In September 2025, St. John’s Riverside Hospital became aware of potential unauthorized access to a limited number of employee email accounts. The incident affected 2,238 individuals and may have involved personal information and protected health information (PHI), although the information varied by person.
It is because of cases like these that patients should not trust healthcare email solely based on whether a message is professionally worded or structured. Patients need to know that the sender is who they claim to be, the information is correct, and the organization has taken steps to secure the channel against intruders. A message is only credible if it appears accurate, transparent, and backed by information that is relevant to the reader. For healthcare organizations, building that trust is a careful, considered process. It also involves affirming patients’ beliefs that their personal information will stay private through protective measures and targeted messaging.
Why credibility matters in healthcare email campaigns
A 2021 NAM Perspectives paper from an independent advisory group of the National Academy of Medicine outlines ways to evaluate health information sources. While this perspective focuses on social media, it can also apply to emails.
The perspective states, “To maintain credibility, sources must clearly acknowledge the limitations of the information they share so that consumers can reach fully informed conclusions.” Additionally, they identify science-based information, objectivity, transparency, and accountability as foundational attributes of health information sources. Clinics can use these attributes by linking to evidence, identifying the clinician or department providing the information, and specifying when the information provided is not individualized medical advice.
Use reliable and current healthcare information
Claims made by healthcare organizations should be sourced from entities like the Centers for Disease Control and Prevention (CDC), the National Institutes of Health, peer-reviewed studies, or medical associations. Clinically, this process means that every claim or piece of content is supported by current clinical guidance and is within the scope of the organization’s practice.
For instance, an email campaign focused on getting vaccinated for the flu can hyperlink to current CDC guidance. Additionally, the email can include when the content was last reviewed and/or whether a clinician verified the content before publishing. When in doubt, providers can avoid presenting evidence as conclusive when it is still uncertain. Clinicians can state what is known, point out any applicable limitations, and advise patients to contact their healthcare professionals for personalized recommendations. It is part of the transparency best practice recommended by the NAM study.
Make the sender easy to recognize
Recipients need to know who sent the message immediately. Organizations can achieve this by including a familiar address, using the same name as the sender every time, and using recognizable branding elements and design in their campaigns. The message should also be clear about who from the organization sent the email. Was it the entire organization, a department, or an individual healthcare professional? An email can be from “Riverside Health Cardiology Team” instead of from a generic email address like “Health Updates.”
The healthcare organization’s street address, main phone number, privacy information, and website can live in the footer. Having this information provides the recipient with another opportunity to verify that the message is legitimate. Organizations should also not use misleading subject lines, overpromise results, or artificially create a sense of urgency. “Your updated diabetes education guide” is a better subject line than one that creates a sense of urgency without detailing the reasoning behind it.
Communicate consistently and respond promptly
Trust is something that is built over time. If an organization sends patients messages twice a week for several weeks and suddenly stops without notification, the inconsistent pattern may weaken the expectations established with recipients. Organizations can set expectations with patients by scheduling regular newsletters, educational series, follow-up campaigns, and letting people know what they will be receiving when signing up.
The 2022 qualitative study Factors Enhancing Trust in Electronic Communication Among Patients from an Internal Medicine Clinic: Qualitative Results of the RECEPT study took a look at how patients and caregivers felt trust was built through patient messaging and video visits. The study notes, “Promptness of reply was the most salient factor in trust formation with a majority desiring same day response.”
Protect patient privacy
If patients do not trust that their information will be kept private, they may be less likely to participate in healthcare communications. Privacy is part of an organization’s trustworthiness. In an analysis called Trust and Privacy: How Patient Trust in Providers is Related to Privacy Behaviors and Attitudes, researchers examined associations between patient trust, privacy attitudes, and information-sharing behavior. They wrote, “Patient concerns about the privacy of their data may be associated with nondisclosure of their information to providers.”
Organizations can address privacy concerns by being transparent about why they are collecting information, how they will use it, and how recipients can control their communication preferences. Healthcare organizations should avoid collecting more information than needed for the campaign and always ensure data collection, storage, and usage remain HIPAA compliant.
