hipaa.systems
Privacy Rule · 45 CFR 164.522(b), 164.530(c)

Emailing patients

HIPAA allows providers to email patients, with reasonable safeguards. Patients may also ask to receive information by email; if they prefer unencrypted email after being warned of the risk, a provider may honor that.

Checked 2026-10-05Sources 4

Emailing patients at a glance

HIPAA allows health care providers to email patients as long as they use reasonable safeguards. Patients can ask to receive communications by email, and HHS guidance says a provider may send unencrypted email to a patient who requests it after being warned of the risks. In practice, a practice should use an email service that signs a BAA, encrypt by default, verify addresses, and record each patient's preference.

Rules45 CFR 164.522(b) and 164.530(c)
Allowed?Yes, with reasonable safeguards
Patient preferenceProviders must accommodate reasonable requests for alternative means of communication
Unencrypted emailPermitted at the patient's request after a risk warning (HHS guidance)
Minimum setupBAA-backed email, encryption by default, address checks, recorded preferences

HIPAA does not prohibit email. Providers may communicate with patients electronically as long as they apply reasonable safeguards (164.530(c)) — the same standard that applies to phone calls or letters.

Patients’ right to choose how they are contacted

Under the confidential communications standard (164.522(b)), a covered health care provider must accommodate reasonable requests from patients to receive communications by alternative means or at alternative locations — for example, by email instead of a letter to the home address.

HHS has explained in its guidance that if a patient asks to receive their information by unencrypted email, the provider may send it that way after warning the patient of the risks and confirming the patient still wants it. The provider is not responsible for unauthorized access to the information while in transmission in that case — but remains responsible for its own systems and for sending to the right address.

Safeguards that make email workable

  • Use a provider that signs a BAA for the mailbox that holds patient messages.
  • Encrypt by default, and have a simple way for patients to open encrypted messages without special software.
  • Verify addresses before sending, and be careful with autocomplete — misdirected email is one of the most common causes of small breaches.
  • Send the minimum necessary, and avoid sensitive details in subject lines.
  • Record patient preferences, including any informed request for unencrypted email.

Where this leaves therapists and small practices

Email with patients is fine; email without a BAA, without encryption and without a record of patient preferences is where problems start. The HIPAA email comparison shows which services sign a BAA and what each still requires you to configure.

Tools and services where this matters

Guides

Scenarios

Frequently asked questions

Can I email patients under HIPAA?

Yes. HIPAA permits email with patients when reasonable safeguards are in place, such as encryption, a BAA with the email provider, and checking the recipient address.

Can I send unencrypted email if the patient asks?

According to HHS guidance, yes — after warning the patient of the risks and confirming they still want unencrypted email. Document that preference.

Is Gmail HIPAA compliant for emailing patients?

Free Gmail does not come with a BAA. Google Workspace offers a BAA you accept in the Admin console, but you still need to configure it and decide how patients receive encrypted messages.