Direct answer

HIPAA-compliant email requires more than encryption. A covered entity or business associate should evaluate permitted use, reasonable safeguards, access controls, risk analysis, workforce practices, incident response, data handling, and whether each service provider that handles ePHI requires a Business Associate Agreement.

Regulatory status — August 2026

HHS states that the HIPAA Security Rule currently in effect remains the operative rule. OCR’s proposed cybersecurity modifications—including more prescriptive requirements discussed in the 2025 NPRM—are still proposed, not final. This guide separates current requirements from proposed changes.

HHS: current Security Rule summary ↗ · HHS: proposed-rule fact sheet ↗

What makes an email workflow HIPAA compliant?

HIPAA does not certify an email product with a universal seal of approval. Compliance is determined by the regulated organization’s complete environment and behavior. That includes the people allowed to use the system, how access is granted and removed, which vendors handle electronic protected health information (ePHI), what safeguards are implemented, how risks are documented, and how incidents are handled.

A secure tool can support a compliant workflow, but it cannot replace the covered entity’s or business associate’s responsibilities. The same product may be appropriate for one use case and inappropriate for another.

HIPAA-compliant email requirements checklist

1. Identify the data and purpose

Determine whether messages contain PHI or ePHI, who is sending and receiving it, and whether the communication is for treatment, payment, operations, patient-requested communication, or another permitted purpose.

2. Perform risk analysis

Evaluate threats and vulnerabilities affecting confidentiality, integrity, and availability. Consider recipient mistakes, compromised devices, weak credentials, forwarding, downloads, backups, lost keys, and retained copies.

3. Control access

Limit access to authorized people. Define how users authenticate, how private keys or credentials are protected, and how access is revoked when staff roles change.

4. Protect messages and files

Choose technical safeguards appropriate to the risk. Encryption can reduce disclosure risk, but organizations should also consider endpoint security, metadata, recipient verification, and secure handling after download.

5. Review vendors and BAAs

If a vendor creates, receives, maintains, or transmits ePHI on behalf of a covered entity or business associate, assess whether the vendor is a business associate and whether a compliant agreement is required before use.

6. Set retention and deletion rules

Decide what must become part of the designated record set or another system of record. Automatic deletion can reduce stored exposure, but it does not eliminate separate legal, clinical, or operational retention duties.

7. Train the workforce

Teach users how to verify recipients, avoid including unnecessary information, protect credentials and keys, respond to suspicious activity, and use only approved communication channels.

8. Plan for incidents

Document who investigates suspected disclosures, how access is contained, how evidence is preserved, when notifications are assessed, and how corrective action is tracked.

Can healthcare providers email patients?

Yes. HHS states that covered healthcare providers may communicate with patients by email when reasonable safeguards are applied. Examples include checking an address for accuracy and confirming the patient’s preferred communication method. A patient’s request for unencrypted email should be handled under the organization’s policies and applicable guidance.

Do not confuse permission with zero risk

The fact that email can be used does not mean every email service, attachment workflow, or device configuration is appropriate. Document the chosen safeguards and the reason they fit the use case.

BAA and vendor questions to ask

  • Will the vendor create, receive, maintain, or transmit ePHI on your behalf?
  • Is a Business Associate Agreement available and executed before ePHI use?
  • What message content, files, timestamps, IP addresses, payment data, or logs are processed?
  • Who controls decryption keys, account recovery, and access revocation?
  • How long is encrypted content stored, and what happens after delivery?
  • What subprocessors and hosting providers participate in the workflow?
  • How are security incidents reported and investigated?
  • Can your organization satisfy record-retention and patient-access duties outside the messaging layer?
  • If voice or live calls are part of the workflow, evaluate room access, media encryption, retention, metadata, endpoints and the vendor relationship separately from written messaging.

Where AliasCloak fits

AliasCloak is a browser-based privacy messenger with generated mailbox identities, end-to-end encrypted mailbox messages and chat, encrypted file delivery up to 4 GB, local private keys, optional TOTP for new sessions, encrypted portable backups, and annual custom-alias leases.

Those features can support data minimization and private delivery, but they do not by themselves establish HIPAA compliance or a BAA. Confirm the live deployment, vendor relationship, retention settings, endpoint controls, and organization-wide safeguards before ePHI use.

Before using AliasCloak for ePHI

Confirm BAA status, permitted use, access and key-management procedures, endpoint security, record-retention needs, incident-response processes, and legal review. Do not assume a BAA is included merely because content is encrypted.

Official sources

Use primary guidance when building a healthcare communication workflow.