Personalize messages carefully
Personalization can help make an email more relevant. However, personalization requires correct information and thoughtful application of patient data. Healthcare organizations should double-check contact information, audience segments, and campaign rules before distributing communications. Sending different preventive care information based on age or documented eligibility is one example of personalization. But if a patient is placed in the wrong segment, they may receive irrelevant information or be inadvertently exposed to sensitive information intended for another individual.
Healthcare providers can test campaign logic, verify recipient email addresses, and create a review process for campaigns that include PHI. Patients should also be allowed to update preferences or unsubscribe from commercial messages. Commercial email campaigns are not automatically exempt from HIPAA. When a campaign uses or discloses PHI, the HIPAA Rules may apply. They may need to comply with both HIPAA and the CAN-SPAM Act.
The Federal Trade Commission notes that recipients have the right to unsubscribe from marketing emails, even if they received them as part of a subscription or membership program. Honoring these requests demonstrates to recipients that the organization respects their time.
Determine whether HIPAA marketing authorization is required
Healthcare organizations should determine the email campaign’s purpose before creating or sending PHI. Communications about treatment, care coordination emails, operationally related notices, and marketing emails may have different requirements.
According to the HHS, the HIPAA Privacy Rule generally requires authorization before using PHI or disclosing PHI for marketing purposes. There are limited exceptions to this rule, such as face-to-face communications or promotional gifts of minimal value. However, sending emails is not considered face-to-face communication and therefore does not fall under that exception.
Instead, organizations should determine if the campaign qualifies as marketing under HIPAA or another permissible purpose. When there is uncertainty about an email campaign’s purpose, privacy or legal teams should review it. Once a determination is made, providers should document it, secure valid authorization if needed, and ensure the email vendor can accommodate any PHI used in the campaign. This allows providers to comply with the law and appear credible to patients.
Correct errors transparently
Even thoroughly vetted campaigns can have an expired link, a confusing directive, or erroneous information. Healthcare organizations should include an obvious way for recipients to contact the organization if they need to send a complaint. Should there be an error that may impact a patient’s choice, the brand should issue a correction right away.
The follow-up message should identify the previous communication, explain what was incorrect, share the correct information, and clarify if any additional action is required from the recipient. If the correction includes protected health information that’s specific to the patient, healthcare organizations can utilize HIPAA compliant email. Additionally, team members should document the issue internally and update the approval process before the next campaign. Transparent corrections support the accountability principles we took into account in our Patient and Healthcare Perspective study, and they also limit outdated information from lingering.
How Paubox can help
With Paubox, covered entities can build customized HIPAA compliant email campaigns. Healthcare marketers can segment audiences, incorporate dynamic content, establish automated workflows, and send TLS-encrypted campaigns. Healthcare marketers can use one platform to manage relevant patient communications, campaign data, and engagement metrics without shifting PHI into a traditional marketing platform that is not built for PHI.
FAQs
Can an email comply with CAN-SPAM but still violate HIPAA?
Yes, because accurate sender information, a postal address, and an unsubscribe link do not give a healthcare organization permission to use PHI for marketing. The sender still needs a HIPAA permitted purpose or valid authorization and must apply appropriate privacy and security safeguards.
Can an email comply with HIPAA but still violate CAN-SPAM?
Yes, because HIPAA permission or authorization does not replace CAN-SPAM’s requirements for commercial messages.
Does a patient’s general consent to receive emails satisfy both HIPAA and CAN-SPAM?
CAN-SPAM generally does not require advance consent for commercial email, but HIPAA may require a specific written authorization before PHI is used or disclosed for marketing. A general consent to treatment or a patient’s failure to unsubscribe does not become a valid HIPAA marketing authorization.
Does a HIPAA marketing authorization replace the CAN-SPAM unsubscribe process?
No, because CAN-SPAM opt-outs and HIPAA authorization revocations are separate rights governed by different requirements.
What happens when an appointment reminder also advertises a discounted service?
CAN-SPAM examines the subject line, placement, and overall emphasis to determine whether the mixed message is primarily commercial.
