According to an article published in Health Services Research and Managerial Epidemiology, “Electronic health records (EHRs) are the electronic records of patient health information created during ≥1 encounter in any health care setting.” This can include diagnoses, prescriptions, test results, treatment plans, or billing. When organizations export this data for referral or patient follow-up, the email system assumes risk by transmitting electronic protected health information (ePHI). By using HIPAA compliant email, providers can safeguard EHR-created reports, summaries, and attachments as they transfer out of the EHR, minimizing risks in the overall communication flow.
A JAMIA Open review from 2025 defines secure messaging as “asynchronous text-based communication between patients (or their care partners) and their healthcare team through the patient portal.” While EHR messaging typically occurs within a single healthcare organization or patient portal, email can be sent to patients, caregivers, laboratories, pharmacies, and outside providers who will not have access to the same system. Using HIPAA compliant email allows for a safeguarded connection across these systems. Healthcare professionals are able to transmit communications and attachments to designated recipients, bypassing the need for an EHR login.
Encryption protects information after it leaves the EHR
A 2022 healthcare data security study stated that, “Encryption is the process of transforming information into a code that is only known to a select few, hence concealing the information’s actual meaning.” Encryption takes plaintext that anyone can read and converts it into ciphertext that cannot be understood without the appropriate key. If a hacker intercepts an encrypted email with an EHR summary attached, the strong encryption can help prevent them from reading that clinical information. Providers can send records, instructions, or supporting documents to an authorized recipient using encrypted email with confidence.
“Encryption is commonly used to protect data in transit and data at rest,” according to another security and privacy paper. Data in transit describes information as it moves from one system to another, such as an attachment traveling from an EHR-connected mailbox to a specialist. Data at rest may include copies of that message stored in sent folders, recipient inboxes, archives, or backup solutions. A HIPAA compliant email environment can protect both to prevent EHR-derived information from being exposed just before or after delivery.
The standards used to protect EHR-related email
The National Institute of Standards and Technology (NIST) states, “Transport Layer Security (TLS) provides mechanisms to protect data during electronic dissemination across the Internet.” TLS allows browsers and servers to create an encrypted connection while email is being transmitted. Recent revisions to NIST standards require federal systems to use appropriately configured TLS 1.2 and TLS 1.3, although HIPAA does not mandate any specific version of TLS. Healthcare organizations can use those options as a benchmark for modern security and confirm their email service authenticates certificates and reduces the risk of delivery over obsolete protocols.
Advanced Encryption Standard (AES) is commonly used to encrypt data at rest. NIST states that its Encryption Standard specifies AES-128, AES-192, and AES-256. The number refers to the length of the cryptographic key used with that algorithm. While AES is widely used to provide strong encryption, the use of a particular algorithm alone does not establish HIPAA compliance or prove that an entire email environment is secure. Key storage, access permissions, backups, and system configuration also influence the protection patients receive. Providers can request this information from email vendors to learn how messages, attachments, archives, and keys are secured.
Opportunistic TLS attempts to establish an encrypted connection but may fall back to plaintext delivery when encryption cannot be negotiated with the receiving server. According to a Paubox data brief from 2026, none of the breached organizations reviewed used MTA-STS, a policy that blocks this silent fallback. Healthcare organizations can configure email to insist on available TLS or queue messages for alternate protected delivery if a connection cannot be secured.
What HIPAA currently requires
According to the HHS, “The Security Rule does not expressly prohibit the use of email for sending e- PHI.” The current language requires access controls, integrity protections, and transmission security. Encryption is currently an addressable implementation specification. Addressable specifications do not mean an organization can avoid implementing encryption. Instead, providers must evaluate if encryption is reasonable and appropriate, adopt it when that determination is true, or document their reasoning when another option sufficiently mitigates the risk.
HHS released a proposed rule which would mandate encryption of ePHI at rest and in transit. The proposed rule would require encryption of ePHI at rest and in transit, subject to specific, limited exceptions. According to HHS’s rulemaking page, “While the Department is undertaking this rulemaking, the current Security Rule remains in effect.” As of September 2026, the proposal has not been finalized, and HHS states that the current Security Rule remains in effect. HIPAA compliant email solutions that encrypt all data can reduce the implementation work needed if this proposal becomes final.
Secure referrals and care coordination
Researchers in a Journal of Qualitative educational outreach study observed that, “A secure provider to provider EHR messaging tool offers the opportunity to reduce fragmentation and create efficiencies.” HIPAA compliant email can provide similar benefits when sending information beyond providers who use the same EHR. A referral coordinator can send an encrypted care summary, diagnostic report, and list of medications to a verified specialist while retaining a record of the exchange in the patient’s EHR. This has the potential to limit follow-up calls and allow the receiving provider to access key information ahead of the patient’s appointment.
A BMC study found that “This study highlights the potential of patient portal messaging as a tool for care coordination to enhance chronic disease self-management.” Providers who adopt HIPAA compliant email can extend this benefit to patients who communicate outside of the portal. Following a telephone conversation, email can deliver follow-up instructions, care-plan changes, or notification that results are available. Providers have the space to identify the subject of the message, explain the next steps, and tell patients to contact a clinical channel for urgent concerns.
Connecting automated messages to the correct record
Researchers integrated EHR-accessible secure messaging into one organization’s portal and analyzed over 9.6 million messages. They found that 69% of messages were associated with a specific patient chart. Automatically connecting a communication to the correct record can provide clinicians with immediate context and allow for complete documentation. When implemented by the organization’s EHR, automated emails triggered by the EHR can contain controlled information, use verified recipient information, and return replies or delivery records to designated users. Consequently, manual copying might become unnecessary, and it would be simpler to see what data was sent and received.
Default encryption reduces reliance on memory
Researchers analyzed 1,485 healthcare breach events occurring between 2015 and 2020 and found that 73.1% of affected records resulted from breaches caused by unintentional factors. Paubox surveyed healthcare IT leaders and discovered that 60% of respondents said their organization experienced accidental PHI exposure through email. Only 54% of respondents always encrypt outbound email containing PHI. Default encryption removes the need for employees to remember to secure every EHR-related email. Recipient validation and data loss prevention rules are still necessary because encryption does not stop a message from reaching the wrong authorized user.
FAQs
Can a patient request an unencrypted copy of their medical records by email?
Yes, a provider generally must honor this access request after briefly warning the patient about the transmission risk and confirming that the patient still wants unencrypted email.
Does a provider need a patient’s authorization before emailing another provider for treatment?
Generally, no, because HIPAA permits provider-to-provider treatment disclosures without authorization when reasonable safeguards are applied.
Does encryption remove the minimum necessary requirement?
No, encryption protects the information but does not change limits on how much PHI may be used or disclosed when the minimum necessary standard applies.
Does encrypted email automatically qualify for HIPAA breach-notification safe harbor?
Only appropriately encrypted ePHI whose confidential process or decryption key was not compromised may qualify as secured PHI under HHS guidance.
