A Single Unencrypted Email Cost This Health Plan $3.5 Million

In 2018, Anthem Inc. paid a record $16 million to settle HIPAA violations after a massive breach — but most people forget that the investigation began, in part, because of failures in how electronic protected health information (ePHI) was handled and transmitted. The truth is, OCR doesn't need a blockbuster breach to come after you. A single unencrypted email containing a patient's Social Security number and diagnosis can trigger an investigation that unravels years of neglected compliance.

If you're sending, receiving, or forwarding any protected health information over email, you need to understand HIPAA secure email requirements right now — not after a complaint lands on OCR's desk.

This post breaks down exactly what the law requires, where most organizations get it wrong, and what you can do this week to close the gap.

What Are HIPAA Secure Email Requirements, Exactly?

HIPAA secure email requirements are the set of administrative, technical, and physical safeguards that covered entities and business associates must implement before transmitting ePHI via email. These requirements come directly from the HIPAA Security Rule, which mandates protections for electronic protected health information at rest and in transit.

Here's the short version: if your email system can't ensure the confidentiality, integrity, and availability of ePHI during transmission, you can't use it to send PHI. Period.

The Security Rule doesn't name specific technologies. It doesn't say "use TLS 1.3" or "buy this vendor's product." What it does say is that you must implement encryption and access controls that are reasonable and appropriate for your organization. That flexibility is intentional — but it's also where most covered entities stumble.

The Four Technical Safeguards That Actually Matter

1. Encryption in Transit

This is the one everyone talks about. The HIPAA Security Rule lists encryption as an "addressable" specification under §164.312(e)(2)(ii). Addressable doesn't mean optional. It means you must implement it or document why an equivalent alternative is equally effective. In practice, I've never seen OCR accept "we decided not to encrypt" as a valid alternative.

At minimum, your email system should support TLS (Transport Layer Security) for server-to-server communication. For emails containing PHI, end-to-end encryption — where only the sender and recipient can read the message — is the gold standard.

2. Access Controls

Every email account that touches PHI needs unique user identification and authentication. Shared logins are a compliance disaster. Under §164.312(d), you need a mechanism to verify that the person accessing that inbox is who they claim to be. Multi-factor authentication isn't explicitly required, but it's become the de facto expectation in 2026.

3. Audit Controls

Can you prove who sent what, when, and to whom? The Security Rule at §164.312(b) requires you to implement hardware, software, and procedural mechanisms to record and examine activity in systems containing ePHI. If your email platform doesn't generate audit logs, you have a gap that OCR will find.

4. Integrity Controls

You must ensure that ePHI transmitted via email hasn't been improperly altered. Digital signatures and checksums are common tools. Under §164.312(e)(2)(i), you need a mechanism to confirm that the data your recipient receives is identical to what you sent.

The $2.3 Million Mistake: Sending PHI to the Wrong Address

In 2020, HHS settled with CHSPSC LLC for $2.3 million after a breach affecting over 6 million individuals. A critical finding: inadequate technical safeguards and poor access controls allowed unauthorized access to ePHI. While the breach involved multiple vectors, email mishandling was a contributing factor.

I've seen this pattern play out at organizations of every size. A medical assistant emails a patient's lab results to the wrong address. A billing department forwards a spreadsheet of claims data to a personal Gmail account. A provider replies-all on a thread that includes a patient's mental health records.

Every one of those scenarios is a potential breach under the HIPAA Breach Notification Rule. And once you trigger breach notification obligations, the costs multiply: forensic investigation, patient notifications, media notice if it's over 500 individuals, and OCR scrutiny.

"Can I Use Regular Email If the Patient Consents?"

This is the most common question I get, so let me answer it clearly.

Yes, a patient can consent to receive unencrypted email — but that doesn't eliminate your obligations. HHS guidance states that if a patient requests communication by unencrypted email, you should warn them of the risk and honor their preference. However, this applies only to communications with that specific patient. It doesn't cover emails between your staff, emails to other providers, or emails to business associates.

And patient consent doesn't exempt you from the Security Rule's requirement to have encryption capabilities in the first place. You still need a system that can encrypt. You're simply choosing not to use it for that specific patient interaction, with documented consent.

Where Most Organizations Fail: It's Not the Technology

In my experience, the encryption software is rarely the weak link. The weak link is your workforce.

Staff members bypass encryption portals because they're slow. Providers send PHI via text message because it's faster than logging into the secure system. New hires never get trained on which types of information require encryption. The IT department sets up a compliant email system, and then nobody uses it correctly.

This is why workforce training isn't a nice-to-have — it's a regulatory requirement under §164.530(b). Every member of your workforce who handles ePHI must understand your email policies. They need to know what qualifies as PHI, when encryption is required, and what to do if they accidentally send an unencrypted email containing patient data.

Our Annual HIPAA Refresher course covers email security practices alongside other critical compliance topics. If your team hasn't completed refresher training this year, that's a gap OCR will flag during an investigation.

Your HIPAA Secure Email Checklist for 2026

Here's what I tell every client to verify before they send another email containing PHI:

  • Encryption is enabled and enforced. Not just available — actually turned on by default for messages containing PHI.
  • Business associate agreements are signed. If you use a third-party email provider (Google Workspace, Microsoft 365, etc.), you must have a BAA in place. Without one, every email you send through that platform is a violation.
  • Access controls are configured. Unique logins, strong passwords, MFA enabled. No shared accounts.
  • Audit logs are active and reviewed. Someone on your team should be checking these regularly — not just when something goes wrong.
  • Your email policy is documented. It should specify who can email PHI, under what circumstances, to which recipients, and using what safeguards.
  • Workforce training is current. Not a one-time onboarding session. Annual refreshers, at minimum, with documentation that proves completion.
  • You have a breach response plan for email incidents. Your staff should know exactly what to do if PHI is sent to the wrong recipient.

The Business Associate Agreement Trap

I can't overstate this: using a major email platform does not make you HIPAA compliant by default. Google, Microsoft, and other providers offer HIPAA-eligible configurations, but you must sign a BAA with them and then configure the platform according to their compliance documentation.

Google's standard consumer Gmail accounts? No BAA available. Microsoft 365 personal plans? Same problem. If even one member of your staff is sending PHI through a personal email account without a BAA, your entire organization has a compliance failure.

What Happens When OCR Comes Knocking

During a compliance review or complaint investigation, OCR will ask for documentation. They want to see your risk analysis, your email security policies, your workforce training records, and your BAAs. They'll ask whether encryption was in place at the time of the incident. They'll review your audit logs.

If you can't produce these documents, the conversation shifts from "let's resolve this" to "let's calculate the penalty." Civil monetary penalties under HIPAA range from $137 to $68,928 per violation, with annual maximums reaching $2,067,813 per violation category. Those numbers come directly from HHS's enforcement page, adjusted for inflation.

Don't Wait for the Complaint

Most enforcement actions I've studied share a common origin: the organization knew it had gaps and didn't act. They planned to "get to it next quarter." They assumed their email was probably encrypted because IT said so two years ago. They never verified.

Start with a focused risk assessment of your email systems this month. Verify your encryption configuration. Confirm your BAAs are current. Schedule workforce training through a program like the HIPAACertify training catalog and document every completion.

HIPAA secure email requirements aren't ambiguous. The rules are clear. The penalties are public. The only variable is whether your organization acts before or after the investigation begins.