HIPAA-Compliant Email: What Actually Qualifies (and What Silently Doesn't)

A BAA alone doesn't make email HIPAA compliant. The qualifying plan, the executed agreement, the configuration work, and the silent failure modes.

By Scott McAuley · Aug 20, 2026 · 11 min read

Ask a practice manager whether their email is HIPAA compliant and you'll usually hear some version of "yes — we're on Microsoft 365 and we signed the BAA." That answer describes maybe a third of the requirement, and the missing two-thirds is exactly where enforcement findings come from.

Here's the thesis of this article, stated up front: a business associate agreement makes your email platform eligible to carry PHI. Configuration is what makes it safe to. An unconfigured tenant with a signed BAA is not a compliant system — it's a finding waiting for an auditor to write it up. This piece expands the email chapter of our complete HIPAA compliance and healthcare IT guide into the working detail: what actually has to be true for email to qualify, the failure modes that silently break compliance in otherwise careful practices, the patient-consent nuance almost everyone gets wrong in one direction or the other, and a configuration checklist you can hand to whoever runs your tenant.

The Three-Part Test

HIPAA-compliant email is a stack of three requirements, and all three have to hold at once:

1. A qualifying plan. Microsoft 365 and Google Workspace both offer BAAs — but only on qualifying business and enterprise tiers. Consumer accounts and some entry-level plans are excluded entirely: no BAA is available at any price, which means no PHI, full stop. Check the plan name on your actual invoice, not your memory of what was bought years ago. (Plan tiers, licensing, and how the two platforms compare for regulated businesses are covered in our Microsoft 365 vs. Google Workspace comparison.)

2. An executed BAA. On both platforms, the BAA is a deliberate step — an agreement you accept through the admin console or your reseller — not something that activates with the subscription. Practices routinely discover, mid-audit, that they've been on the right plan for years with the agreement never executed. Verify it, get the confirmation in writing, and file it with the rest of your BAA inventory. What the agreement actually obligates the vendor to do — and what it doesn't — is the subject of our plain-English BAA guide.

3. Configuration. This is the part nobody sells you, because it isn't a product — it's work. Encryption enforced in transit and at rest, data loss prevention rules, retention policies, MFA on every mailbox, audit logging turned on and reviewed. The rest of this article is mostly about this layer, because it's where the real distance between "licensed" and "compliant" lives.

Miss the first and no agreement exists. Miss the second and no agreement is in force. Miss the third and the agreement is in force over a system that leaks. Only all three together survive scrutiny.

What Configuration Actually Means

The Security Rule doesn't say "buy Microsoft 365." It says implement access controls, transmission security, audit controls, and integrity protections for ePHI. On an email platform, those abstractions become specific switches, and here are the ones that matter:

Encryption in transit and at rest. Both major platforms encrypt data at rest in their data centers and negotiate TLS for mail in transit by default — but opportunistic TLS falls back to plaintext when the receiving server doesn't cooperate. Compliance-grade configuration means enforcing encryption for messages containing PHI: policy-based message encryption that wraps sensitive mail so it stays protected regardless of what the recipient's server supports.

Data loss prevention (DLP). DLP rules scan outbound mail for patterns — medical record numbers, SSNs, diagnosis codes, patient-name-plus-DOB combinations — and act before the message leaves: encrypt it automatically, warn the sender, or block and notify a compliance contact. DLP is the control that catches the well-meaning mistake, which is the overwhelming majority of email incidents. A tenant without DLP is relying on every employee being right every time, forever.

Multi-factor authentication. Compromised email credentials are the front door of most healthcare breaches. MFA on every mailbox — no exceptions for the physician who finds it annoying, no exceptions for the shared front-desk account (more on that below) — is the single highest-value switch in the tenant, and it's also table stakes for your cyber insurance.

Retention policies. Governed deletion instead of inbox housekeeping — covered in its own section below, because email retention is a records question, not just a storage question.

Audit logging. The platform records who accessed which mailbox, what rules were created, what was forwarded where. Logging that nobody has turned on — or that's on but never reviewed — is how auto-forward attacks run for months unnoticed.

What Silently Breaks Compliance

The dangerous failures aren't the dramatic ones. They're the quiet, reasonable-seeming behaviors that move PHI outside the boundary your BAA and configuration protect. Four patterns account for most of what we find in practice assessments:

Forwarding to personal accounts. A staff member forwards the day's schedule to their personal Gmail to work from home. Helpful instinct, reportable incident: the moment PHI lands in a consumer account, it sits on a platform with no BAA, outside your encryption, your DLP, your retention, and your audit trail. This is probably the single most common email violation in small practices, and it's almost never malicious — which is why the fix is DLP rules and a clear policy, not discipline.

Auto-forward rules. Worse than one-off forwarding, because it's systematic and invisible. Sometimes a user sets a rule to a personal address for convenience; just as often, an attacker who briefly compromises a mailbox plants a forwarding rule as a persistent tap — the classic move in business email compromise. Every message thereafter copies itself off-tenant. The remediation is configuration: disable external auto-forwarding at the tenant level, and alert on new forwarding rules so the exception process is deliberate.

Unencrypted attachments. The message is protected; the habit isn't. A staff member exports records to a PDF and attaches it — unencrypted, and one autocomplete mistake away from the wrong recipient. Records requests, referrals, and billing disputes generate this pattern constantly. DLP that detects PHI-bearing attachments and forces encryption (or a secure link) closes it.

Shared mailboxes with shared logins. A shared mailbox — frontdesk@ or referrals@ — is fine and often the right design. The violation is the shared login: five people signing in with one credential means the required audit trail reads as one anonymous user, MFA is weakened to whoever holds the password, and departures never revoke access. Configure shared mailboxes properly — individual accounts granted delegated access — and the same workflow becomes compliant.

