Email is the most common method for protected health information (PHI) to leave healthcare organizations without authorization. The HHS received 170 email-related breach reports in 2025, impacting 2.5 million people, according to Paubox’s 2026 Healthcare Email Security Report. A lot of that exposure did not even come from one organization’s own inbox. Vendor or business-associate email exposure was the cause in 28% of those incidents, and phishing-driven mailbox takeovers accounted for 17%.
Ninety two percent of healthcare IT leaders said they felt confident they could prevent email breaches, but 86% said they were worried about their HIPAA compliance status at the same time. Consent and opt-in questions sit squarely inside that anxiety, because a documented, defensible consent process is one of the few pieces of a breach response an organization fully controls.
What HIPAA actually requires
HIPAA does not require covered entities to get a blanket opt-in for all emails. A reminder about service offerings or other low-risk communication does not automatically create a requirement for consent.
If an email contains PHI, then consent is not optional. Once PHI is in the body of an email or in an attachment, the patient’s explicit consent to receive PHI that way is what matters. There are narrow exceptions for necessary healthcare related communications (treatment reminders or public health alerts). According to the HHS, “The Privacy Rule allows covered health care providers to share protected health information for treatment purposes without patient authorization.”
Where the confusion comes from
Two overlapping regulatory threads exist that should be considered.
Individuals have a right to request confidential communications through the channel of their choice, and covered entities generally must accommodate reasonable requests. A patient can request to receive an email or to not receive one.
The HHS has long maintained that the patient may assume the risk of transmission, but only under certain conditions. The covered entity is not liable for a disclosure of PHI in transit to the individual (per the individual’s own access request), as long as the individual was forewarned of and accepted the risks of unsecured transmission. The protection does not provide a blanket exemption. It now requires more documentation that encrypted options were offered and the patient was fully informed of the departure from the mandatory standard before choosing an unencrypted path under the framework Paubox has described for the upcoming Security Rule update.
The last point will be of interest to anyone tracking the proposed changes to the HIPAA Security Rule. Under the pending Security Rule update, this protection would, if the proposal is finalized, require more documentation demonstrating that encrypted options were offered and that the patient was fully informed of the deviation from the mandatory standard before choosing an unencrypted path. The proposal gives the following example of what must be documented, “Before the disclosure, the regulated entity informed the individual of the risks associated with transmission of unencrypted ePHI.”
What the research says about consent in practice
Research suggests there is a divide between policy and practice when it comes to the everyday use of physician patient email. Seventy five percent of physician respondents never or rarely obtained consent to communicate with patients by email. A national survey of physicians examining email use found that most physicians rarely discussed confidentiality risks or documented the email exchange in the patient’s chart at all.
In a separate survey of 624 primary care patients, 73.2% said they would be willing to be contacted by their health care provider through email to receive health-related information. The patients are generally receptive. What’s not there is the formal consent infrastructure around that willingness.
The gap was predicted in older clinical guidance on electronic communication and a practical fix was offered. Providers can determine the patient’s preferred channel, email, phone, or mail, informally at the time of a visit and note this in the chart or formalize the arrangement with a documented informed consent process. Nearly three decades on, that recommendation is still the right baseline and is still followed inconsistently.
Consent is not the whole compliance picture
A signed opt-in form does not change the protections applicable to the email infrastructure that delivers that message, nor does it lessen a covered entity’s obligation to apply the minimum necessary standard, maintain access controls, or have business associate agreements (BAA) with every vendor that handles that mail flow.
It is where the sale of encryption as a compliance shortcut is oversold. Encryption secures a message in transit. It does nothing for a compromised mailbox, a misconfigured forwarding rule, or a vendor with standing access to a shared inbox. As Paubox’s report on the top 3 email attacks of 2025 puts it, vendor exposure alone accounted for more than a quarter of 2025’s reported email incidents. Both consent and encryption are required controls. The entire Security Rule is not sufficient on its own or in combination with other controls.
Secure email and secure workflow are not the same thing
An organization can have a fully encrypted email platform and still have an insecure workflow around it. Paubox’s Healthcare Email Security Maturity Index 2026 found that 48% of organizations require recipients to log into a portal or create an account to read encrypted email messages, and more than a third of those organizations said clinical staff bypass the workflow. When the secure path is inconvenient, staff route around it, often back to personal email or texting, which defeats both the encryption and the consent documentation built around it.
The same report makes a related point about the human layer of these breaches. Email security assumes users will recognize deception, which is a reasonable description of why credential-theft attacks keep succeeding even where encryption is in place. And as one Paubox article on IT overconfidence put it, "Recipient experience is not secondary to security." Patients and staff will work around a consent and delivery process they find frustrating, regardless of what the underlying technology can do.
See also: HIPAA Compliant Email: The Definitive Guide (2026 Update)
FAQs
Is an email address considered PHI?
No, not unless it is a HIPAA identifier and becomes PHI when it is connected to identifiable health, treatment, or payment information in the hands of a covered entity or business associate.
Can patients withdraw an email opt-in?
Organizations should provide a clear way to change communication preferences. Withdrawing an opt-in affects future communications but does not invalidate actions already taken in reliance on valid permission.
Does an opt-in replace the need for a business associate agreement?
A vendor that creates, receives, maintains, or transmits PHI on behalf of a covered entity generally requires a BAA, regardless of whether the patient agreed to receive email.
