
Regular email is not automatically a HIPAA violation. HIPAA compliance for email rests on the Security Rule’s transmission security standard, 45 CFR 164.312(e), where encryption is addressable. Most practices should encrypt PHI sent to outside addresses, have a BAA with their email provider, and send unencrypted email only to patients who ask for it after a warning.
This is general information, not legal advice. The Microsoft details below come from Microsoft’s own pages, checked September 2026. For the setup itself, our business email encryption service covers any regulated firm and our email encryption setup and testing guide walks through recipient access; this post covers only what HIPAA asks of email.
Is regular email HIPAA compliant?
It can be, depending on how the message travels. HIPAA does not ban email. The transmission security standard asks you to guard ePHI sent over an electronic network against unauthorized access, and its encryption specification says to encrypt ePHI “whenever deemed appropriate.” Addressable does not mean optional. Under 45 CFR 164.306(d)(3) you implement the safeguard if it is reasonable and appropriate, or document why not and adopt an equivalent alternative.
What most people call regular email relies on TLS between mail servers. Microsoft’s TLS documentation (checked September 2026) is clear about the gap: TLS encrypts the connection, not the message, and by default Exchange Online sends a message without encryption if the recipient’s organization does not support TLS. Your email provider also stores every message, which makes it a business associate that needs a signed agreement (see our guide to business associate agreements). Microsoft includes one through its Data Protection Addendum, and Google offers one in the Workspace Admin console.
Which ways of sending patient information hold up?
| Method | What it protects | Where it fits |
|---|---|---|
| Opportunistic TLS, the Exchange Online default | The server connection, when the recipient’s server supports TLS | Internal mail and messages without PHI |
| Forced TLS through a connector | Requires an encrypted connection to a named partner domain | Labs, billing services and other partners you exchange PHI with often |
| Microsoft Purview Message Encryption | The message itself; outside recipients open it with a one-time passcode or by signing in | Patients and any outside address, including Gmail and Yahoo |
| Unencrypted email at the patient’s request | Nothing in transit | Only after the patient is warned of the risk and still wants it |
Do patients have to consent to unencrypted email?
Not with a formal consent form, but they do have to be warned. HHS’s own FAQ pages at hhs.gov refused our automated requests in September 2026, so we quote the rule’s preamble instead. In the 2013 Omnibus Rule, HHS wrote that covered entities “are permitted to send individuals unencrypted emails if they have advised the individual of the risk, and the individual still prefers the unencrypted email” (78 FR 5634). HHS said it expects only a notice that a third party could read the message, and that you are not responsible for unauthorized access in transmission when you send it that way at the patient’s request.
Two patient rights point the same way. A patient who asks for an electronic copy of records you hold electronically gets it in the form and format requested if it is readily producible (45 CFR 164.524(c)(2)(ii)), and providers must accommodate reasonable requests to receive communications by alternative means (45 CFR 164.522(b)). Record each preference where front-desk staff will see it.
How do you send HIPAA-compliant email in Microsoft 365?
- Confirm the BAA and the license. Microsoft’s BAA comes through its Data Protection Addendum, as our Microsoft 365 HIPAA compliance guide explains. Microsoft’s message encryption FAQ lists Purview Message Encryption in Microsoft 365 Business Premium, E3 and E5; Business Basic and Business Standard need Azure Information Protection Plan 1 added, and each user who benefits needs a license.
- Encrypt automatically. Build mail flow rules or Purview data loss prevention policies that encrypt messages containing patient identifiers, so nobody has to remember a button.
- Force TLS for regular partners. Microsoft names medical organizations among those that can require TLS through connectors for specific partners.
- Mind the limits. Purview Message Encryption does not protect OneDrive or SharePoint cloud attachments, and messages are capped at 25 MB including attachments, so attach files directly or share them with named people.
Then send a test to an outside mailbox, open it as a patient would, and keep the written policy with your Security Rule documentation for six years (45 CFR 164.316(b)(2)(i)). On Google Workspace, Gmail is covered once the BAA is accepted; our Google Workspace HIPAA guide lists what else to configure.
A rule change to watch
In January 2025 HHS proposed rewriting the Security Rule (90 FR 898). The proposal would drop the split between required and addressable specifications and require encryption of all ePHI at rest and in transit, with limited exceptions. In September 2026 the Federal Register still listed it as a proposed rule, and the eCFR text still marks encryption addressable. Our post on proposed HIPAA Security Rule changes tracks it. Building to the stricter reading now avoids a second project later.
Where NetSys fits
We set up encryption rules, data loss prevention and partner connectors for medical offices and dental practices as part of our HIPAA safeguards work, then document them for the risk analysis. The same engineers run the Microsoft 365 tenant, so the rules stay current as staff and partners change.
Frequently asked questions
Can a practice email lab results to a patient?
Yes, if the email is encrypted or the patient chose plain email after a warning. Send results through encrypted email or the patient portal by default. If a patient asks for regular email, tell them a third party could read it, note the preference, and then you may send it, as HHS explained in 2013.
Is TLS enough for HIPAA email?
Sometimes, for known partners. TLS protects the connection between servers, not the message, and Exchange Online falls back to sending without encryption when the other side does not offer TLS. Forced TLS with a named partner closes that gap. For patients and unknown recipients, message encryption is the safer default in a risk analysis.
Do emails between staff need encryption?
Usually not as an extra step on Microsoft 365. Microsoft says Exchange Online encrypts connections between its own servers with TLS 1.2 and sends mail within your organization over TLS automatically. Staff accounts and devices still need MFA, device encryption and access controls, because a compromised mailbox exposes the same messages.
What if staff email PHI to the wrong person?
Treat it as a possible breach and assess it. Under 45 CFR 164.402 an impermissible disclosure is presumed to be a breach unless a documented risk assessment shows a low probability of compromise, weighing the data involved, who received it, whether it was viewed, and mitigation. Warning prompts before sending reduce how often this happens.
Does HIPAA cover voicemail?
Yes, in two ways. A message left for a patient is a disclosure, so limit the detail others might overhear (45 CFR 164.530(c)) and honor requests to be contacted another way (45 CFR 164.522(b)). Voicemail with patient details that your phone system keeps as audio files or emailed transcripts is ePHI under the Security Rule.
Sources (checked September 2026)
- 45 CFR 164.312(e), the transmission security standard, and 45 CFR 164.306(d) on addressable specifications, eCFR, checked September 2026.
- Omnibus Rule, 78 FR 5566, including the unencrypted email discussion at 78 FR 5634, checked September 2026.
- HIPAA Security Rule proposed rule, 90 FR 898, published January 6, 2025, checked September 2026.
- Email encryption in Microsoft 365, Microsoft Learn, checked September 2026.
- How Exchange Online uses TLS to secure email connections, Microsoft Learn, checked September 2026.
- Message Encryption FAQ, Microsoft Learn, for plans, limits and cloud attachments, checked September 2026.
- 45 CFR 164.524 and 45 CFR 164.522, patient access and confidential communications, checked September 2026.
Discuss hipaa compliance services for your business.
Tell us about your current systems, the result you need and your timeline. We will discuss the work, responsibilities and pricing before you decide on an engagement.

