HIPAA compliant email solutions
Choose a solution below to get started:
How many senders do you have?
1
10
20
30
40
50+
STANDARD
HIPAA compliant email
$00/month
1 sender
Everything you need to send HIPAA compliant emails with Google Workspace or Microsoft 365.
14 day free trial included
14 day free trial included
100% HIPAA compliant email
Every outbound email encrypted automatically
Works with Google Workspace and Microsoft Outlook
No portals or passwords needed for recipients
Compare all features >
PLUS
HIPAA compliant email + email security
$00/month
1 sender
HIPAA compliant email with
inbound email protection against spam, ransomware, and phishing attacks. Powered by AI.
14 day free trial included
14 day free trial included
Everything in Standard, and:
Prevent display name spoofing attacks with ExecProtect+
Malware and virus protection
Prevents spam, ransomware, and phishing attacks
Automatically transcribe audio attachments in email
Compare all features >
PREMIUM
HIPAA compliant email + email security + archiving & DLP
$00/month
1 sender
HIPAA compliant email with archiving and data loss prevention features.
14 day free trial included
14 day free trial included
Everything in Standard & Plus, and:
Search, view, and export archived emails
Unlimited storage for inbound and outbound email
Blocks emails with sensitive data, including in attachments
Customize filtering options to stop unauthorized data from leaving the organization
Compare all features >
|
Compare all
Paubox offerings |
|||
|---|---|---|---|
| HIPAA email compliance | |||
|
HIPAA compliant email encryption
All outbound email is automatically encrypted by default |
|
|
|
|
Securely send protected health information (PHI) via email
Patented blanket TLS encryption ensures that PHI sent via email is always encrypted. |
|
|
|
|
Works with Google Workspace and Microsoft 365
Add on Paubox to Google Workspace and Microsoft 365, using your existing account |
|
|
|
|
Emails delivered directly to the inbox
Seamless delivery without portals, passwords, or plug-ins |
|
|
|
|
Send secure calendar invites
Send secure, HIPAA compliant calendar invites directly from Microsoft Outlook and Google Workspace. No plugins or apps to install. |
|
|
|
|
Domain-level email protection
Automatically add new senders on your domain to ensure compliance |
|
|
|
|
Optimized email deliverability
Maximizes email deliverability and avoids outbound email ending in spam folders by updating your SPF record and configuring DKIM and DMARC protocols. |
|
|
|
|
Encryption certificate verification
Prevents emails sent to domains with expired or self-signed encryption certificates to ensure email is delivered with proper encryption. |
|
|
|
| Inbound email security | |||
|
Advanced phishing, malware, virus, and BEC detection
Identifies and blocks sophisticated attacks, including credential theft, malicious payloads, and business email compromise attempts that often bypass other filters. |
|
|
|
|
Spam detection and filtering
Automatically identifies and filters unwanted or low-risk emails to reduce inbox clutter and help users focus on legitimate messages. |
|
|
|
|
AI analysis of sender behavior and intent
Uses behavioral signals and context to evaluate how an email is written and sent, not just what it contains, helping catch socially engineered threats. |
|
|
|
|
Display name spoofing protection with ExecProtect+
Prevents attackers from impersonating executives or trusted contacts by detecting deceptive display name and sender identity tactics. |
|
|
|
|
Identify safe senders with Paubox [Tags]
Automatically labels trusted senders so users and admins can quickly distinguish legitimate emails. |
|
|
|
|
Malicious link and attachment analysis
Scans links and attachments in real time to detect phishing destinations, malware, and harmful file behavior before delivery. |
|
|
|
|
QR code scanning
Inspects QR codes in attachments, inline images, and embedded graphics for malicious payloads. |
|
|
|
|
Customizable rules for specific domains, IP addresses, or keywords
Allows admins to define tailored rules to flag, allow, or block emails based on known senders and sources. |
|
|
|
|
Clear detection explanations for quarantined messages
Provides human-readable explanations showing exactly why a message was flagged, so admins can review decisions with confidence. |
|
|
|
|
Quarantine reporting and management
Gives admins control over how quarantined messages are reviewed and delivered, including automated reports, mailbox routing, and user access options. |
|
|
|
| Support | |||
|
Help center
Learn how to use Paubox products quickly with concise how-to articles, and step-by-step instructions. |
|
|
|
|
U.S.-based support team availalble by chat, phone, or email
Our customer success team is available by phone for extended hours, Monday through Friday, to assist with any technical or support issu our customers might have. |
|
|
|
| Data loss prevention | |||
|
Outbound and inbound DLP
Scans both sent and received emails for sensitive content to help prevent accidental data exposure and policy violations. |
|
||
|
Custom keyword and content-based rules
Lets admin define specific keywords or content patterns to quarantine emails based on organizational needs. |
|
||
|
Admin and compliance role notifications
Notifies designated admins or compliance users when emails are flagged by DLP, without requiring full administrative access. |
|
||
|
Sender quarantine notifications for DLP violations
Alerts the sender when an outbound email is quarantined due to a DLP rule, helping them quickly understand and correct the issue. |
|
||
|
Excluded users for outbound DLP scanning
Allows specific senders to be excluded from outbound DLP rules while keeping inbound scanning in place. |
|
||
| Archiving | |||
|
Unlimited archive storage
Archiving costs do not increase based on the number of emails stored or retained. |
|
||
|
No additional cost for volume
Archiving costs do not increase based on the number of emails stored or retained. |
|
||
|
Inbound & outbound mail archive
Automatically archives both incoming and outgoing emails for complete recordkeeping. |
|
||
|
Automatically enroll new email senders
