Yes, if your email platform handles protected health information (PHI) on your behalf, you need a business associate agreement (BAA) with that platform.

For direct-to-patient telehealth companies, this matters because email often replaces the communication infrastructure that a traditional medical practice would have in place. There may be no front desk, waiting room, or patient portal. Instead, email handles everything from intake and visit summaries to lab results, prescription updates, shipment notifications, and refill reminders.

If your email platform creates, receives, maintains, or transmits that PHI on your behalf, it may be a business associate, making a BAA necessary. But the BAA answers only one question: can this vendor handle your PHI?

It does not answer another important question: are you permitted to send this particular email? If a communication qualifies as marketing and requires patient authorization under HIPAA, having a BAA with your email provider does not remove that requirement.

 

What makes an email platform a business associate?

A BAA is not required simply because a vendor is involved in your business. The important question is whether the vendor is handling PHI on your behalf. HHS states that a software vendor does not become a business associate merely by selling software to a covered entity. However, “If the vendor does need access to the protected health information of the covered entity in order to provide its service, the vendor would be a business associate of the covered entity.”

A direct-to-patient telehealth company might use email for:

  • intake and onboarding
  • appointment or visit links
  • visit summaries
  • lab results
  • prescription information
  • refill reminders
  • medication adherence messages
  • shipping notifications
  • tracking information
  • treatment-related follow-ups
  • patient win-back campaigns

If those messages contain or reveal PHI and your email vendor processes or stores that information on your behalf, the vendor may be a business associate. If considered a business associate, you generally need a BAA in place before the vendor handles that PHI. According to the HHS, the BAA will “ensure that the business associates will appropriately safeguard protected health information.”

Learn more: How to know if you're a business associate

 

What about cloud-based email platforms?

HHS applies the same basic principle to cloud service providers. If a cloud service provider creates, receives, maintains, or transmits electronic PHI (ePHI) on behalf of a covered entity, the provider is generally a business associate. The covered entity therefore needs a HIPAA compliant BAA with the provider. That means you cannot assume an email platform is outside HIPAA simply because it is a cloud-based SaaS product or because it is only being used to send emails.

Additionally, according to the HHS, “A covered entity (or business associate) that engages a CSP should understand the cloud computing environment or solution offered by a particular CSP so that the covered entity (or business associate) can appropriately conduct its own risk analysis and establish risk management policies, as well as enter into appropriate BAAs.”

The practical question is still the same: Does the platform handle PHI on your behalf? If it does, you need to establish whether the vendor will enter into the required BAA before putting patient information into the platform. Additionally, you must conduct a risk assessment to understand how the platform handles ePHI, identify potential risks to that information, and establish appropriate safeguards to address those risks.

Read also: All about cloud email services

 

How do I make sure my email platform is HIPAA compliant?

If your email platform handles PHI on your behalf, it must to enter into a HIPAA compliant BAA with your organization. Look at how the platform actually handles your data. Consider whether it:

  • Encrypts emails containing PHI
  • Protects PHI while it is being transmitted and stored
  • Limits access to PHI
  • Provides appropriate security controls and safeguards
  • Has a BAA in place with your organization
  • Allows you to control who can access patient information
  • Protects PHI across the email workflow, including attachments and other message content

A platform calling itself "secure" or "HIPAA-ready" is not enough on its own. You need to understand what the platform does with your PHI and whether the vendor will assume the responsibilities that come with being a business associate.

It is also important to remember that a HIPAA compliant email platform does not make every email you send permissible under HIPAA. You still need to determine whether you are allowed to send the communication, particularly when it involves marketing.

Ultimately, there are two separate checks:

  • Is my email platform set up to handle PHI appropriately?
  • Am I permitted to send this particular email?

Your email platform can help address the first question. Your organization's HIPAA policies and legal requirements determine the second.

Go deeper: HIPAA Compliant Email: The Definitive Guide (2026 Update)

 

Using the Paubox solution

Paubox provides HIPAA compliant email designed for healthcare organizations. It automatically encrypts messages containing PHI, so patients do not need to log into a separate portal or use a password to access their email. Paubox also provides a BAA, helping establish the business associate relationship required when the platform handles PHI on behalf of a covered entity.

This can be useful for telehealth companies that need to send patient communications such as:

  • Prescription and medication updates
  • Refill reminders
  • Visit-related communications
  • Lab result notifications
  • Shipment notifications
  • Patient follow-ups

The goal is to keep the patient experience simple while protecting PHI throughout the email communication process.

See also: Paubox for telehealth

 

FAQS

Does encryption make an email platform HIPAA compliant?

No. Encryption is an important safeguard, but it does not by itself make a platform HIPAA compliant or eliminate the need for a BAA. You also need to consider how the vendor handles PHI and whether the appropriate contractual safeguards are in place.

 

Do email attachments containing PHI need to be encrypted?

PHI in an attachment needs appropriate safeguards. If your email platform automatically protects messages containing PHI, check how that protection applies to attachments as well as the message itself.

 

Does HIPAA apply to email preview text?

The same privacy considerations can apply to preview text as to the email itself. If preview text reveals information about a patient's treatment, medication, or healthcare services, it should be treated as part of the PHI being communicated.

 

Is a HIPAA compliant email platform enough to make my entire telehealth business HIPAA compliant?

No. Email is only one part of the technology stack. Your EHR, telehealth platform, CRM, ecommerce system, analytics tools, cloud services, and other vendors may also handle PHI and need to be assessed separately.