Miami, FL

302-205-0504
All articles

Is my practice email HIPAA compliant?

Short answer: it depends on three things. Which email service you use, what you are actually sending, and whether you have documented what your patient chose. HIPAA does not ban email.

I am Scott Derby, I am an attorney. If you have asked five people whether your email is compliant, you have probably had five answers. Here is what actually matters.

HIPAA does not prohibit email. It requires you to protect patient information wherever that information travels, and email is no exception to that.

One: which email you use. A free personal account and a business account can look identical in your inbox. Under HIPAA they are worlds apart. Business-grade email where the provider will sign a business associate agreement can be part of a compliant setup. A free personal account generally cannot.

Two: what counts as patient information. This is broader than most people assume, and it is where practices are caught out. It is not only clinical notes. An appointment reminder carrying someone’s name, with your practice name in the signature, can qualify. If an email connects an identifiable person to your practice, treat it with care.

Three: what your patients prefer. There is a path for patients who simply want ordinary email. That path exists and it is legitimate. But it requires warning them about the risk and documenting that they chose it anyway. The documentation is the step almost everyone skips, and it is the step that protects you.

Get those three right and email stops being the grey area it usually gets treated as.

This is general information about federal HIPAA. It is accurate as of writing and it can change. Your state very likely has its own privacy rules that sit on top of HIPAA and can be stricter, so treat this as a starting point rather than the final word, and check what applies where you practice. This is education, not legal advice for your specific situation.