Emailing patients
HIPAA allows providers to email patients, with reasonable safeguards. Patients may also ask to receive information by email; if they prefer unencrypted email after being warned of the risk, a provider may honor that.
Emailing patients at a glance
HIPAA allows health care providers to email patients as long as they use reasonable safeguards. Patients can ask to receive communications by email, and HHS guidance says a provider may send unencrypted email to a patient who requests it after being warned of the risks. In practice, a practice should use an email service that signs a BAA, encrypt by default, verify addresses, and record each patient's preference.
| Rules | 45 CFR 164.522(b) and 164.530(c) |
|---|---|
| Allowed? | Yes, with reasonable safeguards |
| Patient preference | Providers must accommodate reasonable requests for alternative means of communication |
| Unencrypted email | Permitted at the patient's request after a risk warning (HHS guidance) |
| Minimum setup | BAA-backed email, encryption by default, address checks, recorded preferences |
HIPAA does not prohibit email. Providers may communicate with patients electronically as long as they apply reasonable safeguards (164.530(c)) — the same standard that applies to phone calls or letters.
Patients’ right to choose how they are contacted
Under the confidential communications standard (164.522(b)), a covered health care provider must accommodate reasonable requests from patients to receive communications by alternative means or at alternative locations — for example, by email instead of a letter to the home address.
HHS has explained in its guidance that if a patient asks to receive their information by unencrypted email, the provider may send it that way after warning the patient of the risks and confirming the patient still wants it. The provider is not responsible for unauthorized access to the information while in transmission in that case — but remains responsible for its own systems and for sending to the right address.
Safeguards that make email workable
- Use a provider that signs a BAA for the mailbox that holds patient messages.
- Encrypt by default, and have a simple way for patients to open encrypted messages without special software.
- Verify addresses before sending, and be careful with autocomplete — misdirected email is one of the most common causes of small breaches.
- Send the minimum necessary, and avoid sensitive details in subject lines.
- Record patient preferences, including any informed request for unencrypted email.
Where this leaves therapists and small practices
Email with patients is fine; email without a BAA, without encryption and without a record of patient preferences is where problems start. The HIPAA email comparison shows which services sign a BAA and what each still requires you to configure.
Tools and services where this matters
Guides
- HIPAA patient rights →The rights HIPAA gives patients over their health information, with deadlines, and what a practice must do to honor each one.
- HIPAA release form →What a HIPAA release form is, when a practice actually needs one, the fields it must contain to be valid, and the most common mistakes.
Scenarios
Related requirements
Frequently asked questions
Can I email patients under HIPAA?
Yes. HIPAA permits email with patients when reasonable safeguards are in place, such as encryption, a BAA with the email provider, and checking the recipient address.
Can I send unencrypted email if the patient asks?
According to HHS guidance, yes — after warning the patient of the risks and confirming they still want unencrypted email. Document that preference.
Is Gmail HIPAA compliant for emailing patients?
Free Gmail does not come with a BAA. Google Workspace offers a BAA you accept in the Admin console, but you still need to configure it and decide how patients receive encrypted messages.