How to Email Medical Records Without Violating HIPAA

Emailing medical records does not automatically violate HIPAA. The rules permit email as a delivery method, but only when the sender applies reasonable safeguards, shares no more information than the purpose requires, confirms the recipient is someone entitled to receive it, and has the right agreements in place with any third-party email service. Most email-related HIPAA problems aren’t caused by email itself. They’re caused by skipping one of those steps.

When Email Is a Permitted Way To Send PHI

HIPAA lets covered entities use and share protected health information without patient authorization for treatment, payment, and healthcare operations. A hospital emailing a specialist about a referral, a clinic sending records to an insurer for claims processing, or providers coordinating internally on quality review all fall inside this permission.1eCFR. 45 CFR 164.506 – Uses and Disclosures to Carry Out Treatment, Payment, or Health Care Operations No separate patient sign-off is required for these routine uses, though the Security Rule’s safeguards still apply to the email system.

Patients also have the right to receive copies of their own records by email if that’s how they want them delivered. This isn’t the formal authorization process that governs disclosures for things like marketing; it flows from the right of access and the patient’s right to request confidential communications by alternative means.2eCFR. 45 CFR 164.522 – Rights to Request Privacy Protection for Protected Health Information

If a patient asks for unencrypted email and the provider has concerns, the provider should warn the patient about the risks and let the patient decide.3U.S. Department of Health & Human Services (HHS). Does the HIPAA Privacy Rule Permit Health Care Providers to Use E-mail to Discuss Health Issues and Treatment with Their Patients? If the patient still wants email, the provider can send it. If the patient finds unencrypted email unacceptable, the provider must offer another channel such as secure messaging, phone, or mail.

The Encryption Question, Cleared Up

The single biggest source of confusion about HIPAA and email is encryption. The Security Rule classifies encryption as an “addressable” implementation specification, not a “required” one.4eCFR. 45 CFR 164.312 – Technical Safeguards Addressable doesn’t mean optional. It means the organization has to decide whether encryption is reasonable and appropriate for its situation. If it is, encrypt. If it truly isn’t, document why and put an equivalent safeguard in place.

In practice, most organizations should be encrypting email that carries PHI. Costs have dropped, and telling an HHS investigator that encryption wasn’t reasonable is a hard argument to win. HHS has confirmed directly that the Privacy Rule does not prohibit unencrypted email for treatment-related communications, provided other safeguards are applied, such as limiting the type or amount of information disclosed.3U.S. Department of Health & Human Services (HHS). Does the HIPAA Privacy Rule Permit Health Care Providers to Use E-mail to Discuss Health Issues and Treatment with Their Patients?

When you do encrypt, federal guidance calls for Transport Layer Security (TLS) 1.2 at minimum, with TLS 1.3 preferred. TLS 1.0 and 1.1 are no longer considered adequate.5National Institute of Standards and Technology (NIST). Guidelines for the Selection, Configuration, and Use of Transport Layer Security (TLS) Implementations

Send Only What the Recipient Needs

Encryption doesn’t cancel the minimum necessary standard. The Privacy Rule requires covered entities to limit PHI in any communication to what’s needed for the purpose.6U.S. Department of Health & Human Services (HHS). How May the HIPAA Privacy Rule’s Minimum Necessary Standard Apply to Electronic Health Information Exchange Through a Networked Environment If a specialist needs lab results, send the lab results, not a decade of visit notes. Standard protocols can cover routine disclosures; non-routine requests need a case-by-case call on what’s actually necessary. The minimum necessary rule does not apply when a patient requests their own records, or when providers are communicating with each other for treatment.

One practical rule falls out of this standard: keep PHI out of subject lines. Subject lines show up in previews, notifications, and logs even when the message body is encrypted. “Lab results for John Smith – HIV panel” defeats every other safeguard behind it.

