Email can be HIPAA compliant when you configure it correctly, and a standard consumer email account does not meet the requirements on its own. To send protected health information (PHI) by email, you need encryption, a signed business associate agreement with your email provider, access controls, and either a secure delivery method or your client's documented consent to plain email. Get those pieces in place and email joins the set of channels you can use with clients. Skip them and a routine message becomes a reportable breach.
This guide is written for health and wellness practitioners who message clients every day: dietitians, coaches, therapists, and functional medicine providers. It walks through when email meets the rule and when it falls short, what encryption and a BAA actually require, why secure portal messaging is the safer default, and how to handle appointment reminders by text. Compliance sets the floor here. The practices that protect clients well build above it.
HIPAA does not ban email. The Privacy Rule permits you to communicate with clients electronically, including by email, as long as you apply reasonable safeguards to protect the information. The Security Rule then spells out what those safeguards look like for electronic PHI: access controls, encryption, integrity protection, and audit trails. The U.S. Department of Health and Human Services publishes guidance confirming that email to patients is allowed when these protections are in place.
Email is permitted. Compliance depends on whether your specific setup carries the safeguards HIPAA requires. Email falls short in a few common situations:
Fix each of those and email moves inside the rule. The next sections cover how.
Check three things: whether the message is encrypted in transit and at rest, whether you hold a signed business associate agreement with your email provider, and whether you have documented consent from any client receiving unencrypted mail. Handle these and the rest of your email hygiene follows.
Encryption scrambles a message so only the intended recipient can read it. The Security Rule makes encryption an addressable implementation specification rather than a required one, and that is not the same as optional. Where encryption is not reasonable and appropriate for your setup, you have to adopt an alternative measure that achieves the same purpose, and document why the original was not reasonable. In practice, encryption is the reasonable choice for anything containing PHI. You want it in two places: in transit, while the message travels between servers, and at rest, while it sits in your account and the recipient's. Business email platforms built for healthcare offer both. Confirm the setting is on rather than assuming the default covers you.
Your email provider stores and transmits client information on your behalf, which makes them a business associate under HIPAA. Before you send any PHI, the rules want satisfactory assurances in writing that the vendor will safeguard it, which in practice means a signed business associate agreement (BAA). The BAA is the contract that binds the vendor to protect the data, limit how they use it, and report incidents to you. Google and Microsoft both make a BAA available for their business services, and both define what the agreement covers by service rather than by plan tier, so read the covered-services list rather than the price page. Google's BAA amends a Workspace or Cloud Identity agreement, which is why a personal Gmail address cannot be covered at all. Ask for the BAA before you send anything, and treat a vendor who will not sign one as a vendor you cannot put client data into.
Clients have the right to receive communication the way they prefer. The Privacy Rule does not prohibit unencrypted email for treatment-related communication with a client, and where a client may not be aware of the risk, you can alert them and let them decide whether to carry on by email. The safeguard here is documentation. Note that the client understood the exposure and chose to continue anyway, and keep that note in their record. Without it, an unencrypted message carrying PHI is a gap you cannot defend. For a fuller picture of how these safeguards fit together across your practice, see our guide to understanding HIPAA compliance for health and wellness professionals.
Secure messaging removes the three moving parts email asks you to manage: encryption settings, BAA coverage, and a record of who consented to what. Email can be made compliant, and every one of those parts stays your job. Inside a client portal they are handled by the platform. Messages stay encrypted inside a system already covered by your BAA, every login is authenticated, and the conversation attaches to the right client record instead of scattering across an inbox.
This is where the difference between compliant and careful shows up. Practice Better's position is that legal compliance is the starting point of good data handling. For practitioners working with eating disorders, disordered eating, or mental health comorbidities, clients "share things in session that they haven't shared anywhere else," so understanding exactly how a tool handles that data "matters in ways that go beyond HIPAA compliance" (source). A secure portal message respects that weight in a way a forwarded email thread struggles to.
There is a practical payoff too. When messaging lives inside the platform you already use for scheduling, records, and billing, the message becomes part of the client's history the moment you send it. You are not copy-pasting a sensitive exchange from a separate inbox into the chart later, and you are not maintaining two systems that have to agree. Practice Better's secure messaging keeps client conversations encrypted and inside the record, so the safe channel is also the convenient one. When the compliant option is the easy option, your team uses it by default.
