Guide

Practice email: your domain, a BAA, and two-factor from day one

Summary

A HIPAA-ready practice email setup needs a custom domain rather than a free consumer address, a business email provider willing to sign a business associate agreement, encryption in transit and at rest, and two-factor authentication turned on before the first patient message arrives. Any vendor creating, receiving, maintaining, or transmitting protected health information on the practice's behalf is a business associate requiring that signed BAA — a consumer email plan with no BAA option is disqualified regardless of its marketing.

By Gale Editorial · Updated 2026-07-27. Every figure cited to a dated source. How we write.

How do I set up practice email properly?

A HIPAA-ready practice email setup starts with a custom domain rather than a free consumer address, a business email provider willing to sign a business associate agreement, encryption in transit and at rest, and two-factor authentication turned on before the first patient message ever arrives. Any email vendor that creates, receives, maintains, or transmits protected health information on the practice's behalf is a business associate requiring a signed BAA, and a consumer email plan with no BAA option is disqualified regardless of how secure its marketing claims it is 1.

Setting this up before opening day, rather than migrating a personal address to a business one mid-practice, avoids the harder problem of moving years of correspondence and matching client expectations to a new address after they've already learned the old one.

Why a free personal address doesn't work

A free consumer email address not covered by a business associate agreement is disqualified for practice use the moment a patient email could contain protected health information, which in behavioral health practice is nearly every incoming message — from a scheduling request naming a specific concern to a records request. Most major email providers do offer a compliant business tier with a signed BAA available, so the fix is usually upgrading to that tier under the practice's own domain rather than switching providers entirely.

A custom domain — the practice's own name rather than a generic provider suffix — also signals legitimacy to patients and referral sources, and it keeps the practice's address portable if the underlying provider ever changes.

Getting the business associate agreement signed

Before sending a single patient-facing email, confirm the provider's BAA is actually signed and on file, not just available somewhere in the terms of service the practice never executed; several major business email platforms require actively requesting and accepting the BAA through an admin console rather than including it by default. The Security Rule requires administrative, physical, and technical safeguards for electronic PHI scaled to the size of the practice, and a signed BAA with the email vendor is the paperwork foundation those safeguards sit on 2.

Filing a copy of the signed BAA somewhere retrievable — not just an email confirmation that could itself get lost — matters if a security incident or an audit ever asks the practice to produce it.

Encryption, two-factor, and the account-takeover risk

Two-factor authentication on the email account is the single highest-leverage security step available to a solo practice, since a compromised password without a second factor gives an attacker the same access a stolen master key would give to a cabinet holding every patient's correspondence. HHS's 405(d) program publishes cybersecurity practices sized for a small practice specifically because a solo clinician isn't going to hire a security team, and the same device setup discipline that governs every phone and laptop in the practice applies to the email account too 3.

Email is also the most common ransomware entry point, arriving as a convincing attachment or link rather than a dramatic break-in, and HHS's own guidance treats a ransomware encryption of electronic PHI as a presumed reportable breach unless a documented risk assessment shows a low probability of compromise — a presumption that runs against the practice by default, not in its favor 4. A practice that has never actually tested restoring email from a backup is more exposed than one that has, since discovering a backup doesn't work during an actual ransomware incident turns a recoverable event into a much longer outage.

Domain and DNS basics worth getting right the first time

Registering the practice's own domain and pointing its mail records at whichever business email provider holds the signed BAA is a one-time setup most providers walk through directly in their onboarding flow, without requiring outside technical help for a single-domain, single-mailbox setup. Configuring the domain's sender authentication records — the settings that tell other mail servers the practice's messages are legitimate — reduces the odds that patient-facing email lands in a spam folder instead of an inbox, a common and avoidable failure for a newly registered domain.

A generic inbox name like info@ or contact@ works fine for a solo practice and avoids tying the address to one specific staff member's name, which matters if the mailbox is ever handed to someone else later. None of this requires choosing the most expensive tier a provider offers; the BAA availability and the security features that come with it, not the price point, are what actually distinguish a compliant setup from a consumer one.

