Any identifiable health data gathered via a wellness initiative within a HIPAA covered group health plan must be secured. These safeguards also apply to internal emails.

The review Patient Privacy in the Era of Big Data illustrates the information at issue, “Protected health information (PHI) is the intersection of health information (HI) and personally identifying information (PII).”

It means a wellness coordinator should check if the information being shared connects to a particular employee's health status. An email detailing an individual's screening outcomes might warrant greater scrutiny compared to a general invitation for a step challenge. It really depends on the nature of the wellness program.

 

Check how the wellness program is organized

The journal article Voluntary workplace genomic testing: wellness benefit or Pandora’s box? explains, “If the employer’s health plan is administering the workplace wellness program, HIPAA’s Privacy Rule would apply.”

Before you send out those registration emails or progress updates, confirm if the wellness challenge is managed by the health plan or provided directly by the employer. HHS provides specific guidance on workplace wellness to clarify this. Health information collected directly by an employer through a wellness program outside its group health plan is generally not protected by HIPAA, although other federal or state laws may apply.

Healthcare professionals involved in the challenge are also subject to HIPAA regulations. Even if your employees go to a screening clinic, their records remain protected by HIPAA and aren't automatically shareable with HR simply because you organized the event. Also, take care to make note of who will be sending what type of emails when you develop an email schedule for your challenge.

 

Choose recipients before sharing results

When sending wellness emails, staff must be taken into account. The method you use to distinguish these individuals from one another serves as your administrative safeguards. Administrative safeguards include policies and procedures governing which staff may access PHI and for what purposes. When an employer receives PHI to administer a group health plan, it must meet the applicable requirements for plan documents, access restrictions, and safeguards. That access does not permit the information to be used for employment-related decisions.

The principle also applies to selecting who receives the information. Ensure an individual's results are sent to them and any other authorized parties. Before directing employees to a shared wellness inbox, verify who has access to it. Do not copy a manager solely because they helped organize the challenge; sharing PHI with them must have a permitted basis.

 

A clinician may send an employee their screening results and follow-up instructions. A manager coordinating time off may need scheduling information without needing the screening results. Determine what each individual requires and the rationale behind it.

 

Review leaderboards before sending them

The review Access and Disclosure of Personal Health Information: A Challenging Privacy Landscape in 2016-2018 observes, "The line between privacy protection of personally identifiable information and aggregate data is blurring as risks of re-identification increase.”

Even when you merge results or remove names, there's still a chance identifiable information could remain. Consider, for example, if an email detailed the weight loss of an employee who was the only one from their department participating in something. It would be possible to deduce who it was, even without the names.

HHS offers guidance detailing what counts as de-identified information, rendering it no longer PHI. Ensure you're clear on the steps taken to purge PHI from communications before you email your teams. Initials and job titles alone often fail to obscure a person's identity.

For a broad update, consider providing general motivation or a reviewed summary of the findings. Disclosing PHI, in line with the HHS privacy summary it necessitates either a valid reason for sharing or a completed authorization form from the subject. Just because someone joins a challenge doesn't mean you can share their progress updates with the entire team.

 

Build secure email into the program

Paubox's Healthcare Email Security Maturity Index 2026 surveyed 170 healthcare IT leaders and reported, "58% of respondents experienced at least one email-related data breach in the past 24 months.” The findings concern healthcare email generally and give wellness teams a reason to review the system used for personal communications before collecting information.

The journal article Email security in clinical practice: ensuring patient confidentiality explains, “Cryptography refers to processes for converting text from a readable to an unreadable format (‘encryption’) and back again (‘decryption’).” For a wellness program, encryption helps protect the contents of private messages as they move between systems.

Ask IT to explain how access to wellness emails and attachments is restricted. Ensure they tell you what safeguards they have in place for your messages and attachments and who can access them. Your process should allow you and the participant to easily follow up about any of their information.

See also: HIPAA Compliant Email: The Definitive Guide (2026 Update)

 

FAQs

Does an email provider need a business associate agreement (BAA) if it cannot read the encrypted messages?

Yes, a provider storing PHI on your behalf generally needs a BAA even without access to the encryption key.

 

Can employees request results at a personal email address?

Yes, employees can request an alternative contact address, which the provider or plan should review under HIPAA's confidential-communication requirements.

 

What should an organizer do after sending results to the wrong person?

Report the mistake promptly through the organization's privacy process so the team can contain it and assess any notification duties under HHS's Breach Notification Rule guidance.