HIPAA compliant email

HIPAA compliant email

Secure, private, and anonymous messaging

HIPAA-compliant email is designed to offer secure, end-to-end encrypted, and anonymous email-like messaging that meets HIPAA standards. Ideal for healthcare providers, therapists, and anyone who requires maximum confidentiality.

Get started

Why choose HIPAA-compliant email?

Our service provides a seamless, secure communication platform that ensures privacy and compliance with healthcare regulations. Whether you're a healthcare provider or someone who values anonymity, our email-like messaging offers the highest standards of security.

End-to-end encryption

Messages and attachments are fully encrypted, ensuring maximum security from sender to receiver.

Anonymous messaging

No account needed. Simply use public keys or aliases, allowing true anonymity and privacy.

HIPAA compliance

Our platform is designed to comply with HIPAA regulations, making it suitable for healthcare communication.

How it works

Using HIPAA-compliant email is straightforward:


  1. Generate a public key: Start by creating a public key for receiving messages.
  2. Share your public key: Share your key with trusted senders to receive encrypted messages.
  3. Decrypt messages: Use your private key to read incoming messages securely.
  4. Enjoy anonymous communication: Communicate with peace of mind, knowing your data is secure.

HIPAA-compliant email overview: Insights from breaches, compliance standards, and service options

Email breaches in HIPAA-regulated entities

Recent reports highlight multiple email breaches across healthcare facilities. Entities like Southern Bone & Joint Specialists, Connally Memorial Medical Center, and Michigan Masonic Home have experienced unauthorized access to email accounts containing protected health information (PHI). Similarly, the Ambulatory Surgery Center of Westchester recently reported a breach impacting 22,000 patients due to a compromised email account.


Understanding HIPAA compliance for email

HIPAA (Health Insurance Portability and Accountability Act) compliance for email requires implementing safeguards to protect PHI. These measures include encryption, access controls, auditing, and secure transmission protocols. Compliance isn’t solely about technology—policy management, employee training, and a clear understanding of when and how patient information can be shared are essential.


Choosing HIPAA-compliant email services

Selecting the right HIPAA-compliant email service is crucial to avoid common violations. A compliant service should support encryption of PHI during both transmission and storage, ensure that a Business Associate Agreement (BAA) is in place, and provide mechanisms for monitoring access and usage. Neglecting these requirements can lead to breaches, fines, and reputational damage.


Evaluating Gmail, ProtonMail, and WhatsApp for HIPAA compliance

  • Gmail: Gmail can be HIPAA-compliant but only when used with Google Workspace Enterprise plans along with a signed BAA. It’s vital to configure Gmail properly, as the default consumer version doesn’t meet HIPAA requirements.
  • ProtonMail: ProtonMail offers HIPAA-compliant features, including end-to-end encryption and secure data centers in Switzerland. It is suitable for covered entities to send encrypted emails containing PHI to other ProtonMail users, provided that necessary BAAs and configurations are in place.
  • WhatsApp: WhatsApp, by default, is not HIPAA-compliant, as it does not meet the necessary safeguards for transmitting PHI. While it offers end-to-end encryption, it lacks the necessary administrative controls and audit capabilities required for HIPAA compliance.

Is it a violation to email patient names?

HIPAA regulations prohibit sharing PHI, including patient names, via unsecured channels without patient consent. However, email communication of patient information is permissible if adequate security measures are implemented and patient consent is obtained.


Why Encrypted Spaces is the best HIPAA-compliant email solution

Encrypted Spaces stands out as the best HIPAA-compliant email solution because it prioritizes patient confidentiality with strong end-to-end encryption. It automatically deletes messages upon receipt, ensuring minimal data exposure and risk of breach. Additionally, Encrypted Spaces provides secure email-like messaging without requiring real accounts, making it highly adaptable to the needs of healthcare professionals while ensuring regulatory compliance.