Blog · HIPAA email

Why consumer email is not enough for PHI

TLS on Gmail or Outlook does not replace a BAA, retention you can explain, or controls that stop auto-forwarding to a personal phone.

Practices hear "we use Google" and assume the Privacy Rule is covered. Encryption between two servers is useful. It is not a Business Associate Agreement, and it is not an audit log of who opened a lab result last Tuesday.

The gaps that show up in real offices

  • Staff auto-forward clinic mail to a personal account so they can "check it on the phone."
  • Shared passwords on a front-desk Outlook profile that never gets disabled.
  • No retention story when a patient requests an accounting of disclosures.
  • No signed BAA because the consumer plan never offered one for that mailbox.

What to do instead

Keep consumer mail for non-PHI operations if you want. Put referrals, records requests, and anything with a name plus a clinical detail on a healthcare email service that signs a BAA, archives messages, and lets you revoke access in minutes.

HIPAA Companion email is designed for that split: staff get a normal inbox, the practice keeps the compliance evidence, and fax plus forms use the same agreement instead of a second vendor stack.