Practice management
Can you email a referral? What HIPAA allows when sharing PHI with other healthcare providers
Estimated reading time: 8 minutes.
You refer a client to another provider and send a brief clinical summary by email. Then you wonder: Was I allowed to do that? Should I have gotten authorization? Was email the right way to send it?
The Privacy Rule covers whether you're allowed to share PHI. The Security Rule covers how you protect it when you do. Most guides only address one side, which leaves the other half unanswered.
This post covers both: am I allowed to share this, and am I sending it safely? Once you see how each one works, the whole picture gets a lot clearer.
TL;DR:
- Yes. HIPAA generally permits you to share PHI with another provider for treatment purposes. Referrals are specifically included, and you don't need your client's authorization.
- But permission and protection are two different things. The Privacy Rule says you may share. The Security Rule still applies to how you send it.
- The other provider being covered by HIPAA doesn't make your email compliant. Their obligations begin when the information arrives, not while it's in transit.
- What matters on your end: a Business Associate Agreement (BAA) with your email provider, a service built to handle PHI, and care taken to send it to the right address.
- You don't need to stop emailing other providers. You need one secure channel for the messages that carry PHI.
Can you email PHI to another provider?
Yes, in many situations. HHS says the Privacy Rule allows providers to share PHI electronically for treatment purposes, as long as they apply reasonable safeguards.
And HIPAA defines "treatment" broadly. It covers coordinating or managing a client's care, consulting with another provider about a client, and referring a client to another provider. So when you email a clinical summary as part of a referral, that's one example of a treatment disclosure. The same permission applies whether you're consulting a psychiatrist about medication or coordinating follow-up with a primary care provider.
Many practitioners know they can share PHI with another provider for treatment purposes without the client's authorization. Your Notice of Privacy Practices (NPP) already tells clients you may do this.
Here's where it gets tricky. Because the sharing is permitted, it's easy to assume the method doesn't matter. That's the gap that catches people. Permission and protection are separate obligations under HIPAA, and being allowed to share doesn't mean any channel will do.
Does HIPAA's permission cover how you send it?
It's easy to assume that once you're permitted to share, the method is up to you. In other areas of practice, that's how it works. But HIPAA treats permission and protection as separate obligations.
HHS puts both obligations together: the disclosing provider is responsible for sharing PHI in a permitted and secure manner. That includes sending it securely and taking reasonable steps to send it to the right address.
So yes, you're allowed to share. And yes, you still need to think about how.
| Am I allowed to share this? | Am I sending it safely? | |
|---|---|---|
| Which rule? | The Privacy Rule | The Security Rule |
| Answer | Yes, for treatment purposes, including referrals | Depends on how you send it |
| Client authorization | Not needed | Reasonable safeguards expected |
| Key distinction | Answers whether disclosure is permitted | Answers how electronic PHI must be protected |
💡 What about psychotherapy notes?
Psychotherapy notes are the exception. They require your client's authorization even for treatment disclosures to another provider.
But the definition is narrower than most therapists assume. Diagnoses, treatment plans, symptoms, progress, medication information, and session start and stop times are all specifically excluded from the definition of psychotherapy notes. So the clinical summary you'd normally send in a referral doesn't fall under this exception. Psychotherapy notes are your separate, private process notes, the ones kept apart from the rest of the client's record.
Why does your email provider need a BAA?
Let's be clear about which BAA we're talking about. This one is between you and your email service provider. Not between you and the provider you're referring to. Two providers exchanging PHI for treatment purposes don't need a BAA with each other.
Under HIPAA, a company that creates, receives, maintains, or transmits PHI on your behalf is a business associate. Your email provider transmits your messages, receives incoming replies, and maintains copies in your sent folder, drafts, and inbox.
That's different from a service that simply moves data through without accessing or holding onto it. HHS limits that exception, known as the conduit exception, to couriers and their electronic equivalents. An email provider doesn't qualify.
👉 Here's the practical takeaway: your email provider handles PHI in multiple ways, so you need a BAA with them. And it's worth checking where your current provider stands. Here's a comparison of HIPAA-compliant email providers if you want to see your options.
💡 Hushmail tip. If you're not sure whether your current email provider has signed a BAA with you, that's worth five minutes to check. Free personal accounts generally don't offer one. Every Hushmail plan includes a signed BAA, so it's in place from day one.
Does it matter that the other provider is also covered by HIPAA?
If you're both bound by the same law, it feels like the information stays inside a closed system. That's an understandable assumption.
The fact that they're also required to comply with HIPAA matters for what happens after the information arrives. Once the receiving provider has the PHI, they have their own obligations to safeguard it. That's reassuring, but it doesn't reach backward to cover how you sent it. The channel you used to get the information there is still your responsibility.
