HIPAAmart

Technology guide

Email and HIPAA

A workflow-based guide to email, PHI, patient requests, misdirection, encryption decisions, and vendor responsibilities.

Reviewed August 2026

Key considerations

  • Email risk depends on the message, recipients, account controls, transport, storage, and workflow.
  • Patient preferences, permitted disclosures, and minimum necessary analysis still matter.
  • Mailbox exports, mobile clients, archives, and support access belong in the data flow.

Questions to ask

  • What PHI is sent, to whom, and under what permitted purpose?
  • How are accounts, devices, forwarding, archives, and misdirected messages handled?
  • What is the response path when an email goes to the wrong person?

References