Most of the risk in a shipment email comes from the sending platform and from the parts of the message that display outside the secure body, not from the medication name itself.
Is a shipment notification PHI?
Yes, when it ties a medication to an identifiable patient. Under 45 CFR 160.103, individually identifiable health information is information that “relates to the past, present, or future physical or mental health or condition of an individual; the provision of health care to an individual,” and that identifies the person or offers “a reasonable basis to believe the information can be used to identify the individual.”
A name plus a prescription drug is exactly that. So does an email address. The de-identification standard at 45 CFR 164.514(b)(2)(i) lists “(F) Electronic mail addresses” and “(R) Any other unique identifying number, characteristic, or code” among the identifiers. Even a message that says only “Your order has shipped” can qualify when a telehealth company sends it, because the message itself shows the recipient is a patient.
A shipment notification is therefore not a generic e-commerce receipt. It is a communication from a covered entity about the delivery of treatment, and it follows the same rules as visit summaries and lab results.
Do you need patient authorization to include the drug name?
No. Telling a patient their prescription has shipped is part of treatment and health care operations, and the Privacy Rule permits those uses and disclosures without authorization.
Authorization comes up when a message does more than notify. HHS’s guidance on the marketing definition at 45 CFR 164.501 sets out what stays outside it. Communications about a drug “currently being prescribed for the individual” fall within the refill reminder exception, including adherence communications and, according to HHS FAQ on what falls within the refill reminder exception, “communications regarding all aspects of a drug delivery system” for self-administered drugs. The exception holds only if any payment from a third party is reasonably related to your cost of making the communication.
The exception does not include everything. HHS FAQ on the “Communications about specific adjunctive drugs related to the currently prescribed drug falling within the “refill reminder” exception to marketing?” says that “only communications about drugs or biologics currently prescribed to the individual fall within the refill reminder exception,” and a specific adjunctive drug does not.
Where the real exposure is
1. The sending platform
If your email or SMS platform stores or processes message content that includes PHI, it is likely a business associate and must sign a BAA before it handles that content.
The conduit exception does not rescue a platform that keeps your messages. HHS FAQ on Can a CSP be considered to be a “conduit” states that “the conduit exception is limited to transmission-only services for PHI (whether in electronic or paper form), including any temporary storage of PHI incident to such transmission.” It adds that a provider that maintains ePHI for storage “will qualify as a business associate, and not a conduit, even if the CSP does not actually view the information, because the entity has more persistent access to the ePHI.”
HHS’s related cloud guidance also states that a covered entity using a cloud provider to maintain ePHI without a BAA is in violation of the HIPAA rules. If your platform will not sign a BAA, the medication name cannot go through it. Either move PHI messages to a platform that will sign one, or remove the PHI from what the unsigned platform sends.
2. The subject line and preview text
Subject lines appear on lock screens, in notification banners, in shared inboxes and on smartwatches, and they travel in message headers that remain readable in transit even when the body is encrypted. A subject such as “Your semaglutide has shipped” exposes the drug to anyone who glances at the screen.
Learn more: Writing a HIPAA compliant subject line
3. Transmission security
The Security Rule’s transmission security standard, 45 CFR 164.312(e)(1), requires covered entities to “implement technical security measures to guard against unauthorized access to electronic protected health information that is being transmitted over an electronic communications network.” Encryption is an addressable specification under (e)(2)(ii). Addressable means you implement it, or document why an equivalent alternative is reasonable.
In the 2013 Omnibus Rule, HHS said “covered entities are permitted to send individuals unencrypted emails if they have advised the individual of the risk, and the individual still prefers the unencrypted email.” HHS FAQ confirms that “individuals have a right to receive a copy of their PHI by unencrypted e-mail if the individual requests access in this manner.” A shipment notification is not an access request.
4. Tracking numbers and carrier pages
A tracking number becomes PHI when it sits beside a patient’s identity in a message from a telehealth company. In practice:
- Put the tracking link in the secure message body, not the subject.
- Confirm the carrier’s tracking page shows status only, with no contents.
- Keep the medication name off any label or packing slip visible from outside the box.
5. Open and click tracking
Many marketing platforms add tracking pixels and rewrite links to record opens and clicks. In a message containing PHI, those mechanisms pass patient-linked data to a vendor. Without a BAA, that is a second disclosure problem. Turn tracking off on messages that contain PHI unless the vendor is covered.
6. Wrong or outdated email addresses
Encryption and a BAA protect a message on its way to an address. They do nothing if the address is wrong. A typo at sign-up, an address the patient has abandoned, or a shared family inbox can send a message that names a patient’s medication to someone else. A shipment notice that reaches the wrong person is an impermissible disclosure risk, and it may need to be assessed under the HIPAA Breach Notification Rule.
The most effective control is at intake:
- Confirm the patient’s email address when you collect it, for example by sending a verification link they must click before the address is used for any PHI-bearing message.
- Let patients review and update their contact details easily, and re-confirm the address when it changes or when messages bounce.
- Stop sending messages that contain PHI to an address after a bounce or a report that it is wrong.
What a compliant shipment notification looks like
- Subject: neutral, with no drug name, dose or condition.
- Body: first name, medication name and strength, quantity, carrier, tracking link, expected delivery date, and storage instructions where they matter, such as refrigeration for injectables.
- Delivery: sent through a platform under a BAA, with encryption applied.
- Tracking: pixels and link rewriting off.
- Content: operational only, with no promotions or upsells.
Naming the medication has a clinical benefit. Patients on injectables or temperature-sensitive drugs need to know what is arriving and how to store it.
Read also: HIPAA compliant email for telehealth and virtual pharmacies
FAQs
What does “addressable” mean in HIPAA’s security standards?
An addressable specification must be implemented, or you must document why it is unreasonable and adopt an equivalent alternative.
What is encryption, and why does it matter for patient messages?
Encryption scrambles a message so that only the intended recipient can read it, which protects the content if it is intercepted along the way.
