LCSW, Therapist, Private Practice Owner, and social media coach based in Raleigh, NC. My work centers on supporting children, teens, and young adults through anxiety, trauma, and meaningful life transitions — both in the therapy room and beyond it. My hope is this resource is a space for modern mental health insights that feel grounded, accessible, and human - what therapy should be!

If you’re a therapist in private practice, chances are you’ve thought about HIPAA compliance. Your EHR is compliant. Your telehealth platform has a BAA. You feel like you’ve checked the boxes.
That was me too. Until I started actually looking into my email.
I was using Gmail and Outlook like most people. Big platforms, trusted names, used by millions of professionals. I assumed that because they were the biggest providers out there, they must be compliant. Honestly it never even occurred to me to question it.
Here’s what I learned: Gmail and Outlook are not HIPAA compliant by default. Not even close. Unless you’re on a specific business plan with a signed Business Associate Agreement and proper encryption settings configured, your standard account does not meet HIPAA requirements for protected health information. And even then, Google and Outlook prioritize delivery over security, so there’s the potential for emails to be sent unencrypted.
Every intake inquiry I responded to. Each coordination email with a referring provider. Every appointment reminder. Potentially non-compliant.
That was a wake-up call.
For your email to be truly HIPAA compliant as a therapist or private practice owner, you need three core things — and all three matter equally.
First, a signed Business Associate Agreement with your email provider. This is non-negotiable. A BAA is a legal document that holds your vendor accountable for protecting any protected health information that passes through their system. Without it, you have no documented assurance that your email provider is handling patient data responsibly — and no legal protection if something goes wrong.
Second, encryption of messages in transit and at rest. This means your emails are scrambled and unreadable if they’re ever intercepted, both while they’re being sent and while they’re sitting in storage! A lot of people assume their emails are encrypted because their connection is secure (me – I am people 😬) — but that’s not the same thing. True encryption for healthcare communication is a specific technical standard, and most default email settings don’t meet it.
Third, and this one is underrated — a system that actually works for your patients in real life. Some HIPAA compliant email solutions require patients to log into a separate portal, create an account, or jump through hoops just to read a routine message from you. In theory that sounds secure. In practice it creates friction that patients abandon, which means important communications go unread. The best solution is one that keeps things simple and seamless for everyone.
Before you do anything else, take five minutes and honestly answer these questions:
Do you have a signed BAA with your current email provider? This isn’t buried in their terms of service — it’s a separate document you would have actively signed. If you’re not sure, you probably don’t have one.
Are your emails encrypted in transit and at rest? Most standard Gmail and Outlook accounts are not, even if you use strong passwords and two-factor authentication. Encryption and account security are two different things.
Have you sent any patient-related communication through your personal or standard business email? Intake forms, insurance coordination, referral notes, appointment details — all of these can contain PHI. If the answer is yes, that’s worth addressing.
And the big one: if a patient filed a HIPAA complaint today, would your email communication hold up to scrutiny? If the answer makes you uncomfortable, that’s important information.
You don’t need to panic — but you do need to look at this. HIPAA violations related to email are among the most commonly cited for small healthcare practices, and the fines can be significant even for unintentional violations.
I’m currently in the process of setting up my practice email on Paubox, and so far I’m really impressed with how straightforward it is. Every message is automatically encrypted — I don’t have to remember to do anything differently. Patients receive emails directly in their inbox with no portal login required. And they provide a signed BAA, which is the compliance piece that matters most.
I’ll be sharing a full step-by-step breakdown of how to make the switch in a future post — because I know “HIPAA compliant email setup” sounds intimidating and I want to show you it really doesn’t have to be. Stay tuned for that one.
HIPAA compliant email for therapists in private practice isn’t a nice-to-have — it’s a foundational piece of running an ethical, legally protected practice. And it’s one that a surprising number of us, myself very much included, have been unknowingly overlooking.
The uncomfortable truth is that good intentions don’t protect you from a HIPAA violation. Using a well-known email platform doesn’t protect you. Assuming your EHR covers everything doesn’t protect you. What protects you is actually verifying that every system handling protected health information in your practice meets the standard — and email is one of the easiest things to overlook precisely because it feels so routine.
The good news is this is also one of the easier things to fix once you know about it. It doesn’t require overhauling your whole practice or learning a complicated new system. It requires switching to a platform built for this — and there are good options out there.
If you want to get ahead of this now, Paubox is where I’m starting. Use code MADDIE for $250 off while you evaluate whether it’s the right fit for your practice.
And keep an eye out for my next post where I’ll walk through the full setup process — step by step, without the tech overwhelm.
This post is sponsored by Paubox. All opinions are my own.
LCSW, Therapist, Private Practice Owner, and social media coach based in Raleigh, NC. My work centers on supporting children, teens, and young adults through anxiety, trauma, and meaningful life transitions — both in the therapy room and beyond it. My hope is this resource is a space for modern mental health insights that feel grounded, accessible, and human - what therapy should be!
Be the first to comment