Skip to sign in Skip to content

Compliance

Do you need to pay for HIPAA-compliant email?

Do you need to pay for HIPAA-compliant email? Learn what HIPAA requires, why encryption alone isn’t enough, and when a paid service makes sense.

Estimated reading time: 6 minutes.

Summarize with ChatGPT
 

TL;DR: You don't necessarily have to replace free Gmail or Outlook, but you do need a solution that helps you meet HIPAA requirements, including a Business Associate Agreement (BAA), appropriate safeguards, and secure handling of protected health information (PHI).

With so many free email services available, do you really need to pay for one for your therapy practice?

Free tools like Gmail and Outlook are familiar and easily accessible. Maybe that's what you're using right now. They seem easier than a paid healthcare-specific provider.

But you wonder: Am I accidentally putting myself at risk? Maybe you've heard your email isn't HIPAA-compliant. A friend told you that all you need is encryption. But after spending hours reading conflicting advice online, you're still not sure what's actually required.

The good news: Becoming HIPAA-compliant doesn't necessarily mean replacing the free email service you already use.

Depending on the solution you choose, you may be able to keep your current email for everyday communication while using a HIPAA-compliant service when handling protected health information (PHI).

Here's what you need to know.

What HIPAA actually requires from email providers

It's easy to think that encryption is the only must-have for keeping your email communication HIPAA-compliant. But it's just one of many requirements.

Your email provider stores and transmits the contents of your emails, including any protected health information (PHI) you send. Because it handles PHI while providing its service, your email provider is considered a business associate (more on this below).

As such, it has to put in place reasonable safeguards to protect PHI from unauthorized or inappropriate access, use, or disclosure.

In addition to encryption, some of the other technical safeguards required for email communication include:

  • Access control. Only the right people should be able to access client information.
  • Audit controls. Maintain a record of who accessed sensitive information and when.
  • Integrity. Client information should be protected from unauthorized changes or deletion.
  • Transmission security. PHI should be protected while it travels from your inbox to your client's inbox.
  • Authentication. The system should confirm that the person signing in is really who they say they are.

As you can see, encryption is only one of many safeguards. HIPAA allows flexibility in how you protect PHI, but requires reasonable safeguards from you and your business associates.

What is a Business Associate Agreement (BAA)?

A key part of HIPAA compliance is having a signed Business Associate Agreement (BAA) from any vendors that handle PHI, including your email service provider.

This signed document is a formal agreement between a healthcare provider and the vendor. In it, the vendor agrees to protect PHI and outlines what happens in the event of a breach.

A BAA is more than paperwork, though. It represents accountability and shared responsibility for protecting sensitive information. Business associates (such as your email service) of covered entities (such as therapists) are directly responsible for compliance with certain requirements of the HIPAA Rules.

This is one of the biggest differences between free personal email accounts and business email services designed for healthcare.

While business versions of services such as Google Workspace and Microsoft 365 may offer BAAs under certain plans and configurations, free personal Gmail and Outlook accounts do not.

Why encryption alone is not enough

Many email providers already encrypt messages in transit, when an email is actively traveling from your computer to your client's inbox.

Encryption is important, but it's only one of many important safeguards. As mentioned earlier, HIPAA compliance also depends on:

  • BAAs
  • Administrative controls
  • Account management
  • Handling of PHI
  • Ongoing risk management

As a healthcare provider, you're responsible for conducting a risk analysis to evaluate whether the tools you use protect PHI appropriately. That includes understanding what safeguards your email provider offers and whether they fit your practice.

Why archives and retention matter

Even after you've sent an email, there's good reason to keep a record of it.

Email archiving is the practice of securely storing every email message so you have a complete record if you need it later.

For healthcare providers, secure email archiving can help support HIPAA documentation requirements, legal requests, and continuity of care.

  • HIPAA has specific documentation and retention requirements.
  • Retaining records matters even after retirement, closing a practice, or when a client stops seeing you.
  • You may need to provide records for a regulatory or insurance audit, or to fulfill a legal request.
  • If a client switches to another practitioner, good records allow for an accurate transfer of information for continuity of care.
  • You may want to review historical communication to facilitate ongoing client care.

A HIPAA-compliant provider can help you securely archive messages and retain important records, making it easier to meet documentation requirements and access information when you need it.

What are healthcare providers actually paying for beyond encryption?

HIPAA-compliant communication involves multiple layers of protection working together behind the scenes.

When you pay for a HIPAA-compliant service, you're paying for more than just email features. You're paying for safeguards designed to support your HIPAA compliance.

You're also paying for the confidence, convenience, and support that come from using a solution designed for healthcare.

The infrastructure needed to properly handle PHI under HIPAA rules can give you benefits such as:

  • The peace of mind that sensitive information is securely protected
  • Assurance that archival records will remain accessible and secure as long as you need them
  • Easier communication with clients
  • Confidence that a BAA is already in place
  • Help from people who understand healthcare
  • Less time worrying about compliance and more time focused on client care

Why free email accounts usually fall short

As enticing as free email can be, most free consumer email accounts have practical limitations for use in your therapy practice:

  • No BAA
  • Limited administrative oversight by the service provider
  • Personal and shared accounts risk allowing unauthorized access by third parties
  • Fewer (if any) compliance-focused controls, like access and audit controls
  • Not designed specifically for healthcare workflows
  • Weaker retention and documentation support

A free personal email account alone isn't enough when you're handling PHI. You need a service that can provide a BAA and the safeguards your practice requires.

Do you need to replace your existing email?

If you've been using a free email service, don't worry! Becoming HIPAA-compliant doesn't necessarily mean abandoning the tools you already use.

Many mental health practitioners choose a secure messaging platform, like Hushmail, that works alongside their existing email.

This lets you use a free service, such as Gmail or Outlook, for non-sensitive communication, like arranging the office cleaning schedule. Then you can log in to the HIPAA-compliant secure messaging platform when your message is client-related and so needs extra security.

HIPAA-compliant communication involves multiple layers of protection working together

Choosing the right email or secure messaging service is an important step. But it's only one part of HIPAA compliance.

You still need to:

  • ✔️ Evaluate your email service provider. Read the BAA carefully, along with any available documentation on how it maintains HIPAA compliance. Make sure these align with the requirements.
  • ✔️ Do a risk analysis. HIPAA requires you to conduct a risk analysis and review risks as your practice and technology change. Your email service should be included in your review.
  • ✔️ Understand your own responsibilities. You still need appropriate policies, procedures, and safeguards in your practice.

👉 Review our HIPAA compliance checklist for a simple overview of the steps to consider in your practice.

Communicating with clients involves more than email. You also need to think about how you collect information, share documents, gather signatures, and protect sensitive data throughout the client journey.

Protecting sensitive client information doesn't have to mean replacing all the tools you already use. The right solution should make secure communication simpler, so you can spend less time worrying about compliance and more time caring for your clients.

A HIPAA-compliant secure messaging and forms service like Hushmail can help protect private client information without complicating communication.

Reviewed by: Steven O. Youngman, VP of Legal and Compliance, Hushmail.

Similar posts