HIPAA compliant email providers
Sending anything about a patient by email puts the message, its attachments and often its subject line into someone else's system. This is the category most small organizations need first and get wrong earliest.
Email is the category most small organizations need first and get wrong earliest, because the failure is invisible. Nothing bounces, nobody complains, and a message about a patient sits in an account that has no agreement behind it. The two routes into this category are genuinely different: either the mail platform you already pay for is covered once somebody accepts the right document, or you buy a dedicated secure email product that sits in front of it.
If you already run a business mail platform, the work is usually administrative rather than commercial. Coverage tends to hang on an amendment an administrator has to accept in a console, on a paid managed account with your own domain, and on the mail app being named on the vendor's list of covered services. A personal address on a free consumer account cannot be brought into scope at all, whatever settings you change.
Dedicated secure email is worth the money when you need encryption applied without asking staff to remember, or inbound filtering, or archiving you can produce on demand. Read the plan table closely here. Vendors in this category commonly sell near-identical mailboxes to healthcare, small business and legal customers, and the agreement is included on the healthcare line only. Some also route non-US customers to a different document entirely.
Can be used with patient information
Each of these requires a signed agreement and, usually, specific settings. Open an entry for the exact conditions.
Gmail
ConditionalYes for Gmail inside a managed Google Workspace account once a super administrator accepts Google's amendment — a free personal Gmail address cannot be covered at all.
Hushmail
ConditionalOnly if you sign up on a Hushmail for Healthcare plan — the identically priced Small Business, Law and Personal plans are marked as not including a business associate agreement.
LuxSci
ConditionalYes — LuxSci includes the agreement at no extra cost, but an authorised officer must sign and return LuxSci's own form, and patient information must stay inside the services it lists as eligible.
Paubox
YesYes — every Paubox account includes a business associate agreement at no extra cost, and Paubox will not finish configuring your email until you have agreed to it.
Virtru
ConditionalYes on a paid Virtru package, but only after you email their BAA address and execute the agreement — Virtru does not issue it automatically, and its subscription terms require you to ask.
What to check before you adopt one
- Establish who has to accept or sign, and get evidence of it. Coverage frequently depends on a named administrator accepting an amendment in a console, or an officer with authority to bind the organisation signing and returning a form — paying the invoice does neither.
- Check that the specific storefront or plan line you are buying includes the agreement, because several vendors sell visually identical mailboxes to healthcare, small business and legal customers with the agreement on the healthcare tier alone.
- Ask whether encryption is automatic or a per-message choice by the sender. Anything that depends on staff remembering to switch it on will be forgotten, and a per-message opt-out can push that message outside the agreement's scope.
- Separate outbound from inbound. Where a product sits in front of your existing mailboxes, outbound protection usually begins only after an SPF and gateway change, and inbound filtering only after the MX record is repointed — often a higher tier.
- Confirm whether archiving, retention and data loss prevention are on your plan, since these are the features an auditor or a payer questionnaire asks you to produce and they are routinely reserved for the top tier.
- Get the vendor's position on add-ons, mail plug-ins and third-party clients in writing. These are commonly excluded by name, and they are the most likely thing already installed.
- Where a product only encrypts or protects mail hosted elsewhere, remember you need an agreement with the mailbox provider underneath as well. One without the other leaves the stored mail uncovered.
The expensive mistake
Assuming the subscription did the work. A practice pays for a business mail platform for years, believes the paid account implies coverage, and nobody with administrative rights has ever opened the page where the amendment is accepted. The same mistake in a different shape is buying a secure email product on the wrong plan line, or updating SPF but never repointing MX, so outbound mail is protected while every inbound patient reply arrives unfiltered. Settle who accepted what, on which plan, and keep the evidence where you can find it.
Tracking which of these your organization uses?
The vendor and BAA register keeps every tool that touches patient information, its agreement status and its renewal date in one place — seeded from this research. See pricing.
Information, not certification and not legal advice. Each entry reflects that vendor’s published documentation as read on the date shown on its page. Vendors change terms without notice — confirm anything you rely on directly with them.