Gmail

How to send HIPAA-compliant email from Gmail

Many practices start on Gmail or Google Workspace. That is fine for operations—but PHI needs a documented compliance channel.

Can you use Gmail for HIPAA email?

Google Workspace can support HIPAA if you sign Google’s BAA, configure security settings, and use it only in ways your policies allow. Free Gmail consumer accounts are not a defensible channel for PHI. Most small clinics eventually add a dedicated HIPAA messaging platform so staff are not guessing which inbox is safe.

What Gmail does not give you by default

  • A clear, clinic-specific audit trail for every PHI message
  • Staff training and policies tied to one compliant workflow
  • Fax and secure intake forms in the same compliance model
  • Proof for OCR that vendors touching PHI have signed BAAs

Practical steps clinics take

  1. Inventory PHI flows. List who emails patients, referrals, and labs—and from which accounts.
  2. Sign BAAs with every vendor that stores or transmits PHI (email, EHR add-ons, forms, fax).
  3. Pick one compliant channel for PHI and train staff not to split messages across personal inboxes.
  4. Turn on logging you can export during an audit.

When to keep Gmail vs add HIPAA email

Some groups keep Google for internal (non-PHI) mail and route patient communication through a HIPAA-ready inbox. Others migrate entirely. The right answer depends on size, specialty, and how often PHI leaves the EHR.

Read: what HIPAA-compliant email actually requires · Book a consult

Next step

Questions after reading?

Book a consult or take the risk check—no sales pitch required.