Blog · HIPAA email

TLS, archiving, and the email logs OCR actually asks about

Investigators rarely ask if you "take security seriously." They ask who accessed a message and whether you can prove encryption was on.

A due-diligence questionnaire and an OCR data request look different, but both end at evidence. Screenshots of a settings page are weak evidence. Exportable logs and a signed BAA are stronger.

Minimum email evidence to keep

  • Proof that messages with PHI travel over TLS (or another documented encryption method).
  • An archive or journal that survives a laptop wipe.
  • Login and access events for mailboxes that handle PHI.
  • A current BAA and a list of users who still have accounts.

Do not invent a binder the week of the letter

Turn the logs on before the first production send. Assign someone to export a sample quarterly so you know the buttons still work. HIPAA Companion healthcare email is designed so archiving and activity logging are part of the product, not a professional-services project.

Fax confirmations and form submission histories belong in the same conversation. OCR will not care that those lived in a different brand of software if you cannot produce them.