Skip to sign in Skip to content

Practice management

Not sure when to use secure messaging? Use this 3-question framework

Learn how to spot PHI in client emails, when regular email is fine, and when secure messaging can help support HIPAA compliance.
Secure messaging

Estimated reading time: 8 minutes.

Summarize with ChatGPT
 

TL;DR: Therapists can use regular email for many day-to-day communications. But if you're handling protected health information (PHI), use a HIPAA-compliant secure messaging service.

Not sure whether to use regular email or secure messaging? Use this three-question test:

  • Is there individually identifiable information?
  • Is the information related to health, healthcare services, or payment for healthcare?
  • Am I handling this as a healthcare provider?

If you answer "Yes" to all three, you're handling PHI. Use a secure messaging service instead of regular email.

Do you feel a little anxious anytime you email a client? You're acutely aware of your HIPAA obligations and your responsibility to keep sensitive personal information private. And anytime you hit Send, there's a nagging question in the back of your mind: Is it ok for me to share this by email?

In healthcare, certain types of communication require a more secure, controlled approach than regular email provides. Keeping protected health information (PHI) private is critical for maintaining trust with your clients and colleagues and for staying HIPAA-compliant.

But how do you know which messages can be sent by regular email and which ones need additional protection from a secure messaging service?

Our framework will help you figure out which platform to use for every message you send.

When therapists need HIPAA-compliant email

The HIPAA Security Rule governs email communication. It requires healthcare providers to safeguard electronic protected health information (ePHI), including emails, digital records, and other health data stored or shared online.

Technical safeguards include controlling who can access messages and ensuring that ePHI is protected as it travels from one inbox to another.

There are two common ways to communicate with clients, colleagues, and other people in the day-to-day of running a practice:

  1. Regular email services encrypt messages while they're in transit, protecting them as they travel from your computer to your client's inbox. This level of security is sufficient for most daily business use.
  2. A secure messaging service like Hushmail keeps communication protected throughout the message lifecycle. You and your client sign in to a secure web page to read, send, and store messages and files. This helps ensure that only the intended recipients can access sensitive information.

A secure messaging service supports HIPAA compliance and reduces risk exposure.

⚠️ Any service you use to send PHI must have a Business Associate Agreement (BAA) for you to be HIPAA compliant. Free personal email services, such as personal Gmail accounts, don't include a BAA. To send PHI compliantly, use a service that will sign one.

👉 Learn more: For full details, read our guide to why regular email may not be enough to protect PHI.

How therapists can decide between regular email and secure messaging

Both regular email and secure messaging services have their uses. The challenge is knowing when to use which one. Certain scenarios increase risk, like when you're discussing sensitive details or replying to ongoing threads.

Whether you use regular email or a secure messaging service depends on whether you're sending PHI. Answer these three questions to help you figure out if you're dealing with PHI:

1. Is there individually identifiable information?
2. Is the information related to health, healthcare services, or payment for healthcare?
3. Am I handling this as a healthcare provider?

✅ If the answer to all three is yes, you're handling PHI.
Use a secure messaging service instead of regular email.

👉 For more details on what PHI is and isn't, read our article “What counts as PHI?

⚠️ Before hitting Send on any message, stop and ask yourself: Does this communication involve PHI? Should this conversation move to a secure messaging service?

Examples of when therapists should use secure messaging

Here are a few examples of situations you may run into at your therapy practice:

Scenario: A client emails you a question about their care and shares detailed personal information.

🤔 Without thinking, you might hit reply and respond to them directly. But be sure to pause before answering to determine whether you're dealing with PHI.

The message:

✅ Includes individually identifiable information (the client's name and email address)

✅ Is related to healthcare services

✅ Is handled in your role as a healthcare provider

👉 It's PHI. In this case, move the conversation to a secure option.

Scenario: A new client needs to fill out intake forms.

🤔 Sending blank PDFs by regular email seems reasonable. They don't yet contain your client's personal information, so it seems like there's nothing on them that needs protecting.

The message:

✅ Includes individually identifiable information (the client's name and email address)

✅ Is related to future healthcare services

✅ Is handled in your role as a healthcare provider

👉 Using a therapy intake form within a secure messaging service like Hushmail also ensures that once clients respond with their filled-in personal details, it stays secure.

Scenario: Your clients subscribe to your monthly newsletter, where you share general mental-health resources and updates about your practice.

🤔 You wonder if you should keep your newsletter private because sometimes you send information about sensitive topics like living with depression.

