HIPAA email services
Email services that sign a BAA, compared on what actually protects patient messages — and what you still have to configure yourself.
HIPAA email services at a glance
We compare 5 products in HIPAA email services. 5 sign a Business Associate Agreement (Google Workspace, Hushmail for Healthcare, Microsoft 365, Paubox, Proton Mail). They are compared on: Encryption in transit, Encryption at rest, Secure delivery to patients, Enforceable MFA, Audit logs for customers. Every value links to the vendor's own documentation and shows when it was checked.
| Products compared | 5 |
|---|---|
| Sign a BAA | Google Workspace, Hushmail for Healthcare, Microsoft 365, Paubox, Proton Mail |
| Compared on | Encryption in transit, Encryption at rest, Secure delivery to patients, Enforceable MFA, Audit logs for customers |
| Commissions | None — no vendor pays us |
| Facts checked since | 2026-10-05 |
Comparison
Alphabetical. No vendor pays us for listings, rankings or referrals — methodology.
| Product | Signs a BAA | Encryption in transit | Encryption at rest | Secure delivery to patients | Enforceable MFA | Audit logs for customers |
|---|---|---|---|---|---|---|
| Google Workspace | Yes | Yes | Yes | Partial | Yes | Yes |
| Hushmail for Healthcare | Yes | Yes | Yes | Yes | Partial | Not verified |
| Microsoft 365 | Yes | Yes | Yes | Partial | Yes | Yes |
| Paubox | Yes | Yes | Not verified | Yes | Partial | Yes |
| Proton Mail | Yes | Yes | Yes | Yes | Not verified | Not verified |
How we compare
- Encryption in transit
- Messages are protected with TLS between mail servers, and the service can require encryption or switch to a secure delivery method when the recipient's server does not support it.
- Encryption at rest
- Stored mail and attachments, including backups, are encrypted by the provider by default.
- Secure delivery to patients
- You can send an encrypted message that a patient can open without installing software or buying the same service — for example through a secure web portal or one-time code.
- Enforceable MFA
- An administrator can require multi-factor authentication for every user on the account, not just recommend it.
- Audit logs for customers
- You can see sign-in and mailbox activity logs yourself, on your plan, for long enough to investigate an incident.
What it costs
Requirements behind these criteria
- Business associate agreements (BAAs) →§ 164.502(e)
- Encryption of ePHI →§ 164.312(a)(2)(iv)
- Emailing patients →§ 164.522(b)
- Access control and sign-in →§ 164.312(a)(1)
- Audit controls and activity logs →§ 164.312(b)