CompyMax

HIPAA compliant email providers

Sending anything about a patient by email puts the message, its attachments and often its subject line into someone else's system. This is the category most small organizations need first and get wrong earliest.

Email is the category most small organizations need first and get wrong earliest, because the failure is invisible. Nothing bounces, nobody complains, and a message about a patient sits in an account that has no agreement behind it. The two routes into this category are genuinely different: either the mail platform you already pay for is covered once somebody accepts the right document, or you buy a dedicated secure email product that sits in front of it.

If you already run a business mail platform, the work is usually administrative rather than commercial. Coverage tends to hang on an amendment an administrator has to accept in a console, on a paid managed account with your own domain, and on the mail app being named on the vendor's list of covered services. A personal address on a free consumer account cannot be brought into scope at all, whatever settings you change.

Dedicated secure email is worth the money when you need encryption applied without asking staff to remember, or inbound filtering, or archiving you can produce on demand. Read the plan table closely here. Vendors in this category commonly sell near-identical mailboxes to healthcare, small business and legal customers, and the agreement is included on the healthcare line only. Some also route non-US customers to a different document entirely.

5 email providers compared

5 of 5 can be used with patient information under a signed agreement. Each row is drawn from that vendor’s published documentation as read on the date shown — open an entry for the full conditions and sources.

VendorVerdictAgreement and planHow to get itNot coveredReviewed
GmailGmail in Google WorkspaceConditionalA Google Workspace or Cloud Identity subscription. Google names no edition requirement.Sign in as a super administrator → Admin console → Account settings → Legal and compliance → accept the amendment.Free personal Google accounts, which have no Admin console and no Services Agreement for the amendment to attach to.
HushmailHushmail for Healthcare and Hushmail for ProfessionalsConditionalHushmail for Healthcare (Basic, Essentials or Growth), plus Hushmail for Professionals. Not on Small Business, Law or Personal plans.Choose a Hushmail for Healthcare plan at signup, enter your business name when prompted, and sign the agreement Hushmail presents during account creation.Hushmail Small Business plans, which show 'No' against the agreement on all three tiers.
LuxSciLuxSci secure email, forms, text and hostingConditionalIncluded with LuxSci plans at no additional cost. The gate is signing and account designation rather than a pricing tier.Open LuxSci's agreement page, have an authorised officer complete the form, and return it using their electronic signature field.Any message where a user has indicated the content does not contain patient information, for example by opting out of encryption.
PauboxPaubox Email SuiteYesAll plans. Paubox includes the agreement with every account and lists it as a feature of Standard, Plus and Premium alike.Nothing to negotiate — Paubox requires every customer to agree before configuring email. Download your copy from their agreement page, or contact support if you signed up before 10 November 2017.Bulk commercial email through Email Suite, which the acceptable use policy prohibits.
VirtruVirtru email encryption and Secure Share for Gmail and OutlookConditionalPaid packages — the signed agreement appears as a Business-tier feature. Not offered to free Personal Privacy users.Email baa@virtru.com as directed in section 11.9 of the Subscription Agreement, or contact Virtru sales, and execute before sending patient information.Free Virtru for Personal Privacy accounts.

What to check before you adopt one

  • Establish who has to accept or sign, and get evidence of it. Coverage frequently depends on a named administrator accepting an amendment in a console, or an officer with authority to bind the organisation signing and returning a form — paying the invoice does neither.
  • Check that the specific storefront or plan line you are buying includes the agreement, because several vendors sell visually identical mailboxes to healthcare, small business and legal customers with the agreement on the healthcare tier alone.
  • Ask whether encryption is automatic or a per-message choice by the sender. Anything that depends on staff remembering to switch it on will be forgotten, and a per-message opt-out can push that message outside the agreement's scope.
  • Separate outbound from inbound. Where a product sits in front of your existing mailboxes, outbound protection usually begins only after an SPF and gateway change, and inbound filtering only after the MX record is repointed — often a higher tier.
  • Confirm whether archiving, retention and data loss prevention are on your plan, since these are the features an auditor or a payer questionnaire asks you to produce and they are routinely reserved for the top tier.
  • Get the vendor's position on add-ons, mail plug-ins and third-party clients in writing. These are commonly excluded by name, and they are the most likely thing already installed.
  • Where a product only encrypts or protects mail hosted elsewhere, remember you need an agreement with the mailbox provider underneath as well. One without the other leaves the stored mail uncovered.

The expensive mistake

Assuming the subscription did the work. A practice pays for a business mail platform for years, believes the paid account implies coverage, and nobody with administrative rights has ever opened the page where the amendment is accepted. The same mistake in a different shape is buying a secure email product on the wrong plan line, or updating SPF but never repointing MX, so outbound mail is protected while every inbound patient reply arrives unfiltered. Settle who accepted what, on which plan, and keep the evidence where you can find it.

Tracking which of these your organization uses?

The vendor and BAA register keeps every tool that touches patient information, its agreement status and its renewal date in one place — seeded from this research. See pricing.

Information, not certification and not legal advice. Each entry reflects that vendor’s published documentation as read on the date shown on its page. Vendors change terms without notice — confirm anything you rely on directly with them.