Paubox: HIPAA status
Email encryption built for healthcare that encrypts outbound email by default, with a BAA on every account.
Signs a BAAYes
Paubox signs a Business Associate Agreement. Paubox states that BAAs are included with all accounts.
Source: Paubox — Pricing · checked
Paubox and HIPAA at a glance
Paubox signs a Business Associate Agreement. A BAA alone does not make its use HIPAA compliant: you still need to require multifactor authentication for each user's Paubox sign-in. Facts checked against Paubox's own documentation on 2026-10-05.
| Signs a BAA | Yes |
|---|---|
| How you get it | Paubox states that BAAs are included with all accounts. |
| You still need to | Require multifactor authentication for each user's Paubox sign-in. |
| Last checked | 2026-10-05 |
BAA details
| Signs a BAA | Yes | Paubox — Pricing |
|---|
What you still have to configure
- Require multifactor authentication for each user's Paubox sign-in. source
Against our criteria
| Encryption in transit | Yes — All outbound email is encrypted by default. | Paubox — Pricing |
|---|---|---|
| Encryption at rest | Not verified | Not verified yet |
| Secure delivery to patients | Yes — Recipients read messages in their normal inbox, without portals, passwords or plug-ins. | Paubox — Pricing |
| Enforceable MFA | Partial — MFA is available; the pricing page does not say whether admins can require it for all users. | Paubox — Pricing |
| Audit logs for customers | Yes — Email analytics and mail logs are included. | Paubox — Pricing |