July 19, 2026
12 min read
By Albert Wong, PhD · Clinical Psychologist
The short answer
You can email clients — HIPAA allows it, with a documented warning about the risks and the client's documented preference. But every vendor that stores or transmits client information on your behalf must sign a Business Associate Agreement first, and no free consumer tier of anything (Gmail, Zoom, Dropbox) ever qualifies. Paid Google Workspace, Microsoft 365 business plans, and eligible paid Zoom plans all offer BAAs; with Google you must also formally accept the BAA in the Admin console, or you don't have one. The habit that makes all of it simpler: email for logistics, portal for everything clinical.
It's 9pm on a Tuesday. A client emails asking to move Thursday's session. You type back: "Sounds good, see you Thursday at 4 — and yes, we can absolutely talk about the medication anxiety then." Send. Kettle on, day done.
Somewhere in that sentence, you crossed a line you couldn't see. The scheduling half was defensible. The back half — a named clinical concern, tied to an identifiable person, sent from a free Gmail account that has never signed anything with anyone — is protected health information sitting on a server with no Business Associate Agreement behind it. Nothing bad will probably happen. That's the trouble with this whole topic: the water looks calm right up until it isn't, and the rocks were under the surface the entire time.
This guide is the map. What the BAA rule actually says, which vendors will sign one (and at what tier), the client-initiated-email nuance that confuses everyone, the honest version of the texting question, and a checklist of every vendor in a typical solo practice that needs an agreement you may not have.
HIPAA's business associate rule (45 CFR 164.502(e) and 164.308(b)) says: any vendor that creates, receives, maintains, or transmits protected health information on your behalf is your business associate, and you may not share PHI with them until they've signed a Business Associate Agreement — a contract making them legally responsible for safeguarding it. Your email host maintains and transmits every message you send. If a client's name plus anything about their care passes through that inbox, the host is handling PHI on your behalf.
Three corollaries do most of the work:
Think of your practice as a small boat. Every vendor that touches client data is a through-hull fitting — a deliberate hole below the waterline. Perfectly seaworthy, as long as each one is properly sealed. The BAA is the seal. An unsealed one doesn't leak on sunny days. It leaks in the storm — the breach, the audit, the board complaint — which is exactly when you can't fix it.
Tiers and product names shift, so treat the table as a July 2026 snapshot and confirm on each vendor's own HIPAA page before you rely on it. The shape of the landscape, though, has been stable for years:
| Vendor | BAA available? | Typical tier required |
|---|---|---|
| Gmail (free consumer) | No — ever | Not available at any price |
| Google Workspace | Yes | Any paid plan; admin must accept the BAA in the console |
| Microsoft 365 | Yes | Business/Enterprise plans, via the Data Protection Addendum |
| Zoom | Yes | Eligible paid plans (healthcare packaging); free tier no |
| Paubox | Yes — core product | All plans; encrypted delivery to normal inboxes |
| Hushmail for Healthcare | Yes — core product | Healthcare plans, BAA included |
| Proton Mail | Yes (reported) | Paid business plans; confirm directly with Proton |
| Dropbox / Google Drive | Yes | Paid team/business plans only; consumer plans no |
| Standard SMS (any carrier) | No | Carriers don't sign BAAs — see the texting section |
Google Workspace deserves the longest look, because it's where most solo practices already live and where the quietest compliance failure happens. Google offers its BAA on paid Workspace plans — but the agreement is not automatic. A super admin has to go into the Admin console (Account settings, then Legal and compliance), find the HIPAA Business Associate Amendment, and formally review and accept it. Plenty of therapists pay for Workspace for years believing the subscription itself made them compliant. It didn't. Until someone clicks accept, there is no BAA, and you're sailing without the paperwork you think you have. Google also publishes a list of covered services — Gmail, Drive, Meet, Calendar, and most core apps are on it; third-party add-ons bolted onto them are not.
Microsoft 365 takes the opposite approach: BAA terms are baked into Microsoft's standard Data Protection Addendum for business and enterprise subscriptions, so coverage attaches without a separate signature ceremony. The catch shifts downstream — the agreement doesn't configure your tenant for you, and the defaults are not a clinical practice's defaults.
Zoom signs BAAs for healthcare customers on eligible paid plans — the healthcare packaging has gone by a few names over the years (Zoom for Healthcare, and more recently HIPAA-enabled Business and Enterprise configurations), so confirm the current SKU when you buy. Two things stay constant: the free tier is never covered, and the BAA plus the HIPAA account settings must actually be in place, not merely available.
The therapist-marketed options — Paubox, Hushmail for Healthcare, Proton Mail — exist because the mainstream products make you assemble compliance yourself. Paubox's model is encryption by default: your outbound mail is encrypted in transit and lands in the client's ordinary inbox with no portal or extra password, and a BAA comes with every account. Hushmail's healthcare plans bundle a BAA with encrypted mail and web forms and are priced for solo practices. Proton Mail is end-to-end encrypted and is reported to offer BAAs on paid business plans — verify that directly with Proton before you commit, and check that your retention settings satisfy your state's record-keeping rules.