The message:

✅ Includes individually identifiable information (such as the recipient's email address)

✅ Is related to healthcare

✅ Is handled in your role as a healthcare provider

👉 This communication involves PHI. Marketing communications are one of the more complex areas of HIPAA, illustrating how broad HIPAA's definition of PHI is. If you're sending newsletters to clients, make sure your email marketing service supports HIPAA compliance and understands the additional requirements that may apply.

💡 For an in-depth dive on this topic, check out Person Centered Tech's “Marketing in Mental Health: The Legal and Ethical Do’s and Don'ts You Need to Know” CE training.

Scenario: A back-and-forth conversation began with a question about your clinic's location, but the most recent response asks how to make an appointment and includes personal details.

🤔 The first messages didn't contain any sensitive information, but you're not sure what to do now that the client has responded with a question about their condition.

The message:

✅ Includes individually identifiable information (name and email address)

✅ Is related to healthcare services

✅ Is handled in your role as a healthcare provider

👉 It's time to move the conversation to a secure messaging service.

Scenario: You have to disclose information to another healthcare provider, an insurance company, or a colleague to get your client the treatment they need.

🤔 The PHI you want to share is allowable under the HIPAA Privacy Rule, and/or the client has authorized disclosure. And you're following the minimum necessary standard. So regular email should be fine, right?

The message:

✅ Includes individually identifiable information (the client's name and email address)

✅ Is related to healthcare services

✅ Is handled in your role as a healthcare provider

👉 You still need to transmit PHI via a HIPAA-compliant provider that has the necessary Business Associate Agreement.

Scenario: A client emails asking about an invoice or payment for a recent session.

🤔 Because the conversation is about billing and logistics, you might assume regular email is fine. But it still counts as PHI because it includes individually identifiable information related to payment for healthcare.

The message:

✅ Includes individually identifiable information (the client's name and email address)

✅ Is related to payment for healthcare

✅ Is handled in your role as a healthcare provider

👉 Since the message involves PHI, continue the conversation using a secure messaging service.

 

A simpler way to send HIPAA-compliant messages

You don't need to stop using regular email in your therapy practice. But it's important to pay attention to when and how you use it.

Regular email is fine for things like organizing the office cleaning schedule. But you need a HIPAA-compliant option for handling PHI.

When you need to send PHI securely, a service like Hushmail can help simplify the process. It keeps communication confidential and secure while messages are being sent, read, and stored. (We also provide ready-to-go templates for secure contact, intake forms, and assessments.)

Setup is easy with our new Secure Messaging and Forms plan, which lets you keep using your existing email service, like Gmail or Outlook. Just sign in to Hushmail when your message needs extra security. Your clients get an email with a secure link they can click to sign in and view the secure message. You can both feel confident knowing your conversation will remain protected.

 

Frequently asked questions about HIPAA and email

 

Can therapists use regular email in their practice?

Yes, therapists can use regular email for some day-to-day communication. But if a message contains protected health information (PHI), HIPAA requires reasonable safeguards to protect it. In many cases, that means using a HIPAA-compliant secure messaging service instead of standard email.

What counts as PHI in an email?

PHI is any information that:

  • Identifies a person, or could be used to identify them
  • Relates to their past, present, or future health, healthcare services, or payment for healthcare
  • Is held or transmitted by a covered entity or business associate

👉 Learn more in our guide to what counts as PHI.

Is Gmail HIPAA compliant?

Free personal Gmail accounts don't include a Business Associate Agreement (BAA), which HIPAA requires when sending protected health information (PHI).

Google Workspace can support HIPAA compliance, but healthcare providers must use an eligible paid plan, sign a Business Associate Agreement with Google, configure the account appropriately, and implement additional safeguards for protecting PHI.

Healthcare providers who need to send PHI electronically should use services that support HIPAA compliance and will sign a BAA.

👉 Learn more in our guide to whether Gmail is HIPAA compliant.

When should therapists use secure messaging instead of regular email?

Therapists should use secure messaging whenever a conversation includes PHI or could reveal that someone is receiving care from their practice. This helps protect client privacy and supports HIPAA compliance.

Can clients give permission to use regular email?

HIPAA does allow clients to request or consent to email communication in some situations. However, healthcare providers are still expected to use reasonable safeguards to protect PHI and document their processes appropriately.

👉 Learn more in our guide to what therapists call a "HIPAA waiver".

What's the difference between regular email and secure messaging?

Regular email may protect messages while they're being sent, but secure messaging services add protections for reading, storing, and accessing sensitive information. They also typically include HIPAA-related features like access controls, audit trails, and Business Associate Agreements.

👉 Watch our video on "What makes email HIPAA-compliant".

Reviewed by: Steven O. Youngman, VP of Legal and Compliance, Hushmail.

Similar posts