Email integrations can make healthcare communication faster and more efficient. A healthcare organization can connect its email platform with an electronic health record (EHR), scheduling system, customer relationship management (CRM) platform, or other application to automate notifications, route messages, and share patient information.
However, every integration creates another pathway through which protected health information (PHI) can move.
An email integration may cause PHI to be copied into another application, processed by a third-party service, stored in additional locations, or made accessible through new user permissions. If these connections are poorly configured or inadequately secured, they can increase the opportunities for unauthorized access or disclosure.
Email use and HIPAA
According to the US Department of Health and Human Services (HHS), “The Privacy Rule allows covered health care providers to communicate electronically, such as through e-mail, with their patients, provided they apply reasonable safeguards when doing so.” This means HIPAA does not prohibit healthcare providers from communicating with patients by email, including when the communication contains PHI. HHS recommends safeguards such as verifying email addresses before sending information and limiting the amount or type of PHI included in an unencrypted email.
The privacy and security risks of connected healthcare systems
Research into healthcare interoperability suggests that connecting previously separate systems can create important privacy and security challenges. As EHRs, health information exchanges (HIEs), and other healthcare applications become more interconnected, patient information can move across a larger number of systems, organizations, and technical environments.
The systematic review ‘Interoperable Electronic Health Records and Health Information Exchanges’ examined the effects of interoperable EHRs and HIEs across 44 studies. The review found that security and privacy were among the outcome areas in which negative findings outnumbered positive findings. The authors noted concerns including unauthorized access, data breaches, and difficulties maintaining the privacy and security of health information as systems become more connected.
These findings are relevant to email integrations because connecting an EHR to an email platform similarly creates a pathway for patient information to move between systems. Depending on how the integration is designed, PHI may be accessed by APIs, third-party applications, email servers, or other intermediary services. Each additional component can introduce its own access controls, storage locations, and security requirements.
How email integrations create additional PHI exposure points
An integration connects two or more systems that previously operated separately. For example, an organization might configure its EHR to automatically send appointment reminders through an email platform. Depending on how the integration is configured, patient information may pass through several systems before reaching the recipient. This creates additional environments that need to be considered when protecting PHI.
Here is how these integrations can lead to PHI exposure:
Integrations can create additional copies of PHI
David Kreindler, in the study ‘Email security in clinical practice: ensuring patient confidentiality' indicated that electronic messages can exist in multiple locations as they move between sender and recipient. The author identified potential confidentiality risks at the sender's computer, intermediate mail servers, and the recipient's computer, noting that copies of messages may also remain in backups or other storage locations.
Although email infrastructure has evolved since the study was published, the underlying concern remains relevant: health information can exist in more places than the sender and recipient may realize. Email integrations can add potential storage and processing points by connecting email with EHRs, workflow platforms, CRM systems, or other third-party applications.
For example, an automated appointment reminder workflow may retrieve a patient's name, appointment details, provider information, medical record number, or other relevant information from an EHR before generating an email. Depending on how the integration is configured, some of this information may also be captured in application logs, message records, databases, backups, or troubleshooting systems.
This is important under HIPAA because the Security Rule requires covered entities and business associates to protect electronic protected health information (ePHI) that they create, receive, maintain, or transmit. HHS, under the Risk Analysis Guidance, recommends identifying where ePHI is located and how it moves through an organization as part of its risk analysis.
As a result, organizations assessing an email integration should look beyond the EHR and the recipient's inbox. The systems and services connecting the two, including APIs, integration platforms, email infrastructure, logs, and storage environments, may also need to be considered when determining where PHI is handled and what safeguards are required.
