Practice email: your domain, a BAA, and two-factor from day one
Summary
A HIPAA-ready practice email setup needs a custom domain rather than a free consumer address, a business email provider willing to sign a business associate agreement, encryption in transit and at rest, and two-factor authentication turned on before the first patient message arrives. Any vendor creating, receiving, maintaining, or transmitting protected health information on the practice's behalf is a business associate requiring that signed BAA — a consumer email plan with no BAA option is disqualified regardless of its marketing.
By Gale Editorial · Updated 2026-07-27. Every figure cited to a dated source. How we write.
How do I set up practice email properly?
A HIPAA-ready practice email setup starts with a custom domain rather than a free consumer address, a business email provider willing to sign a business associate agreement, encryption in transit and at rest, and two-factor authentication turned on before the first patient message ever arrives. Any email vendor that creates, receives, maintains, or transmits protected health information on the practice's behalf is a business associate requiring a signed BAA, and a consumer email plan with no BAA option is disqualified regardless of how secure its marketing claims it is 1Ref 1HHS Office for Civil Rights (2026).Business Associates.That any vendor creating, receiving, maintaining, or transmitting PHI on the practice's behalf, including an email provider, is a business associate requiring a signed BAA..
Setting this up before opening day, rather than migrating a personal address to a business one mid-practice, avoids the harder problem of moving years of correspondence and matching client expectations to a new address after they've already learned the old one.
Why a free personal address doesn't work
A free consumer email address not covered by a business associate agreement is disqualified for practice use the moment a patient email could contain protected health information, which in behavioral health practice is nearly every incoming message — from a scheduling request naming a specific concern to a records request. Most major email providers do offer a compliant business tier with a signed BAA available, so the fix is usually upgrading to that tier under the practice's own domain rather than switching providers entirely.
A custom domain — the practice's own name rather than a generic provider suffix — also signals legitimacy to patients and referral sources, and it keeps the practice's address portable if the underlying provider ever changes.
Getting the business associate agreement signed
Before sending a single patient-facing email, confirm the provider's BAA is actually signed and on file, not just available somewhere in the terms of service the practice never executed; several major business email platforms require actively requesting and accepting the BAA through an admin console rather than including it by default. The Security Rule requires administrative, physical, and technical safeguards for electronic PHI scaled to the size of the practice, and a signed BAA with the email vendor is the paperwork foundation those safeguards sit on 2Ref 2HHS Office for Civil Rights (2026).Summary of the HIPAA Security Rule.That the Security Rule requires administrative, physical, and technical safeguards for ePHI, scalable to practice size, resting on a signed BAA with the email vendor..
Filing a copy of the signed BAA somewhere retrievable — not just an email confirmation that could itself get lost — matters if a security incident or an audit ever asks the practice to produce it.
Encryption, two-factor, and the account-takeover risk
Two-factor authentication on the email account is the single highest-leverage security step available to a solo practice, since a compromised password without a second factor gives an attacker the same access a stolen master key would give to a cabinet holding every patient's correspondence. HHS's 405(d) program publishes cybersecurity practices sized for a small practice specifically because a solo clinician isn't going to hire a security team, and the same device setup discipline that governs every phone and laptop in the practice applies to the email account too 3Ref 3HHS 405(d) Program (2026).HHS 405(d) — Aligning Health Care Industry Security Approaches.That HHS's 405(d) program publishes a small-practice cybersecurity baseline that includes multi-factor authentication for accounts like practice email..
Email is also the most common ransomware entry point, arriving as a convincing attachment or link rather than a dramatic break-in, and HHS's own guidance treats a ransomware encryption of electronic PHI as a presumed reportable breach unless a documented risk assessment shows a low probability of compromise — a presumption that runs against the practice by default, not in its favor 4Ref 4HHS Office for Civil Rights (2016).FACT SHEET: Ransomware and HIPAA.That a ransomware encryption of ePHI, often delivered by email, is presumed a reportable breach unless a documented risk assessment shows low probability of compromise.. A practice that has never actually tested restoring email from a backup is more exposed than one that has, since discovering a backup doesn't work during an actual ransomware incident turns a recoverable event into a much longer outage.