Think of it this way: two clinics can both be locked at night. That says nothing about how the file got from one building to the other.
Even if your EHR handles client communication securely, that doesn't cover what happens when you need to email another provider directly. It's worth considering why secure communication outside your EHR matters too.
Does this mean you should stop emailing referrals?
No. And this is important, because the overcorrection is a real problem too.
HIPAA doesn't prohibit emailing PHI to other providers. It asks for reasonable safeguards. Those are two very different things.
Some providers respond by refusing to email referrals at all, insisting on fax (which comes with its own compliance concerns), or making the process so cumbersome that referral partners stop reaching out. That has a cost your client pays. A referral that takes three weeks to move is a client who waited three weeks for care.
Coordination between providers is part of good treatment. The goal isn't less communication. It's the same communication through a channel that protects it.
And if you've ever added a HIPAA disclaimer to your email signature hoping it would cover you, it's worth understanding why that's not quite how it works.
How do you send a referral securely?
- Check the address before you send, and make sure you're attaching the right file. HHS names verifying the recipient specifically. Autocomplete pulling up the wrong contact, or attaching the wrong client's documents, are two of the most ordinary ways referrals go sideways. If you haven't emailed that practice before, confirm the address first.
- Use a service built to handle PHI, with a signed BAA. This is the most straightforward thing you can do. A service designed for PHI has the safeguards in place, so you're not piecing it together yourself.
- Send what's relevant. HIPAA's minimum necessary standard doesn't apply to treatment disclosures (45 CFR 164.502(b)(2)), so you don't have to agonize over trimming a referral down to the bare minimum. But that's not a reason to send a client's entire record when a summary of what the other provider needs would do. Good clinical judgment still applies.
- Keep the follow-up in the same protected place. Referrals generate back-and-forth. Does the client have out-of-network benefits? What's your availability? Can you send more history? Those replies carry PHI too, and they're easy to fire off from wherever is convenient.
- Confirm it arrived. Not a HIPAA requirement, but a referral that sits unread in someone's inbox is a client who's still waiting.
💡 Hushmail tip. With Hushmail, you can send a secure message to another practitioner just by entering their email address. They get a link to read and reply in a protected space, so the whole referral conversation stays in one place instead of scattered across inboxes. They don't need a Hushmail account.
What about referrals coming to you?
Now flip the direction. If you accept referrals, other providers are sending you PHI, and you have no control over how they send it. You can have your own setup completely in order and still receive a client's full history as an attachment from a free email account.
Without a defined process, referrals can arrive incomplete, go to a shared inbox, or get buried in a thread. That means follow-ups, delays, and a client waiting longer for care. The referral another provider sent two weeks ago might still be sitting in a general inbox nobody checks regularly.
A secure referral form gives referral partners a defined way to send what you need: client contact details, reason for referral, relevant clinical information, and supporting documents. Fewer incomplete referrals. Less time chasing people for the piece they forgot.
Share the link on your website or in your email signature so it's there when someone wants to refer to you.
💡 Hushmail tip. You can build a secure referral form with drag-and-drop fields, including file uploads for intake forms and assessments, and submissions arrive in your secure inbox.
Frequently asked questions about emailing PHI to other providers
Can I email another provider using Gmail?
Gmail doesn't sign a BAA for free personal accounts. Google Workspace does offer a BAA, but you'd need to confirm it covers your use case. If your email provider hasn't signed a BAA with you, consider a service built for PHI.
Do both providers need Hushmail?
No. When you send a secure message through Hushmail, the recipient gets a link to read and reply in a protected space. They don't need their own Hushmail account.
Can I send referrals to providers outside my EHR?
Yes. HIPAA's treatment permission doesn't depend on both providers using the same system. What matters is that you use a secure method with appropriate safeguards.
Do I need written authorization for every referral?
Not for treatment disclosures. HIPAA permits providers to share PHI with other providers for treatment purposes without the client's authorization. Psychotherapy notes are the exception.
Your next step
You're probably already clear on the first question now. The second one is worth a few minutes. Look at the last referral you sent. Was it through a service that has signed a BAA with you? If you accept referrals, check what happens when someone tries to send you one. Is there a secure way to do it, or does it land in a regular inbox?
You don't need to complicate your practice or stop emailing other providers. You need one channel you trust for the messages that carry PHI. Once that's in place, you can stop second-guessing every Send.
For a broader look at your setup, here's a HIPAA compliance checklist to work through.
Ready to send referrals securely?
Reviewed by: Steven O. Youngman, VP of Legal and Compliance, Hushmail.
Overwhelmed by the business side of private practice? In this guide, therapists share 20 ways they've offloaded what drains them, to create more space for the work they love.