Compliance

July 19, 2026

12 min read

By Albert Wong, PhD · Clinical Psychologist

HIPAA-Compliant Email for Therapists: Which Vendors Need a BAA (Probably More Than You Think)

The short answer

You can email clients — HIPAA allows it, with a documented warning about the risks and the client's documented preference. But every vendor that stores or transmits client information on your behalf must sign a Business Associate Agreement first, and no free consumer tier of anything (Gmail, Zoom, Dropbox) ever qualifies. Paid Google Workspace, Microsoft 365 business plans, and eligible paid Zoom plans all offer BAAs; with Google you must also formally accept the BAA in the Admin console, or you don't have one. The habit that makes all of it simpler: email for logistics, portal for everything clinical.

It's 9pm on a Tuesday. A client emails asking to move Thursday's session. You type back: "Sounds good, see you Thursday at 4 — and yes, we can absolutely talk about the medication anxiety then." Send. Kettle on, day done.

Somewhere in that sentence, you crossed a line you couldn't see. The scheduling half was defensible. The back half — a named clinical concern, tied to an identifiable person, sent from a free Gmail account that has never signed anything with anyone — is protected health information sitting on a server with no Business Associate Agreement behind it. Nothing bad will probably happen. That's the trouble with this whole topic: the water looks calm right up until it isn't, and the rocks were under the surface the entire time.

This guide is the map. What the BAA rule actually says, which vendors will sign one (and at what tier), the client-initiated-email nuance that confuses everyone, the honest version of the texting question, and a checklist of every vendor in a typical solo practice that needs an agreement you may not have.

The rule, in one breath

HIPAA's business associate rule (45 CFR 164.502(e) and 164.308(b)) says: any vendor that creates, receives, maintains, or transmits protected health information on your behalf is your business associate, and you may not share PHI with them until they've signed a Business Associate Agreement — a contract making them legally responsible for safeguarding it. Your email host maintains and transmits every message you send. If a client's name plus anything about their care passes through that inbox, the host is handling PHI on your behalf.

Three corollaries do most of the work:

  • No BAA, no PHI. Full stop. There's no "but I was careful" exception and no volume threshold. One email with clinical content through a non-BAA service is the same category of problem as a thousand.
  • Encryption doesn't substitute for the agreement. A service can be beautifully encrypted and still be off-limits, because the BAA is a legal relationship, not a technical feature. You generally need both.
  • Free consumer tiers never qualify. This is the pattern across every vendor in this article. Free Gmail, free Zoom, free Dropbox — the companies offer BAAs only on paid business products, without exception that I'm aware of. If you're not paying, there is no agreement to sign.

Think of your practice as a small boat. Every vendor that touches client data is a through-hull fitting — a deliberate hole below the waterline. Perfectly seaworthy, as long as each one is properly sealed. The BAA is the seal. An unsealed one doesn't leak on sunny days. It leaks in the storm — the breach, the audit, the board complaint — which is exactly when you can't fix it.

The vendor walk: who signs, and at what tier

Tiers and product names shift, so treat the table as a July 2026 snapshot and confirm on each vendor's own HIPAA page before you rely on it. The shape of the landscape, though, has been stable for years:

VendorBAA available?Typical tier required
Gmail (free consumer)No — everNot available at any price
Google WorkspaceYesAny paid plan; admin must accept the BAA in the console
Microsoft 365YesBusiness/Enterprise plans, via the Data Protection Addendum
ZoomYesEligible paid plans (healthcare packaging); free tier no
PauboxYes — core productAll plans; encrypted delivery to normal inboxes
Hushmail for HealthcareYes — core productHealthcare plans, BAA included
Proton MailYes (reported)Paid business plans; confirm directly with Proton
Dropbox / Google DriveYesPaid team/business plans only; consumer plans no
Standard SMS (any carrier)NoCarriers don't sign BAAs — see the texting section

Google Workspace deserves the longest look, because it's where most solo practices already live and where the quietest compliance failure happens. Google offers its BAA on paid Workspace plans — but the agreement is not automatic. A super admin has to go into the Admin console (Account settings, then Legal and compliance), find the HIPAA Business Associate Amendment, and formally review and accept it. Plenty of therapists pay for Workspace for years believing the subscription itself made them compliant. It didn't. Until someone clicks accept, there is no BAA, and you're sailing without the paperwork you think you have. Google also publishes a list of covered services — Gmail, Drive, Meet, Calendar, and most core apps are on it; third-party add-ons bolted onto them are not.