Domain and DNS basics worth getting right the first time
Registering the practice's own domain and pointing its mail records at whichever business email provider holds the signed BAA is a one-time setup most providers walk through directly in their onboarding flow, without requiring outside technical help for a single-domain, single-mailbox setup. Configuring the domain's sender authentication records — the settings that tell other mail servers the practice's messages are legitimate — reduces the odds that patient-facing email lands in a spam folder instead of an inbox, a common and avoidable failure for a newly registered domain.
A generic inbox name like info@ or contact@ works fine for a solo practice and avoids tying the address to one specific staff member's name, which matters if the mailbox is ever handed to someone else later. None of this requires choosing the most expensive tier a provider offers; the BAA availability and the security features that come with it, not the price point, are what actually distinguish a compliant setup from a consumer one.
Records requests and the clock they start
A patient emailing to request their records starts a clock the practice needs to track regardless of the channel it arrived on: patients have a right to inspect and obtain copies of their health information within 30 days, with one permitted 30-day extension, for a reasonable cost-based fee, though psychotherapy notes are excluded from that access right 5Ref 5HHS Office for Civil Rights (2026).Individuals' Right under HIPAA to Access their Health Information.That patients have a right to inspect and obtain copies of records within 30 days (one extension), for a reasonable fee, with psychotherapy notes excluded, relevant when a request arrives by email.. Practice email is not itself a records-delivery system, but it is very often where that request first lands, which makes a documented process for routing it to whoever handles records requests worth setting up before the first request actually arrives.
A short written procedure — who reads incoming mail, how a records request gets flagged and forwarded, and where the 30-day deadline gets tracked — turns this from a one-off scramble into a repeatable step, which matters more once the practice is busy enough that email isn't checked constantly. Practice email also intersects with the practice line and any e-fax service the practice runs, since all three routinely carry the same category of correspondence and deserve the same BAA-and-encryption discipline rather than being treated as separate problems.
Common questions
Run your practice on Gale
The software is free. Gale earns one flat 3.5% all-in per paid transaction — only on transactions that actually pay. No subscription, no setup fee, no network cut.
Start or manage a practice →References
- 1.HHS Office for Civil Rights (2026). Business Associates. U.S. Department of Health and Human Services. linkThat any vendor creating, receiving, maintaining, or transmitting PHI on the practice's behalf, including an email provider, is a business associate requiring a signed BAA.
- 2.HHS Office for Civil Rights (2026). Summary of the HIPAA Security Rule. U.S. Department of Health and Human Services. linkThat the Security Rule requires administrative, physical, and technical safeguards for ePHI, scalable to practice size, resting on a signed BAA with the email vendor.
- 3.HHS 405(d) Program (2026). HHS 405(d) — Aligning Health Care Industry Security Approaches. U.S. Department of Health and Human Services. linkThat HHS's 405(d) program publishes a small-practice cybersecurity baseline that includes multi-factor authentication for accounts like practice email.
- 4.HHS Office for Civil Rights (2016). FACT SHEET: Ransomware and HIPAA. U.S. Department of Health and Human Services. link ✓That a ransomware encryption of ePHI, often delivered by email, is presumed a reportable breach unless a documented risk assessment shows low probability of compromise.
- 5.HHS Office for Civil Rights (2026). Individuals' Right under HIPAA to Access their Health Information. U.S. Department of Health and Human Services. linkThat patients have a right to inspect and obtain copies of records within 30 days (one extension), for a reasonable fee, with psychotherapy notes excluded, relevant when a request arrives by email.
https://www.gale.care/for-providers/spc-practice-email-domain · 5 sources. Competitor details are cited to dated public sources and maintained as they change; figures are estimates, not commitments. Synthetic demonstration.