Estimated reading time: 6 minutes.
Summarize with ChatGPTTL;DR: You don't necessarily have to replace free Gmail or Outlook, but you do need a solution that helps you meet HIPAA requirements, including a Business Associate Agreement (BAA), appropriate safeguards, and secure handling of protected health information (PHI).
With so many free email services available, do you really need to pay for one for your therapy practice?
Free tools like Gmail and Outlook are familiar and easily accessible. Maybe that's what you're using right now. They seem easier than a paid healthcare-specific provider.
But you wonder: Am I accidentally putting myself at risk? Maybe you've heard your email isn't HIPAA-compliant. A friend told you that all you need is encryption. But after spending hours reading conflicting advice online, you're still not sure what's actually required.
The good news: Becoming HIPAA-compliant doesn't necessarily mean replacing the free email service you already use.
Depending on the solution you choose, you may be able to keep your current email for everyday communication while using a HIPAA-compliant service when handling protected health information (PHI).
Here's what you need to know.
It's easy to think that encryption is the only must-have for keeping your email communication HIPAA-compliant. But it's just one of many requirements.
Your email provider stores and transmits the contents of your emails, including any protected health information (PHI) you send. Because it handles PHI while providing its service, your email provider is considered a business associate (more on this below).
As such, it has to put in place reasonable safeguards to protect PHI from unauthorized or inappropriate access, use, or disclosure.
In addition to encryption, some of the other technical safeguards required for email communication include:
As you can see, encryption is only one of many safeguards. HIPAA allows flexibility in how you protect PHI, but requires reasonable safeguards from you and your business associates.
A key part of HIPAA compliance is having a signed Business Associate Agreement (BAA) from any vendors that handle PHI, including your email service provider.
This signed document is a formal agreement between a healthcare provider and the vendor. In it, the vendor agrees to protect PHI and outlines what happens in the event of a breach.
A BAA is more than paperwork, though. It represents accountability and shared responsibility for protecting sensitive information. Business associates (such as your email service) of covered entities (such as therapists) are directly responsible for compliance with certain requirements of the HIPAA Rules.
This is one of the biggest differences between free personal email accounts and business email services designed for healthcare.
While business versions of services such as Google Workspace and Microsoft 365 may offer BAAs under certain plans and configurations, free personal Gmail and Outlook accounts do not.
Many email providers already encrypt messages in transit, when an email is actively traveling from your computer to your client's inbox.
Encryption is important, but it's only one of many important safeguards. As mentioned earlier, HIPAA compliance also depends on:
As a healthcare provider, you're responsible for conducting a risk analysis to evaluate whether the tools you use protect PHI appropriately. That includes understanding what safeguards your email provider offers and whether they fit your practice.
Even after you've sent an email, there's good reason to keep a record of it.
Email archiving is the practice of securely storing every email message so you have a complete record if you need it later.
For healthcare providers, secure email archiving can help support HIPAA documentation requirements, legal requests, and continuity of care.
A HIPAA-compliant provider can help you securely archive messages and retain important records, making it easier to meet documentation requirements and access information when you need it.
HIPAA-compliant communication involves multiple layers of protection working together behind the scenes.
When you pay for a HIPAA-compliant service, you're paying for more than just email features. You're paying for safeguards designed to support your HIPAA compliance.
You're also paying for the confidence, convenience, and support that come from using a solution designed for healthcare.
The infrastructure needed to properly handle PHI under HIPAA rules can give you benefits such as:
As enticing as free email can be, most free consumer email accounts have practical limitations for use in your therapy practice:
A free personal email account alone isn't enough when you're handling PHI. You need a service that can provide a BAA and the safeguards your practice requires.
If you've been using a free email service, don't worry! Becoming HIPAA-compliant doesn't necessarily mean abandoning the tools you already use.
Many mental health practitioners choose a secure messaging platform, like Hushmail, that works alongside their existing email.
This lets you use a free service, such as Gmail or Outlook, for non-sensitive communication, like arranging the office cleaning schedule. Then you can log in to the HIPAA-compliant secure messaging platform when your message is client-related and so needs extra security.
Choosing the right email or secure messaging service is an important step. But it's only one part of HIPAA compliance.
You still need to:
👉 Review our HIPAA compliance checklist for a simple overview of the steps to consider in your practice.
Communicating with clients involves more than email. You also need to think about how you collect information, share documents, gather signatures, and protect sensitive data throughout the client journey.
Protecting sensitive client information doesn't have to mean replacing all the tools you already use. The right solution should make secure communication simpler, so you can spend less time worrying about compliance and more time caring for your clients.
A HIPAA-compliant secure messaging and forms service like Hushmail can help protect private client information without complicating communication.
Reviewed by: Steven O. Youngman, VP of Legal and Compliance, Hushmail.