HIPAA Compliant Email

The Private Medical Practice Academy

HIPAA Compliant Email

January 11, 2022

HIPAA Compliant Email

We send and receive email every day so  it would seem natural to send emails to your patients. But what if the emails contain protected health information? How do you make email HIPAA compliant?

How you will use email with protected health information

The first questions to ask are, “Is my email network is behind a firewall?” Are you only emailing protected health information between you and your staff within the confines of the firewall? If you answer yes to both questions, then you don’t need to encrypt your emails. But, you do need access controls for email accounts so that only those individuals who are authorized have access to protected health information.

On the other hand, if you intend to use email to send protected health information externally, you are responsible for protecting the protected health information—in other words, making it HIPAA compliant.  Encryption is the key to making your email HIPAA-compliant but it’s not that simple. Many email service providers that offer an encrypted email service are not HIPAA compliant because they do not incorporate all the necessary safeguards to meet the requirements of the HIPAA Privacy and Security Rules. 

 Here are some of the things you will want to consider to make your email is HIPAA compliant 

  • Ensure you have end-to-end encryption for email
  • Enter into a HIPAA-compliant business associate agreement with your email provider
  • The most important step—Develop policies on the use of email and train your staff
  • Emails containing PHI need to be retained for 6 years
  • Secure, encrypted email archiving saves storage space and is indexed making its easier to search
  • Obtain consent from patients before communicating with them by email

HIPAA email compliance should be included in your compliance plan. You don’t want something we all do every day—send and receive emails to get you into HIPAA trouble. If you are unsure of the requirements of HIPAA compliant speak with a healthcare attorney that specializes in HIPAA to advise you of your responsibilities and the requirements of HIPAA with respect to email.

You can join me in  The Private Medical Practice Academy membership to how to maximize your practice's success.

For a full searchable copy of the transcript,
If you'd like to hear more tips on how to start, run and grow your practice and related medical businesses, please sign up for my newsletterat   
Be sure to join my FB group, The Private Medical Practice Academy to be part of a community interested in starting, running and growing their private medical practices and leveraging them into multiple revenue streams.

You may also like

Top Health Podcasts. Delivered to Your Inbox and Eardrums.

Join Our Newsletter

We gratefully acknowledge the many organizations that have generously supported our podcasts and platform.

Network Sponsors and Advertisers

Event and Media Partners

Buffer LinkedIn WhatsApp