Email & BAAs
Does your email need a BAA? The gap careful practices miss
Published July 24, 2026
The company that runs your email can see what lands in your inbox — including the things clients send about their care, even when you’ve asked them not to. A Business Associate Agreement (BAA) is the contract that makes it okay for them to handle that. Most solo and small practices have a gap here and don’t know it.
The mistake careful practices make
A therapist we worked with — let’s call her Leslie — believed she was fully covered. Her clinical records lived in a proper records system, and she had every client sign an agreement not to share personal health information over email. She thought that was enough.
It wasn’t. Her email was personal Gmail, and Google’s free Gmail doesn’t come with a BAA. A client agreement doesn’t move the responsibility off you — HIPAA holds the practice responsible, not the client. If a client emails appointment details, insurance questions, or anything about their care to an inbox that isn’t covered, that can count as a violation — even though you never asked them to. And clients do email these things, constantly, no matter what they signed.
If it’s ever looked at after a breach, the federal office that enforces HIPAA doesn’t ask whether you meant to get health information by email. An early question is simpler: did you have a BAA with your email company? Without one, the penalties are real — they can run from a few hundred dollars into the millions.
One question decides most of it: which email do you use?
- Free Gmail (personal account). Google does not offer a BAA for it. No setting fixes this — closing the gap means moving to a plan that carries one.
- Free Outlook.com or Hotmail. Same story: Microsoft only offers its BAA on paid business and enterprise plans, even if the free inbox is used exclusively for your practice.
- Google Workspace (paid). A BAA is available — but it is not enabled by default. Sign in at admin.google.com → Account → Account settings → Legal and compliance, and look for the HIPAA Business Associate Amendment. Once accepted, it covers Gmail, Drive, Calendar, and other core services.
- Microsoft 365 Business or Enterprise. The BAA comes with the plan — Outlook and OneDrive are covered. Personal and family plans are not; your subscription page should say “Microsoft 365 Business” Basic, Standard, or Premium.
- Hushmail healthcare plans. The BAA is bundled in from the start.
- Something else? Ask the provider whether they offer a HIPAA BAA. Several that market to healthcare do — ProtonMail for Business, Virtru, and Paubox among them. If they don’t, or you can’t get a clear answer, treat it as a gap.
What doesn’t need a BAA
Not everything that touches a client’s name needs a contract. Running a payment is the piece HIPAA deliberately leaves out: Square doesn’t need a BAA just to take your payments, and your bank doesn’t need one to deposit a client’s check — moving the money is the exempt part. And emailing a client their own bill isn’t a confidentiality problem either; people are allowed to have their own information. Two small things keep it clean: send it to an address the client gave you, and keep your email on a plan covered by a BAA — which is the same question as above.
Close it this week
This is one of the most straightforward gaps in all of HIPAA to close. Identify which provider your practice email actually runs on. If it’s a free personal account, move to a plan that carries a BAA. If it’s Workspace or Microsoft 365, confirm the agreement is actually in place — then write down the date you accepted it and where your copy lives. The free assessment’s first chapter walks this exact check with you, question by question, and puts the answers in your Security Manual so the paper trail exists before anyone asks for it.
Free — no account needed to start, and your answers never leave your browser. Not legal advice: for questions about your specific obligations, talk to a healthcare attorney.