In this piece
Evaluate HIPAA compliant email across the whole handoff: mailbox access, delivery, attachments, and the copies recipients keep. A protected inbox is one part of that review. Start with a familiar process, such as a billing question that moves between a shared mailbox, a colleague, and a laptop.
Review how your organization protects ePHI at each step, including what happens after delivery. Use synthetic information to test the process before moving patient data.
Can you send PHI by email?
Yes, HIPAA permits email with appropriate safeguards. HHS explains that organizations must protect access, integrity, and transmission of ePHI, assess the available safeguards, and document their decisions. Its email security guidance is the starting point for evaluating a workflow.
Under the current Security Rule, encryption is an addressable implementation specification. Addressable does not mean optional: assess whether it is reasonable and appropriate, implement it when it is, and document the justification and an appropriate alternative when it is not. See the HHS Security Rule summary.
For a new deployment, make encryption in transit and at rest an evaluation baseline. Ask the provider to demonstrate how external delivery works, including what happens when a recipient’s mail service cannot accept the required protection.
Start with the service and BAA scope
A provider’s business associate agreement (BAA) should cover the service that will handle ePHI. HHS permits cloud services to store or process ePHI when the required BAA is in place and the parties otherwise comply with HIPAA. See HHS cloud computing guidance.
Before onboarding, list the features your team will actually use: email, contacts, calendar invitations, attachments, archiving, and mobile clients. Ask which are covered, which require configuration, and which connected services need a separate review. An email add-on that summarizes messages deserves its own entry in that inventory.
Our BAA review guide provides questions to bring to that conversation.
Test the daily work before moving mail
Use synthetic patient information in a pilot and walk through these scenarios:
- New employee: Individual account, role-based mailbox access, MFA, and recovery checks
- Shared inbox: Collaboration without shared passwords and actions attributable to individuals
- External delivery: Recipient notification, attachment access, and fallback behavior
- Wrong recipient: Prevention limits, recall limits, and an incident contact
- Departure: Access removal, session and forwarding checks, and record ownership transfer
Have the staff who handle billing, scheduling, and referrals run these practical acceptance tests. Their workarounds often reveal more than an administrator’s demonstration.
Evaluating a new inbox for your team? Request a healthcare email pilot with IRONKEEP to scope a billing or referral handoff using synthetic data. The workspace is in private beta; review BAA scope before introducing ePHI.
Treat patient communication as a separate workflow
HHS allows providers to communicate with patients by email with reasonable safeguards, such as verifying the address and limiting exposed information. It also discusses accommodating reasonable requests for alternative communication methods and explaining the risks of unencrypted email. Read the HHS patient email guidance.
Give staff a documented way to record those preferences and choose the appropriate channel. A patient’s willingness to use email should not become a blanket policy for internal mailboxes, vendor transfers, or bulk exports.
Follow the attachment after delivery
Transport protection does not control what an authorized recipient does with a downloaded file. Include downloads, synced folders, backups, and forwarded copies in the workflow review. Where a managed sharing workflow is appropriate, evaluate it alongside attachments using the HIPAA file sharing guide.
Keep a short operating record: the approved service configuration, who owns mailbox access, how staff report mistakes, and when the workflow was last tested. Make that record useful to the next person who has to administer the system.
Evaluate the healthcare workspace
Bring one inbox workflow, its intended recipients, and the acceptance tests above to your evaluation. Include the file-sharing steps that follow delivery so you can assess the whole handoff.
Scope your healthcare workspace.
Evaluate email, files and docs, and team access with IRONKEEP. Start with your workflow and BAA needs.