Here's the nuance that unknots most of the anxiety: your clients are not covered entities. HIPAA doesn't regulate them. A client can email you their entire history from a Hotmail account they opened in 2004, and nobody has violated anything. Your obligations attach to what you send, and to where messages containing PHI end up stored — which includes your inbox once their email is sitting in it.
And HIPAA is more permissive about your replies than the folklore suggests. HHS has said plainly that providers may communicate with patients by email, and the Omnibus Rule commentary goes further: if you've warned a client about the risks of unencrypted email and they still prefer it, you may honor that preference — clients have a right to receive communications by the channel they ask for, within reason. The compliance pattern, then, is not "never email." It's three documented moves:
That last habit — email for logistics, portal for everything clinical — is the one to tattoo somewhere visible. It's not just safer; it's simpler. You stop adjudicating every message ("is this one okay?") because the rule decides for you. It's the difference between checking the chart every time and knowing the channel is deep enough to begin with.
Standard SMS is worse than email on every axis: unencrypted in transit, stored by carriers who will not sign a BAA with your practice, and mirrored onto whatever devices and smartwatch your client's messages sync to. There is no paid tier that fixes this. If your compliance posture requires a BAA behind every channel, ordinary texting can't clear the bar.
And yet nearly every therapist texts, because clients confirm appointments by text and ignore almost everything else. So here's the honest framing rather than the pretend one: the same HHS posture that permits unencrypted email at a client's informed request is generally read to extend to texting — warn about the risks, document the client's preference for text, and keep content minimal. A large share of real-world practices operate exactly this way, as a documented, risk-tolerant choice: appointment reminders and scheduling only, nothing clinical, nothing you'd wince at on a lock screen. What the guidance does not tolerate is texting as a therapy channel — session content, crisis check-ins, diagnoses, medication details over SMS. If a text thread starts drifting clinical, the professional move is one sentence: "Let's take this to the portal or our next session."
Email is just the visible mast. The BAA rule applies to the whole rigging — every service that creates, receives, maintains, or transmits client information for you. Walk this list and ask two questions for each: does client data touch it, and do I have a signed BAA on file?
Most solo practices that run this audit find seven to ten vendors and two or three missing agreements. That's not a scandal — it's Tuesday. The point of the audit isn't shame; it's that every missing BAA is fixable in an afternoon once you can see it.
Notice what actually made that list long: PHI scattered across many harbors. Notes here, messages there, billing in a third place, each with its own agreement, tier requirements, and console checkbox to remember. The most effective compliance move available to a solo practice isn't a better email vendor — it's fewer places where client information lives at all. When clinical conversation happens in a client portal inside your EHR, the message never leaves a system that's already covered; your email goes back to being what it's good at, which is logistics. That's the design behind Practice Harbor: portal messaging, notes, scheduling, and billing under one BAA — including the AI note-drafting — so the audit list above collapses to a handful of entries, and the 9pm reply about medication anxiety has a home that was built for it.
Portal messaging, notes, scheduling, and billing in a single covered system — with a BAA that includes the AI processing. The fewer places PHI lives, the shorter your audit list gets. Free for pre-licensed clinicians, $19/mo licensed.
Yes. HIPAA permits providers to communicate with clients by email, and HHS guidance says clients who have been warned about the risks of unencrypted email may still choose it — you can honor that documented preference. The standard pattern is written consent language in the intake packet describing email risks, a documented channel preference in the chart, and a discipline of keeping your own emails to logistics (scheduling, fees, directions) while clinical content goes through a covered channel like a client portal. Your email host also needs a signed Business Associate Agreement, since it stores and transmits messages containing PHI.
Free consumer Gmail never includes a BAA and cannot be used for client PHI at any price. Paid Google Workspace plans do offer a HIPAA Business Associate Amendment covering Gmail, Drive, Meet, Calendar, and other core services — but the BAA is not automatic. A super admin must go into the Google Admin console (Account settings, then Legal and compliance) and formally accept the HIPAA Business Associate Amendment. Paying for Workspace without completing that acceptance step means you have no BAA in effect.
Not automatically, but it requires care. Standard SMS is unencrypted and cell carriers do not sign BAAs, so texting can never carry clinical content safely. HHS guidance permits unencrypted communication when a client has been warned of the risks and still prefers that channel, so many practices text with documented client consent, restricted to minimal logistics: appointment confirmations and scheduling only. Session content, diagnoses, medication details, or crisis communication over SMS falls outside what that posture tolerates and should move to a covered channel.
Any vendor that creates, receives, maintains, or transmits PHI on your behalf: your EHR, email host, video/telehealth platform, cloud storage holding client files, transcription or AI note tools, e-fax service, scheduling software, and human business associates like billing services and accountants who see client information. Payment processors are the exception — HIPAA carves out pure payment-processing activities, though services beyond moving money can create a business associate relationship, so keep clinical detail out of payment descriptions. Consolidating messaging, notes, and billing into one platform under one BAA shortens the list considerably.