Technology guide
Email and HIPAA
A workflow-based guide to email, PHI, patient requests, misdirection, encryption decisions, and vendor responsibilities.
Reviewed August 2026
Key considerations
- Email risk depends on the message, recipients, account controls, transport, storage, and workflow.
- Patient preferences, permitted disclosures, and minimum necessary analysis still matter.
- Mailbox exports, mobile clients, archives, and support access belong in the data flow.
Questions to ask
- What PHI is sent, to whom, and under what permitted purpose?
- How are accounts, devices, forwarding, archives, and misdirected messages handled?
- What is the response path when an email goes to the wrong person?