Texting is HIPAA compliant for appointment logistics a client has agreed to receive, and standard SMS travels unencrypted, so clinical detail belongs in secure messaging instead. The rule becomes workable once you separate those two uses.
Appointment logistics. HIPAA treats appointment reminders as part of treatment, so they need no separate authorization, and a text is a reasonable way to send one when your client has agreed to receive messages that way. Keep the content minimal: a name, a date, a time, and a way to confirm or reschedule. A reminder that says "This is a reminder of your appointment on Thursday at 2pm" carries little sensitive information and lands squarely inside what the rule allows. Get the client's agreement to text reminders and note their number and preference in the record. Our overview of reminder notifications shows how automated reminders cut no-shows without extra admin.
Clinical content. Standard SMS travels unencrypted and often sits on a device with no lock and no BAA behind the carrier. That makes plain texting a poor fit for anything clinical: symptoms, results, plan details, or anything a client would consider private. For those exchanges, point clients to secure messaging in the portal. A short text that says "I've sent you a secure message, please check your portal" gives you the immediacy of a text without putting PHI on an unprotected channel.
Drawing that line once, and building it into how your reminders and messages are set up, keeps texting useful and keeps PHI where it belongs.
Five steps, in this order: sign a BAA, turn on encryption, set access controls, capture consent, and route clinical detail to the portal. Here is the practical sequence for a wellness practice putting this in order.
Assembling secure messaging, a compliant email provider, telehealth, and a client portal is the point of our roundup of HIPAA-compliant tools your practice can't live without. When those pieces sit in one system, the safe path and the fast path are the same path.
Meeting the HIPAA requirements for email keeps you inside the law. You earn the confidence a client places in you when they share something they have told no one else by handling their information with more care than the minimum asks for: defaulting to the secure channel, keeping sensitive detail out of plain email even when consent would allow it, and choosing tools whose entire design assumes the data is protected.
For a wellness practitioner, that care is part of the clinical relationship. The channel a message travels on tells a client something about how seriously you take what they told you. Choosing the protected channel by default is a small, repeated signal that you do. You can control your notification content too; our guide to customizing email notifications covers how to strip sensitive detail out of the automated messages your system sends.
Email has a place in a compliant practice, sitting next to secure messaging, appointment texts, and a client portal. Practice Better brings those channels together in one HIPAA-compliant platform built for health and wellness care, so every client conversation stays encrypted and inside the record. Start your free trial to see how secure messaging fits the rest of your workflow.
{{operations-checklist-for-better-group-practice-simple-text}}
Email can be HIPAA compliant, and a standard consumer email account is not compliant on its own. To send PHI by email you need encryption in transit and at rest, a signed business associate agreement with your email provider, access controls, and either a secure delivery method or documented client consent to unencrypted email. With those in place, email meets the rule.
A free personal Gmail account cannot be made HIPAA compliant. Google's BAA is an amendment to a Google Workspace or Cloud Identity agreement, and a consumer account has no such agreement for it to amend. Google Workspace can be covered once you enter Google's BAA and keep PHI inside the services that agreement lists. Compliance comes down to the account type and configuration behind the address.
Yes, if your email provider stores or transmits protected health information for you, you need a signed business associate agreement with that provider before you send PHI. The BAA is the contract that makes the vendor legally accountable for protecting the data and for reporting any incident to you.
The Privacy Rule does not prohibit unencrypted email for treatment-related communication with a client. Where a client may not be aware of the risk, alert them, let them decide, and record that they chose to continue. Without that note, sending PHI over unencrypted email is a compliance risk you cannot defend.
Yes. Appointment reminders are permitted when your client has agreed to be contacted that way. Keep the content to a name, a date, a time, and a way to confirm or reschedule, and record the client's contact preference in their file alongside the rest of their communication consent.
Secure messaging inside a HIPAA-compliant client portal is the safest default. Messages stay encrypted inside a system covered by your BAA, access is authenticated, and the conversation attaches to the client record. It closes the consent and encryption gaps that plain email and SMS leave open.
