Saved · this browser
Chapter 1 · §164.314(a)

Email and Business Associate Agreements

The company that runs your email can see what lands in your inbox — including the things clients send about their care, even when you’ve asked them not to. A Business Associate Agreement(BAA) is the contract that makes it okay for them to handle that. Most solo or small practices have a gap here and don’t know it.

Why this chapter exists, in plain English

A therapist we worked with — let’s call her Leslie — believed she was fully covered. She used TherapyNotes for clinical records and had her clients sign an agreement not to share personal health information via email. She thought that was enough.

It wasn’t. Her email was personal Gmail, and Google’s free Gmail doesn’t come with a BAA. Having clients sign an agreement doesn’t move the responsibility off youHIPAAholds the practice responsible, not the client. If a client emails appointment details, insurance info, or anything about their care to an inbox that isn’t covered, that can count as a violation — even though you never asked them to.

If it’s ever looked at after a breach, the federal office that enforces HIPAA doesn’t ask whether you meantto get health information by email. The first thing they ask is: did you have a BAA with your email company? Without one, the fines are real — they can run from a few hundred dollars into the millions.

The good news: this is one of the most straightforward gaps to close. Let’s figure out where you stand.

Common questions: Square, your bank, and emailing a bill

Do I need a BAA with Square (or whoever takes my payments)? No — not just to take payments. Running a charge is the one piece HIPAA deliberately leaves out, the same reason your bank doesn’t sign one to deposit a client’s check. Square is just moving the money. (If you ever use Square for more than payments — messaging clients, say — that part is a separate question.)

What about my bank? It sees the checks clients write me. Same answer: no BAA needed. A bank handling a payment falls under that same exception — moving the money is the exempt part, so that’s not something you put under contract. (It only changes if a bank does more than process payments — say, running your billing for you.)

Am I breaking confidentiality by emailing a client their bill? No. Sending people their own bill isn’t sharing it with anyone else — they’re allowed to have their own information. Two small things keep it clean: send it to an address the client gave you, and keep your email on a plan that’s covered by a BAA (the same Microsoft or Google question from the top of this chapter). It’s also fair to let clients know plain email isn’t perfectly private — and to jot a quick note in your records that you did.

So where does a BAA actually matter? Your email— because your inbox can carry the back-and-forth about care, not just a dollar amount. That’s the gap the rest of this chapter helps you close.

01

Discovery

3 questions

Which email provider do you use for anything patient-related — scheduling, appointment reminders, follow-ups, or messages from clients?

Do any of your clients ever email you about their care — appointment changes, symptoms, insurance questions, or anything related to their treatment?

Do you have a signed agreement with your clients about email communication?

02

Where you stand

Not quite there yet

Answer the remaining questions above to see your chapter resolution.

Can you help us make this better?

How easy is HIPAAPath to use so far?
HardEasy

Please don’t include patient information — this goes to us by email.