New users and senders are added to archiving automatically, with no manual setup required. |
|
||
|
Archived mail search
Enables fast, searchable access to archived emails for audits, compliance requests, or internal review. |
|
||
| Additional Features | |||
|
HIPAA compliant forms
Create secure, customized HIPAA compliant forms to collect patient data, signatures, and attachments. Included free with all paid plans. |
|
|
|
|
Voicemail and audio file attachment transcription
Automatically transcribe audio attachments in email |
|
|
|
|
Salesforce CRM integration
Securely send HIPAA compliant email from Salesforce CRM. |
Optional add-on
|
Optional add-on
|
|
| Dashboard access | |||
|
Dashboard access for admin and users
Admin access to manage accounts and settings, and user level access to view user settings and quarantine |
|
|
|
|
SSO options to access dashboard
Login with Google Workspace or Microsoft 365 accounts |
|
|
|
|
Multi-factor authentication
Require authentication beyond a username and password when logging into your Paubox account. |
|
|
|
|
Real-time analytics
Comprehensive email analytics, mail logs, ruleset access, and quarantine. |
|
|
|
|
Email reports
Daily or weekly email reports on usage, analytics, patterns, and alerts sent directly to your inbox. These reports make it easy to quickly demonstrate value to upper management. |
|
|
|
| Compliance and security | |||
|
HIPAA compliant
Maintain the highest privacy and data protection with third party audits against HIPAA regulations. |
|
|
|
|
HITRUST certified
Safeguard your data with Paubox Email Suite, which has been HITRUST certified for its rigorous controls. |
|
|
|
|
Business associate agreement
Under HIPAA, organizations that use a service provider to process PHI on their behalf must put in place a business associate agreement with that service provider. Paubox includes BAAs with all accounts. |
|
|
|
|
TLS protocols 1.2 & 1.3
As per NSA guidance, Paubox supports only TLS 1.2 and TLS 1.3. The following obsolete protocols are not supported: SSL 2.0, SSL 3.0, TLS 1.0, and TLS 1.1. |
|
|
|
|
U.S. data centers
Rely on our cloud-based, redundant infrastructure with 99.99%, uptime. Customer data is stored encrypted at-rest and solely in U.S data centers. |
|
|
|
Customer success stories
“Getting onboarded with Paubox was actually amazing – probably the easiest product, and some of the best folks I have ever worked with.”
Tony Cox, Henderson Behavioral Health
“I was blown away by the customer service that I had when
I talked to folks at Paubox and really that was kind of the selling feature for me.”
Gretchen Murchison, Sunrise LCSW
“We were so used to our encryption and security technology being hard to use. With Paubox, you don’t have to do anything – just send and receive your email. It’s amazing."
Elena Yau, Five Acres
Every plan includes:
U.S.-based support
Top ranked support that you can contact via phone or email.
Signable, encrypted forms
Save over $1,000 per year using our HIPAA compliant forms, free with any paid plan.
Business associate agreement
Paubox includes a BAA with all accounts.
HITRUST certified
Certified by a third-party for HIPAA compliance and security.
Secure calendar invites
Avoid common HIPAA compliance violations.
Complimentary setup
We’ll help you get your HIPAA compliant email set up.
$250 referral credit
Get $250 credit for every referral you send our way.
$100 off with a Paubox badge
Get $100 off your renewal for adding a Paubox Badge to your website.
Optimized email delivery
Maximize deliverability so your important messages don’t go to spam.
Frequently asked questions
Not finding what you’re looking for? Contact us and we’d be happy to answer any additional questions!
What makes Paubox better than other solutions?
Paubox is designed for ease-of-use, both for senders and recipients alike. Paubox eliminates unnecessary friction while also maintaining compliance. Portal logins, plugins and app downloads are a thing of the past with Paubox.
Which email hosts work with Paubox?
Paubox works with Google Workspace, Microsoft 365, and Microsoft Exchange. Be sure your email host provides a business associate agreement.
Can I keep my email address?
Yes! If you have a business email address that ends in your business domain (like @yourbusiness.com), you can keep it. Paubox integrates with Google Workspace, Microsoft 365 and Microsoft Exchange.
If I have a Google Workspace or Microsoft 365, why do I need Paubox?
Google and Microsoft will both sign business associate agreements in connection with their email platforms, but those agreements only cover emails within their servers and at rest. Paubox ensures your emails are secure in transit outside of their servers.
How do my recipients know my email is encrypted?
Every email includes a message in the footer identifying that Paubox secured the email. Additionally, recipients can look at the header and see that each relay was secured with up to 256-bit AES encryption.
What if I don't have a business email address?
If you use a consumer email provider, like @gmail.com or @yahoo.com, then you need a business email in order to be HIPAA compliant. Consumer solutions are not compliant and should not be used.
What happens if the recipient’s email system doesn’t support TLS encryption?
If a recipient's mail server is not setup to handle TLS encryption, Paubox automatically uploads the email (including attachments) to our secure webapp. In order for the recipient to view your message, it's only one additional click.
Can I use my smartphone with Paubox?
Yes, you can use your smartphone and your favorite email apps.
Paubox can also easily be setup on tablets and smartwatches with no proprietary apps or downloads needed.
Paubox can also easily be setup on tablets and smartwatches with no proprietary apps or downloads needed.
Are my attachments encrypted?
Yes, all attachments are encrypted. Paubox supports attachments up to 50MB.
Are replies to my emails encrypted?
Yes. By default, replies to your emails are encrypted in transit.
Are there any fees for a business associate agreement?
No. All customers receive a business associate agreement at no additional charge.
What is a sender?
A sender is defined as one email address such as you@yourcompany.com.