Third-party platforms can become part of the PHI environment
Many email integrations rely on third-party services. For example, a healthcare organisation might use a separate service for:
- email automation
- appointment reminders
- marketing communications
- customer relationship management
- email delivery
- message archiving
- workflow automation
- cloud storage
If the third-party service creates, receives, maintains, or transmits PHI on behalf of a covered entity, it may qualify as a business associate under HIPAA. HHS specifically identifies HIE organizations, health information networks, e-prescribing gateways, healthcare application developers, and cloud service providers as examples of organizations that may qualify as business associates when they handle PHI on behalf of covered entities. This means that connecting an email system to another platform should not be treated purely as an IT configuration exercise. The organization also needs to understand the contractual and compliance implications of giving another service access to PHI.
How integration can expand access to PHI
Integrations typically require permissions. An application may need permission to read information from an EHR, retrieve patient contact details, create messages, or send emails on behalf of users. The more permissions an integration receives, the greater the potential impact if the integration account, API credentials, or connected application is compromised.
For example, an organization may intend for an integration to access appointment information only. If the integration is instead given broad access to an entire patient record, a compromise could expose substantially more information than the workflow actually requires.
This is why access should be limited to what the integration needs to perform its intended function.
Email integrations can expose more information than intended
Another concern is data minimization. An integration may have access to substantially more information than the email actually needs.
For instance, an appointment reminder may only require:
- Patient name
- Appointment date
- Appointment location
Sending unnecessary PHI through an integration increases the amount of sensitive information that could potentially be exposed if the integration or one of its connected systems is compromised.
This principle is consistent with HHS guidance on email communication, which notes that when unencrypted email is used, providers should consider limiting the amount or type of information disclosed.
The same concept can be applied to integrations: only the information required for the workflow should be made available to it.
Read also: A guide to HIPAA's minimum necessary standard
Cloud services require additional consideration
Many modern email integrations rely on cloud infrastructure. In fact, the HHS states that “provided the covered entity or business associate enters into a HIPAA compliant business associate contract or agreement (BAA) with the CSP […] and otherwise complies with the HIPAA Rules.” This means a healthcare organization can use a cloud service to store or process electronic protected health information (ePHI), but the organization must meet the applicable HIPAA requirements. When the cloud service provider (CSP) creates, receives, maintains, or transmits ePHI on behalf of the covered entity or business associate, the CSP generally qualifies as a business associate, and a BAA is required.
HHS also recommends that organizations understand the specific cloud environment they are using so they can conduct an appropriate risk analysis and establish suitable risk-management measures. This is particularly relevant to email integrations, where a cloud-based third party may process or store PHI as information moves between an EHR and an email platform.
Read also: All about cloud email services
How to reduce the risk of PHI exposure
Healthcare organizations can reduce the risk of PHI exposure by taking a closer look at how information moves through email integrations. Start by mapping what PHI is shared, which systems and third-party services can access it, where it is stored, and how long it is retained. Integrations should use the minimum data and permissions necessary for their intended purpose.
Using a secure email solution such as Paubox can add another layer of protection when PHI needs to be communicated by email. Paubox encrypts email in transit without requiring patients to log in to a separate portal, helping healthcare organizations protect sensitive information while maintaining a familiar email experience. Organizations should still configure their email environment appropriately and ensure that any vendors handling PHI have the necessary contractual safeguards, including a BAA.
Strong access controls, authentication, encryption, logging, and monitoring can further limit unauthorized access. Automated workflows should also be tested regularly to ensure messages are sent to the correct recipients and do not include unnecessary PHI.
Finally, email integrations should be included in the organization's HIPAA risk analysis and reviewed whenever systems, vendors, permissions, or workflows change. This helps ensure that new connections do not create unmanaged pathways through which PHI could be exposed.
See also: HIPAA Compliant Email: The Definitive Guide (2026 Update)
FAQS
Does an email integration need a BAA?
It depends on the service and how it handles PHI. If a third-party provider creates, receives, maintains, or transmits PHI on behalf of a covered entity, it may be a business associate and require a BAA.
Does encryption make an email integration HIPAA compliant?
No. Encryption is an important security measure, but HIPAA compliance involves broader administrative, physical, and technical safeguards. HHS also notes that a cloud provider handling encrypted ePHI can still qualify as a business associate.