{{free-trial-simple-text}}

Email can be HIPAA compliant when you configure it correctly, and a standard consumer email account does not meet the requirements on its own. To send protected health information (PHI) by email, you need encryption, a signed business associate agreement with your email provider, access controls, and either a secure delivery method or your client's documented consent to plain email. Get those pieces in place and email joins the set of channels you can use with clients. Skip them and a routine message becomes a reportable breach.
This guide is written for health and wellness practitioners who message clients every day: dietitians, coaches, therapists, and functional medicine providers. It walks through when email meets the rule and when it falls short, what encryption and a BAA actually require, why secure portal messaging is the safer default, and how to handle appointment reminders by text. Compliance sets the floor here. The practices that protect clients well build above it.
HIPAA does not ban email. The Privacy Rule permits you to communicate with clients electronically, including by email, as long as you apply reasonable safeguards to protect the information. The Security Rule then spells out what those safeguards look like for electronic PHI: access controls, encryption, integrity protection, and audit trails. The U.S. Department of Health and Human Services publishes guidance confirming that email to patients is allowed when these protections are in place.
Email is permitted. Compliance depends on whether your specific setup carries the safeguards HIPAA requires. Email falls short in a few common situations:
Fix each of those and email moves inside the rule. The next sections cover how.
Check three things: whether the message is encrypted in transit and at rest, whether you hold a signed business associate agreement with your email provider, and whether you have documented consent from any client receiving unencrypted mail. Handle these and the rest of your email hygiene follows.
Encryption scrambles a message so only the intended recipient can read it. The Security Rule makes encryption an addressable implementation specification rather than a required one, and that is not the same as optional. Where encryption is not reasonable and appropriate for your setup, you have to adopt an alternative measure that achieves the same purpose, and document why the original was not reasonable. In practice, encryption is the reasonable choice for anything containing PHI. You want it in two places: in transit, while the message travels between servers, and at rest, while it sits in your account and the recipient's. Business email platforms built for healthcare offer both. Confirm the setting is on rather than assuming the default covers you.
Your email provider stores and transmits client information on your behalf, which makes them a business associate under HIPAA. Before you send any PHI, the rules want satisfactory assurances in writing that the vendor will safeguard it, which in practice means a signed business associate agreement (BAA). The BAA is the contract that binds the vendor to protect the data, limit how they use it, and report incidents to you. Google and Microsoft both make a BAA available for their business services, and both define what the agreement covers by service rather than by plan tier, so read the covered-services list rather than the price page. Google's BAA amends a Workspace or Cloud Identity agreement, which is why a personal Gmail address cannot be covered at all. Ask for the BAA before you send anything, and treat a vendor who will not sign one as a vendor you cannot put client data into.
Clients have the right to receive communication the way they prefer. The Privacy Rule does not prohibit unencrypted email for treatment-related communication with a client, and where a client may not be aware of the risk, you can alert them and let them decide whether to carry on by email. The safeguard here is documentation. Note that the client understood the exposure and chose to continue anyway, and keep that note in their record. Without it, an unencrypted message carrying PHI is a gap you cannot defend. For a fuller picture of how these safeguards fit together across your practice, see our guide to understanding HIPAA compliance for health and wellness professionals.
Secure messaging removes the three moving parts email asks you to manage: encryption settings, BAA coverage, and a record of who consented to what. Email can be made compliant, and every one of those parts stays your job. Inside a client portal they are handled by the platform. Messages stay encrypted inside a system already covered by your BAA, every login is authenticated, and the conversation attaches to the right client record instead of scattering across an inbox.
This is where the difference between compliant and careful shows up. Practice Better's position is that legal compliance is the starting point of good data handling. For practitioners working with eating disorders, disordered eating, or mental health comorbidities, clients "share things in session that they haven't shared anywhere else," so understanding exactly how a tool handles that data "matters in ways that go beyond HIPAA compliance" (source). A secure portal message respects that weight in a way a forwarded email thread struggles to.
There is a practical payoff too. When messaging lives inside the platform you already use for scheduling, records, and billing, the message becomes part of the client's history the moment you send it. You are not copy-pasting a sensitive exchange from a separate inbox into the chart later, and you are not maintaining two systems that have to agree. Practice Better's secure messaging keeps client conversations encrypted and inside the record, so the safe channel is also the convenient one. When the compliant option is the easy option, your team uses it by default.