Microsoft 365 takes the opposite approach: BAA terms are baked into Microsoft's standard Data Protection Addendum for business and enterprise subscriptions, so coverage attaches without a separate signature ceremony. The catch shifts downstream — the agreement doesn't configure your tenant for you, and the defaults are not a clinical practice's defaults.

Zoom signs BAAs for healthcare customers on eligible paid plans — the healthcare packaging has gone by a few names over the years (Zoom for Healthcare, and more recently HIPAA-enabled Business and Enterprise configurations), so confirm the current SKU when you buy. Two things stay constant: the free tier is never covered, and the BAA plus the HIPAA account settings must actually be in place, not merely available.

The therapist-marketed options — Paubox, Hushmail for Healthcare, Proton Mail — exist because the mainstream products make you assemble compliance yourself. Paubox's model is encryption by default: your outbound mail is encrypted in transit and lands in the client's ordinary inbox with no portal or extra password, and a BAA comes with every account. Hushmail's healthcare plans bundle a BAA with encrypted mail and web forms and are priced for solo practices. Proton Mail is end-to-end encrypted and is reported to offer BAAs on paid business plans — verify that directly with Proton before you commit, and check that your retention settings satisfy your state's record-keeping rules.

When the client emails you first

Here's the nuance that unknots most of the anxiety: your clients are not covered entities. HIPAA doesn't regulate them. A client can email you their entire history from a Hotmail account they opened in 2004, and nobody has violated anything. Your obligations attach to what you send, and to where messages containing PHI end up stored — which includes your inbox once their email is sitting in it.

And HIPAA is more permissive about your replies than the folklore suggests. HHS has said plainly that providers may communicate with patients by email, and the Omnibus Rule commentary goes further: if you've warned a client about the risks of unencrypted email and they still prefer it, you may honor that preference — clients have a right to receive communications by the channel they ask for, within reason. The compliance pattern, then, is not "never email." It's three documented moves:

  • Warn in writing. Your intake paperwork includes plain-language email and texting consent: ordinary email isn't fully secure, here are the risks, here's what we'll use it for. This lives in the intake packet, alongside your Notice of Privacy Practices.
  • Record the preference. The client chooses email, portal, phone, or text — and their choice is documented in the chart, not remembered.
  • Keep your side minimal. Whatever they send you, your replies stay in the logistics lane: dates, times, directions, fees. "See you Thursday at 4" is logistics. "Let's discuss the medication anxiety" is clinical content, and it belongs somewhere covered.

That last habit — email for logistics, portal for everything clinical — is the one to tattoo somewhere visible. It's not just safer; it's simpler. You stop adjudicating every message ("is this one okay?") because the rule decides for you. It's the difference between checking the chart every time and knowing the channel is deep enough to begin with.

Texting: the honest version

Standard SMS is worse than email on every axis: unencrypted in transit, stored by carriers who will not sign a BAA with your practice, and mirrored onto whatever devices and smartwatch your client's messages sync to. There is no paid tier that fixes this. If your compliance posture requires a BAA behind every channel, ordinary texting can't clear the bar.

And yet nearly every therapist texts, because clients confirm appointments by text and ignore almost everything else. So here's the honest framing rather than the pretend one: the same HHS posture that permits unencrypted email at a client's informed request is generally read to extend to texting — warn about the risks, document the client's preference for text, and keep content minimal. A large share of real-world practices operate exactly this way, as a documented, risk-tolerant choice: appointment reminders and scheduling only, nothing clinical, nothing you'd wince at on a lock screen. What the guidance does not tolerate is texting as a therapy channel — session content, crisis check-ins, diagnoses, medication details over SMS. If a text thread starts drifting clinical, the professional move is one sentence: "Let's take this to the portal or our next session."

Audit yourself: every vendor that touches PHI

Email is just the visible mast. The BAA rule applies to the whole rigging — every service that creates, receives, maintains, or transmits client information for you. Walk this list and ask two questions for each: does client data touch it, and do I have a signed BAA on file?

