Email is one of the most common ways protected health information (PHI) leaves a healthcare organization, and one of the most common ways it gets exposed. Making email HIPAA compliant is not a single switch you flip. It is a set of decisions about your email provider, your encryption, your access controls, your staff, and the threats coming into your inbox. This checklist walks through each step, from confirming HIPAA applies to you all the way to locking down inbound email.
Want the printable version? Download the HIPAA compliant email checklist and work through it alongside this guide.
Why HIPAA compliant email matters
The Health Insurance Portability and Accountability Act (HIPAA) requires covered entities and business associates to protect PHI in transit and at rest. Email touches both. When an unencrypted message carrying PHI leaves your organization, it can be intercepted or misaddressed, and either outcome is reportable.
The consequences are documented publicly. The Department of Health and Human Services (HHS) Office for Civil Rights breach portal lists every breach affecting 500 or more individuals, and email remains a recurring entry. Beyond the reputational cost, resolution agreements and civil penalties can reach into the millions.
For the full background on requirements, encryption standards, and how the rules apply, read our guide to HIPAA compliant email.
The HIPAA compliant email checklist
1. Determine HIPAA applicability and scope
Before configuring anything, confirm where you sit under the law.
- Determine whether you are a covered entity or a business associate
- Identify every workflow where PHI moves through email, inbound and outbound
- Note which staff, systems, and third parties touch that PHI
2. Select and configure a secure email service
Your provider and its configuration do most of the heavy lifting.
- Choose between Google Workspace and Microsoft 365 as your underlying platform
- Establish a business associate agreement (BAA) with that platform
- Connect Paubox to your chosen provider so every outbound email is encrypted by default
- Set up DomainKeys Identified Mail (DKIM) and Sender Policy Framework (SPF) records to authenticate your domain and ensure secure delivery
- Send a test email to verify encryption is working before you go live
Paubox seamlessly encrypts emails using 256-bit advanced encryption standard (AES) and transport layer security (TLS) 1.2 or higher, with no portals, passwords, or plugins for the recipient.
Read also: Top 12 HIPAA compliant email services
3. Develop access control policies
Limit who can reach PHI, and prove that you did.
- Define who can access which types of electronic protected health information (ePHI)
- Set guidelines for password complexity
- Activate two-factor authentication for every account that touches PHI
4. Establish email usage policies
Written rules turn good intentions into repeatable behavior.
- Develop guidelines for how ePHI should be handled and shared over email, including sending only the minimum necessary information
- Incorporate data retention and deletion policies that specify how long emails containing PHI are kept and how they are securely disposed of
Read also: What are HIPAA's email archiving and retention requirements
5. Train staff regularly
Most email breaches trace back to a person, not a system.
- Train staff on HIPAA rules and secure email practices
- Educate staff on your internal email policies
- Run refreshers on recognizing phishing and business email compromise (BEC)
6. Conduct regular risk assessments
- Regularly review and update your security measures and policies
- Reassess whenever your systems, vendors, or workflows change
7. Implement an incident response plan
- Create a plan for responding to and reporting security incidents
- Train staff on your breach response protocols
- Test the plan and update it as your environment changes
8. Secure inbound email
Encryption protects what you send. It does nothing for what arrives. Inbound is where phishing, spoofing, and BEC get in.
- Implement inbound email security, including ExecProtect and Geofencing
- Set up notifications for when ExecProtect catches a display name spoofing attempt
- Train staff to recognize phishing emails
Paubox Email Suite Plus adds AI-powered inbound email security that uses generative AI to detect phishing, spoofing, and BEC by analyzing sender behavior, tone, and message intent. ExecProtect specifically stops display name spoofing, the tactic attackers use to impersonate executives and trusted colleagues.
9. Document and review compliance measures
Documentation is what turns your work into a defensible compliance posture during an audit.
- Keep detailed records of every compliance measure, decision, and policy you implement
- Maintain a dedicated folder for all HIPAA related documents
- Log the dates and content of training sessions, policy updates, and risk assessments
- Schedule regular policy reviews so your email practices stay current with HIPAA regulations
HIPAA compliant email with Paubox
Paubox is a leader in HIPAA compliant email security for healthcare, trusted by more than 8,000 healthcare organizations. Paubox Email Suite encrypts every outbound email by default and works directly with Google Workspace and Microsoft 365, so your team keeps sending email the way they always have. Paubox Email Suite Plus layers on AI-powered inbound email security to catch the threats that reach your inbox.
The result covers most of this checklist at once: encryption in transit, BAA coverage, authenticated delivery, and inbound protection, without portals, passwords, or added steps for your recipients.
FAQs
What does it mean for an email to be HIPAA compliant?
A HIPAA compliant email system implements administrative, physical, and technical safeguards to protect PHI. That includes encryption in transit and at rest, access controls, authentication of your sending domain, staff training, and a business associate agreement (BAA) with any vendor that handles PHI on your behalf.
Do all healthcare emails have to be HIPAA compliant?
Any email containing PHI must meet HIPAA standards. Messages with no PHI are not subject to the same requirements, though applying one consistent standard across your organization removes the risk of a mistake.
Can I use Gmail, Outlook, or Yahoo for HIPAA compliant email?
Standard consumer versions do not meet HIPAA requirements on their own. Google Workspace and Microsoft 365 can be made compliant with a signed BAA and an encryption layer such as Paubox. Free Yahoo, consumer Gmail, and personal Outlook accounts cannot.
Get the checklist
Download the HIPAA compliant email checklist to keep this on hand as you configure your systems, and see Paubox Email Suite for HIPAA compliant email you can set up in about 15 minutes.