What Turns an Email Into a HIPAA Violation

The email itself isn’t the violation. The failure to apply the required safeguards is. The common failure modes:

  • Wrong recipient. Autocomplete suggestions, similar names, and typos drive a large share of reported breaches. Once PHI reaches someone who shouldn’t have it, you have an impermissible disclosure.
  • No safeguards at all. Sending PHI from a personal Gmail or Yahoo account with no encryption, access controls, or audit capability violates the Security Rule’s technical safeguards.4eCFR. 45 CFR 164.312 – Technical Safeguards
  • No business associate agreement. Using a third-party email service to handle PHI without a signed BAA violates the administrative safeguard requirements. If your provider hasn’t signed one, every PHI-carrying message is exposure.7eCFR. 45 CFR 164.308 – Administrative Safeguards
  • Sharing more than necessary. Sending an entire medical record when a prescription history was all that was asked for breaks the minimum necessary standard.
  • Ignoring a patient’s stated preference. If a patient has asked not to receive email and you send it anyway, that violates the confidential communications requirement.2eCFR. 45 CFR 164.522 – Rights to Request Privacy Protection for Protected Health Information

If You Send PHI to the Wrong Person

A misdirected email containing PHI triggers the Breach Notification Rule. Any impermissible disclosure is presumed to be a breach unless the organization can show a low probability that the information was compromised, based on a documented risk assessment covering four factors:8U.S. Department of Health & Human Services (HHS). Breach Notification

  • The nature of the PHI involved, and how easily someone could re-identify the patient.
  • Who received it: another covered entity, a stranger, or someone with a motive to misuse it.
  • Whether the email was actually opened or viewed, or recalled or deleted first.
  • What mitigation was taken, such as confirmation of deletion or a signed confidentiality agreement.

If the assessment can’t demonstrate low probability of compromise, affected individuals must be notified within 60 calendar days of discovery.9eCFR. 45 CFR 164.404 – Notification to Individuals Breaches affecting 500 or more people also require notification to HHS and prominent local media within the same 60-day window. Smaller breaches still have to be reported to HHS, but they can go into an annual log submitted within 60 days after the end of the calendar year.

What Violations Cost

HHS enforces HIPAA through its Office for Civil Rights (OCR), and penalties scale with the level of culpability. As of early 2026, the four tiers are:

  • Didn’t know and couldn’t reasonably have known: $145 to $73,011 per violation, up to $2,190,294 per year for identical violations.
  • Reasonable cause, not willful neglect: $1,461 to $73,011 per violation, same annual cap.
  • Willful neglect, corrected within 30 days: $14,602 to $73,011 per violation, same annual cap.
  • Willful neglect, not corrected: $73,011 minimum per violation, up to $2,190,294 per year.

Real settlements show what those brackets look like in practice. In early 2025, OCR settled a phishing-related breach investigation with Solara Medical Supplies for $3,000,000 and another with a healthcare network for $600,000. Both involved email systems that lacked adequate protection against unauthorized access.10U.S. Department of Health & Human Services (HHS). Resolution Agreements and Civil Money Penalties Settlements usually also carry a multi-year corrective action plan with ongoing HHS monitoring, which often costs the organization more than the fine itself.

Safeguards That Keep Email Compliant

Compliant email uses layered administrative, technical, and physical safeguards. No single measure carries the load on its own.11eCFR. 45 CFR Part 164 – Security and Privacy

Technical Controls

End-to-end encryption protects email in transit and at rest so that intercepted messages can’t be read without the decryption key. Use TLS 1.2 or higher for transmission. Restrict access to email accounts that handle PHI and require multi-factor authentication for login. Turn on audit logging so you can see who accessed what and when, which matters both for Security Rule compliance and for investigating anything that goes wrong.

Administrative Controls

Train staff regularly on what PHI looks like, when email is appropriate, and what to do when something goes wrong. Write policies that spell out what can be emailed, to whom, and under what conditions. Sign a business associate agreement with every third-party email provider before they touch PHI.7eCFR. 45 CFR 164.308 – Administrative Safeguards Major platforms such as Google Workspace and Microsoft 365 offer HIPAA-eligible configurations with BAAs, but the BAA doesn’t switch on by default. It has to be requested, signed, and paired with the correct account configuration.

Habits That Prevent the Common Mistakes

Double-check the recipient address before sending anything with PHI. Disable autocomplete in clinical systems where possible, or train staff to verify the suggested address matches the intended person. Keep PHI out of subject lines. When you attach records, password-protect the file and send the password through a separate channel. These are unglamorous habits, and they prevent the majority of reported email breaches.

How Long To Keep Emails That Contain PHI

HIPAA requires covered entities to retain documentation of privacy policies, procedures, and related communications for six years from the date of creation or the date the document was last in effect, whichever is later.12eCFR. 45 CFR 164.530 – Administrative Requirements Emails that document compliance activity, patient authorization decisions, or breach responses fall inside that six-year floor. State medical record laws often impose their own retention periods, and some run longer than HIPAA’s minimum. Medicare participation carries additional retention requirements that vary by program. Your email archiving setup needs to follow whichever period is longest.