  • Your EHR. Obvious, and almost certainly already signed — but confirm you can actually produce the document.
  • Email host. Everything above.
  • Video platform. Zoom, Meet, Doxy.me, or whatever runs your telehealth — same paid-tier-plus-BAA logic as email.
  • Cloud storage. The Drive or Dropbox folder holding scanned intake forms is maintaining PHI. Both vendors offer BAAs on paid business plans; consumer accounts don't qualify.
  • Transcription and AI tools. Anything that hears a session or drafts a note is swimming in PHI. The vendor needs a BAA covering the AI processing itself, not just storage — the full test is in our guide to HIPAA-compliant AI notes.
  • Fax services. E-fax providers transmit records for you. BAA required; most healthcare-oriented ones sign readily.
  • Scheduling tools. A booking calendar holding client names and appointment reasons is holding PHI. Free consumer schedulers usually can't sign.
  • Payment processors. The genuine nuance: HIPAA carves out financial institutions' payment-processing activities — authorizing, clearing, settling, and collecting payments isn't business-associate work, which is why card processing per se doesn't require a BAA. But the carve-out is narrow. Services beyond moving money (storing treatment descriptions, invoicing with clinical detail) can pull a processor back into business-associate territory. Keep clinical information out of payment descriptions and receipts, and the carve-out works as intended.
  • Your accountant and your biller. The ones everyone forgets. A billing service sees diagnoses and dates of service; a bookkeeper reconciling client payments may too. Humans and firms can be business associates just as easily as software.

Most solo practices that run this audit find seven to ten vendors and two or three missing agreements. That's not a scandal — it's Tuesday. The point of the audit isn't shame; it's that every missing BAA is fixable in an afternoon once you can see it.

The shortest list wins

Notice what actually made that list long: PHI scattered across many harbors. Notes here, messages there, billing in a third place, each with its own agreement, tier requirements, and console checkbox to remember. The most effective compliance move available to a solo practice isn't a better email vendor — it's fewer places where client information lives at all. When clinical conversation happens in a client portal inside your EHR, the message never leaves a system that's already covered; your email goes back to being what it's good at, which is logistics. That's the design behind Practice Harbor: portal messaging, notes, scheduling, and billing under one BAA — including the AI note-drafting — so the audit list above collapses to a handful of entries, and the 9pm reply about medication anxiety has a home that was built for it.

One Platform, One BAA

Portal messaging, notes, scheduling, and billing in a single covered system — with a BAA that includes the AI processing. The fewer places PHI lives, the shorter your audit list gets. Free for pre-licensed clinicians, $19/mo licensed.

Frequently Asked Questions

Can therapists email their clients?

Yes. HIPAA permits providers to communicate with clients by email, and HHS guidance says clients who have been warned about the risks of unencrypted email may still choose it — you can honor that documented preference. The standard pattern is written consent language in the intake packet describing email risks, a documented channel preference in the chart, and a discipline of keeping your own emails to logistics (scheduling, fees, directions) while clinical content goes through a covered channel like a client portal. Your email host also needs a signed Business Associate Agreement, since it stores and transmits messages containing PHI.

Does Gmail sign a BAA?

Free consumer Gmail never includes a BAA and cannot be used for client PHI at any price. Paid Google Workspace plans do offer a HIPAA Business Associate Amendment covering Gmail, Drive, Meet, Calendar, and other core services — but the BAA is not automatic. A super admin must go into the Google Admin console (Account settings, then Legal and compliance) and formally accept the HIPAA Business Associate Amendment. Paying for Workspace without completing that acceptance step means you have no BAA in effect.

Is texting clients a HIPAA violation?

Not automatically, but it requires care. Standard SMS is unencrypted and cell carriers do not sign BAAs, so texting can never carry clinical content safely. HHS guidance permits unencrypted communication when a client has been warned of the risks and still prefers that channel, so many practices text with documented client consent, restricted to minimal logistics: appointment confirmations and scheduling only. Session content, diagnoses, medication details, or crisis communication over SMS falls outside what that posture tolerates and should move to a covered channel.

What vendors does a therapy practice need a BAA with?

Any vendor that creates, receives, maintains, or transmits PHI on your behalf: your EHR, email host, video/telehealth platform, cloud storage holding client files, transcription or AI note tools, e-fax service, scheduling software, and human business associates like billing services and accountants who see client information. Payment processors are the exception — HIPAA carves out pure payment-processing activities, though services beyond moving money can create a business associate relationship, so keep clinical detail out of payment descriptions. Consolidating messaging, notes, and billing into one platform under one BAA shortens the list considerably.