Records requests and the clock they start

A patient emailing to request their records starts a clock the practice needs to track regardless of the channel it arrived on: patients have a right to inspect and obtain copies of their health information within 30 days, with one permitted 30-day extension, for a reasonable cost-based fee, though psychotherapy notes are excluded from that access right 5. Practice email is not itself a records-delivery system, but it is very often where that request first lands, which makes a documented process for routing it to whoever handles records requests worth setting up before the first request actually arrives.

A short written procedure — who reads incoming mail, how a records request gets flagged and forwarded, and where the 30-day deadline gets tracked — turns this from a one-off scramble into a repeatable step, which matters more once the practice is busy enough that email isn't checked constantly. Practice email also intersects with the practice line and any e-fax service the practice runs, since all three routinely carry the same category of correspondence and deserve the same BAA-and-encryption discipline rather than being treated as separate problems.

Common questions

Not for anything touching patient information — upgrade to a covered business tier with a signed BAA under the practice's own domain instead, since a free consumer tier almost never offers one. Keep a separate personal account entirely apart from anything patient-facing, so the two inboxes never blur together.

Most do in a behavioral health practice, since even a scheduling message often names a concern or a reason for contact. Treating the mailbox as touching PHI by default, rather than judging each message individually, is the safer working assumption.

Switch providers. A signed BAA is not negotiable for any vendor whose service could touch protected health information, and a provider unwilling to sign one isn't a compliant option regardless of its other features, its price, or how secure its marketing claims to be.

Not named explicitly by that term, but the Security Rule requires access controls scaled to the practice's risk, and multi-factor authentication is the practical, low-cost way a small practice meets that expectation on an account holding years of patient correspondence and records requests.

Patients have a right to their records within 30 days, with one permitted 30-day extension, for a reasonable cost-based fee. Psychotherapy notes are excluded from that access right, so routing the request to whoever handles it correctly, and tracking the deadline, both matter.

Run your practice on Gale

The software is free. Gale earns one flat 3.5% all-in per paid transaction — only on transactions that actually pay. No subscription, no setup fee, no network cut.

Start or manage a practice →

References

  1. 1.HHS Office for Civil Rights (2026). Business Associates. U.S. Department of Health and Human Services. linkThat any vendor creating, receiving, maintaining, or transmitting PHI on the practice's behalf, including an email provider, is a business associate requiring a signed BAA.
  2. 2.HHS Office for Civil Rights (2026). Summary of the HIPAA Security Rule. U.S. Department of Health and Human Services. linkThat the Security Rule requires administrative, physical, and technical safeguards for ePHI, scalable to practice size, resting on a signed BAA with the email vendor.
  3. 3.HHS 405(d) Program (2026). HHS 405(d) — Aligning Health Care Industry Security Approaches. U.S. Department of Health and Human Services. linkThat HHS's 405(d) program publishes a small-practice cybersecurity baseline that includes multi-factor authentication for accounts like practice email.
  4. 4.HHS Office for Civil Rights (2016). FACT SHEET: Ransomware and HIPAA. U.S. Department of Health and Human Services. linkThat a ransomware encryption of ePHI, often delivered by email, is presumed a reportable breach unless a documented risk assessment shows low probability of compromise.
  5. 5.HHS Office for Civil Rights (2026). Individuals' Right under HIPAA to Access their Health Information. U.S. Department of Health and Human Services. linkThat patients have a right to inspect and obtain copies of records within 30 days (one extension), for a reasonable fee, with psychotherapy notes excluded, relevant when a request arrives by email.

https://www.gale.care/for-providers/spc-practice-email-domain · 5 sources. Competitor details are cited to dated public sources and maintained as they change; figures are estimates, not commitments. Synthetic demonstration.

Findability, by specialty

How practices like yours get found in local search and AI answers — the honest playbook, per specialty.

SEO for private practices · SEO for AI search / answer engines (all verticals)