Notice the common thread: none of these are platform failures, and the BAA is irrelevant to all four. They're configuration and policy failures — the exact layer the "we signed the BAA" answer skips.

Emailing Patients: The Consent Nuance

Practices get patient email wrong in both directions. Some refuse to email patients at all, citing HIPAA — which frustrates patients and isn't what the rule says. Others email freely, assuming a reply from the patient constitutes permission for anything — which isn't what the rule says either.

The actual rule has a nuance worth knowing precisely: patients have the right to request communication by unencrypted email, and you may honor that request — if you've warned them of the risk and documented both the warning and the request. The right belongs to the patient, not to the practice: it covers that individual, by their choice, and it is not a general license to send unencrypted PHI. "The patient emailed us first" is not documentation.

The safer default — and the one we recommend practices standardize on — is the secure-link pattern: the email itself carries no PHI, just a notification and an authenticated link; the actual content sits behind the portal or a secure-message viewer. The patient experience is one extra click; in exchange, a misaddressed message discloses nothing, forwarded messages carry nothing, and the sensitive content lives inside a system you control. Reserve documented-consent unencrypted email for patients who explicitly want it, and route everything else through the link.

Two boundaries to keep in view. Marketing email is a different regime — sending promotional content to patient lists raises authorization requirements beyond the scope of this article, so treat any "let's email our patients about the new service" idea as a compliance question first. And texting is its own discipline entirely: standard SMS is unencrypted, and the consent, platform, and policy requirements for compliant patient texting — along with phone and voicemail channels — are covered in depth by our sister publication Talk Is Cheap in its guide to HIPAA compliant communications. Don't assume email rules transfer to those channels; they don't.

Retention: Email Is Part of the Record

Email retention is where compliance and records management meet, and most practices have never made a deliberate decision about it.

Two clocks matter. HIPAA requires compliance documentation — policies, risk assessments, authorizations, and correspondence evidencing them — to be retained for six years. Separately, any email that functions as part of a patient's designated record set — clinical back-and-forth with the patient, referral communications, documentation of decisions — falls under medical-record retention rules, which in Texas generally means at least seven years for adults and longer for minors.

The operational translation: deletion should be governed by policy, not by whoever cleans out their inbox. Configure retention rules in the platform so mail is preserved for your required periods and disposed of on schedule afterward — because retention has a second edge: mail kept forever is discoverable forever, and a breach of a mailbox holding fifteen years of patient correspondence is a fifteen-year breach. Litigation-hold capability matters here too; qualifying business tiers include it, and it's one more reason the plan tier from the three-part test isn't a formality.

The Configuration Checklist

Hand this to whoever administers your tenant — in-house or your IT partner — and ask them to return it with each line marked done, scheduled, or not applicable with a reason. That returned document, dated and filed, is itself the kind of evidence that audits reward.

Identity and access

Encryption

Data loss prevention

Retention

Audit

Where This Lands

Email is the system every employee touches every hour, which is why it leaks more PHI than any other channel — and why it rewards deliberate setup more than almost any other compliance investment. The pattern of this article is the pattern of the full HIPAA guide: the paperwork makes you eligible, the configuration makes you defensible, and the documentation proves it.

If you'd rather not run the checklist alone, this is standing work for our compliance support practice: we audit the tenant against exactly these categories, close the gaps, and hand you the findings in writing — the before-and-after an auditor actually wants to see. Either way, run the checklist. The BAA you signed is only as good as the tenant behind it.

Scott McAuley is the founder and CEO of Texas Management Group, and founder of Talos Automation and Talk Is Cheap — 25+ years running IT, communications, and automation for Texas businesses.

Frequently Asked Questions

Is Microsoft 365 or Google Workspace HIPAA compliant?

Either can be — neither is by default. Three things must hold at once: a qualifying business plan (consumer and some entry-level tiers offer no BAA at all), a deliberately executed BAA, and real configuration — enforced encryption, DLP rules, retention policies, MFA everywhere, audit logging on. A tenant with a BAA and default settings is licensed, not compliant.

Does a signed BAA make our email HIPAA compliant?

No. The BAA governs the platform vendor's obligations; it does nothing about your tenant's behavior. An unconfigured tenant with a signed BAA can still auto-forward PHI off-platform, send unencrypted attachments, and run shared logins that erase the audit trail. The agreement is necessary; configuration is what actually protects the data.

Can we email patients directly under HIPAA?

Yes, carefully. Patients may request unencrypted email after being warned of the risk — document the warning and the request, and remember it covers only that patient. The safer default for everyone else is the secure-link pattern: the email carries an authenticated link, and the PHI stays behind the portal.

What are the most common ways practices break email compliance without knowing?

Staff forwarding work mail to personal accounts, auto-forward rules (user convenience or attacker persistence) copying mail off-tenant, unencrypted PDF attachments of records, and shared mailboxes accessed through one shared login. All four are configuration and policy failures the BAA does nothing to prevent — and all four are closeable with DLP, forwarding restrictions, and delegated access.

How long do we need to keep emails under HIPAA?

Six years for compliance documentation under HIPAA, and medical-record retention rules — at least seven years for adults in Texas, longer for minors — for any email that is part of the designated record set. Configure platform retention policies so preservation and deletion follow the schedule rather than individual inbox habits.

About the Author

Scott McAuley is a Marine Corps veteran and 25-year IT executive. He is President & CEO of Texas Management Group, founder of Talos Automation, and creator of Talk Is Cheap, and was named IT Services CEO of the Year 2023. Full bio at scottmcauley.com →