Texting is HIPAA compliant for appointment logistics a client has agreed to receive, and standard SMS travels unencrypted, so clinical detail belongs in secure messaging instead. The rule becomes workable once you separate those two uses.
Appointment logistics. HIPAA treats appointment reminders as part of treatment, so they need no separate authorization, and a text is a reasonable way to send one when your client has agreed to receive messages that way. Keep the content minimal: a name, a date, a time, and a way to confirm or reschedule. A reminder that says "This is a reminder of your appointment on Thursday at 2pm" carries little sensitive information and lands squarely inside what the rule allows. Get the client's agreement to text reminders and note their number and preference in the record. Our overview of reminder notifications shows how automated reminders cut no-shows without extra admin.
Clinical content. Standard SMS travels unencrypted and often sits on a device with no lock and no BAA behind the carrier. That makes plain texting a poor fit for anything clinical: symptoms, results, plan details, or anything a client would consider private. For those exchanges, point clients to secure messaging in the portal. A short text that says "I've sent you a secure message, please check your portal" gives you the immediacy of a text without putting PHI on an unprotected channel.
Drawing that line once, and building it into how your reminders and messages are set up, keeps texting useful and keeps PHI where it belongs.
Five steps, in this order: sign a BAA, turn on encryption, set access controls, capture consent, and route clinical detail to the portal. Here is the practical sequence for a wellness practice putting this in order.
Assembling secure messaging, a compliant email provider, telehealth, and a client portal is the point of our roundup of HIPAA-compliant tools your practice can't live without. When those pieces sit in one system, the safe path and the fast path are the same path.
Meeting the HIPAA requirements for email keeps you inside the law. You earn the confidence a client places in you when they share something they have told no one else by handling their information with more care than the minimum asks for: defaulting to the secure channel, keeping sensitive detail out of plain email even when consent would allow it, and choosing tools whose entire design assumes the data is protected.
For a wellness practitioner, that care is part of the clinical relationship. The channel a message travels on tells a client something about how seriously you take what they told you. Choosing the protected channel by default is a small, repeated signal that you do. You can control your notification content too; our guide to customizing email notifications covers how to strip sensitive detail out of the automated messages your system sends.
Email has a place in a compliant practice, sitting next to secure messaging, appointment texts, and a client portal. Practice Better brings those channels together in one HIPAA-compliant platform built for health and wellness care, so every client conversation stays encrypted and inside the record. Start your free trial to see how secure messaging fits the rest of your workflow.
{{operations-checklist-for-better-group-practice-simple-text}}
Email can be HIPAA compliant, and a standard consumer email account is not compliant on its own. To send PHI by email you need encryption in transit and at rest, a signed business associate agreement with your email provider, access controls, and either a secure delivery method or documented client consent to unencrypted email. With those in place, email meets the rule.
A free personal Gmail account cannot be made HIPAA compliant. Google's BAA is an amendment to a Google Workspace or Cloud Identity agreement, and a consumer account has no such agreement for it to amend. Google Workspace can be covered once you enter Google's BAA and keep PHI inside the services that agreement lists. Compliance comes down to the account type and configuration behind the address.
Yes, if your email provider stores or transmits protected health information for you, you need a signed business associate agreement with that provider before you send PHI. The BAA is the contract that makes the vendor legally accountable for protecting the data and for reporting any incident to you.
The Privacy Rule does not prohibit unencrypted email for treatment-related communication with a client. Where a client may not be aware of the risk, alert them, let them decide, and record that they chose to continue. Without that note, sending PHI over unencrypted email is a compliance risk you cannot defend.
Yes. Appointment reminders are permitted when your client has agreed to be contacted that way. Keep the content to a name, a date, a time, and a way to confirm or reschedule, and record the client's contact preference in their file alongside the rest of their communication consent.
Secure messaging inside a HIPAA-compliant client portal is the safest default. Messages stay encrypted inside a system covered by your BAA, access is authenticated, and the conversation attaches to the client record. It closes the consent and encryption gaps that plain email and SMS leave open.
{{free-trial-simple-text}}

Try any paid plan free.