Confirm the exact service and plan
Record the legal customer, covered service, included features, exclusions, renewal owner, and where the BAA is stored.
A business email platform is only the starting point. A medical practice still needs to decide who owns each mailbox, when PHI may appear, which destination is approved, what safeguards apply, and what record proves the handoff was controlled.
The route changes with the message. An appointment reminder, referral packet, patient attachment, billing file, and vendor screenshot should not inherit one blanket rule.
HHS permits electronic communication with reasonable safeguards, while the Security Rule requires appropriate administrative, physical, and technical safeguards for ePHI. The practical setup job is to define permitted routes, not to label one product “HIPAA compliant.”
A BAA, encryption feature, or business plan does not finish the setup. The practice must connect platform scope, risk analysis, access, patient preferences, workforce rules, approved alternatives, incident handling, and documented ownership.
This ledger is a planning aid, not a universal policy. The practice's risk analysis, legal/compliance guidance, contracts, systems, patient request, and clinical or records responsibilities determine the approved route.
Do not copy these examples into policy without review. State law, specialty rules, payer or vendor contracts, records obligations, and the facts of a patient request may change the appropriate route.
HHS explains that a cloud provider handling ePHI generally needs an appropriate business associate agreement, while the covered entity or business associate must still understand the environment, conduct risk analysis, and establish risk-management policies.
Record the legal customer, covered service, included features, exclusions, renewal owner, and where the BAA is stored.
Use named accounts, limit privileged roles, protect emergency access, and avoid shared administrator credentials.
Approve creation, delegation, shared mailbox access, forwarding, mobile use, offboarding, retention, and recovery ownership.
Include scanners, EHR notices, scheduling tools, website forms, billing systems, vendors, and applications that send as the domain.
Staff need usable portal, Direct, fax, phone, mail, or vendor routes when ordinary email is not the chosen path.
Retain the BAA record, risk decision, account review, configuration evidence, domain reports, training, exceptions, and remediation owners.
MFA can reduce account-compromise risk, but it does not replace mailbox review, authorized sender inventory, user lifecycle, device safeguards, or an approved response path.
Require strong MFA, prioritize phishing-resistant methods where appropriate, and protect privileged access.
Review delegates, shared access, forwarding rules, inbox rules, recovery methods, and dormant accounts.
Connect email access to screen lock, patching, encryption, approved apps, and lost-device procedures.
Inventory legitimate senders, publish SPF and DKIM correctly, monitor DMARC, and tighten policy deliberately.
Define who disables access, reviews sessions and rules, preserves needed records, resets credentials, and escalates.
These controls help receiving systems evaluate whether a sender is authorized and whether a message aligns with the visible domain. They reduce domain spoofing risk when correctly deployed, but they do not encrypt message content, approve a workflow, stop display-name impersonation, or make every connected sender safe.
HHS says providers may communicate with patients by email with reasonable safeguards. It also explains that patients may initiate email and may request alternative communication, while the provider should consider privacy risks and offer more secure methods when appropriate.
Use the practice's approved process to confirm the destination, communication preference, representative authority, and any confidential-communication request.
Use the least detail needed for the purpose. Subject lines, filenames, signatures, quoted replies, and attachments can reveal more than intended.
Explain the portal or approved alternative in plain language. A policy that staff and patients cannot follow will create workarounds.
Tenant access, MFA, shared mailboxes, forwarding, domain authentication, approved workflow mapping, staff-ready procedures, and evidence ownership.
If an account, device, patient message, payment, or ePHI may be affected now, use the practice's approved response process and current provider, insurer, privacy, legal, vendor, and regulatory resources. This page does not start incident response.
This article owns education and initial planning. Implementation, ongoing administration, formal safeguard work, and phishing education have dedicated owners.
These answers provide orientation, not a legal conclusion or a substitute for the practice's risk analysis, policy, contracts, and professional advice.
HIPAA does not create a blanket ban on email. HHS describes reasonable safeguards for patient email and requires the Security Rule's safeguards for ePHI. The appropriate route depends on the message, risk, recipient, workflow, and documented controls.
Office 365 can support HIPAA safeguards, but a subscription or BAA alone does not establish compliance. Confirm that the services you use are covered by the applicable agreement, then review administrator access, MFA, mailbox permissions, forwarding, audit visibility, and approved ways to send sensitive information. Available controls depend on the product and license. The practice still needs risk analysis, policies, workforce procedures, and ongoing review. See Microsoft's HIPAA and HITECH guidance. For an existing tenant, request a Microsoft 365 management review.
No single agreement or product setting establishes compliance. A BAA addresses the vendor relationship; the practice still needs risk analysis, appropriate safeguards, permitted-use decisions, access control, workforce procedures, and ongoing review.
Prefer named accounts and approved shared-mailbox delegation so access can be granted, reviewed, removed, and attributed. Avoid a common password that hides individual ownership or remains active after staff changes.
No. They help authenticate sending domains and reduce some spoofing risk. They do not encrypt message content, confirm a recipient, approve PHI use, or replace MFA and mailbox controls.
HHS says a provider may generally infer that email is acceptable unless the patient states otherwise, but the practice should still follow its safeguards, consider whether the patient understands the risk, limit content, and offer a more secure route when appropriate.
Start with mailbox ownership, administrator roles, MFA, forwarding and inbox rules, leavers, approved patient and referral routes, scanner and application senders, BAA records, SPF/DKIM/DMARC status, and the current account-compromise procedure.
HealthDesk does not certify products or legal outcomes. These current government sources support the bounded statements above; implementation must be evaluated in the practice's actual environment.
Share the platform, broad workflow, approximate user count, and the decision that needs an owner. Keep patient information and sensitive technical material out of this form.