Content

How to Email Patients Without Violating HIPAA, and Where Most Practices Actually Slip

Blog
Content

The HIPAA violation almost never looks like a violation. It doesn't look like a hacker or a leaked database. It looks like a merge field.

A subject line that says "Following up on your dermatology visit." A list segment named "GLP-1 patients, active." A well meaning front desk staffer who exports a spreadsheet with appointment types in it and drops it into Mailchimp because that's the tool everyone already knows. None of that feels like a compliance event in the moment. All of it can be one.

Here's what actually matters if you're sending email or text to patients.

What counts as PHI in an email

The HHS Privacy Rule defines protected health information as information that relates to a person's health, condition, or care, and that identifies them or could reasonably be used to identify them. The full definition covers "demographic data" tied to "past, present or future physical or mental health or condition" or "the provision of health care to the individual."

In marketing terms, that means a name and email address alone is usually fine. A name and email address next to an appointment type, a diagnosis, a treatment name, or a procedure code is PHI, whether it sits in a spreadsheet, a list segment, or a merge tag inside a template. It doesn't matter that the email itself reads as friendly and routine. The classification depends on what data touched the system, not on how the message sounds.

What a BAA actually requires from a vendor

A business associate, under HHS guidance, is anyone who performs a function on behalf of a healthcare provider that involves "creating, receiving, maintaining, or transmitting PHI." An email or SMS platform that stores your patient list and sends campaigns on your behalf fits that definition the moment PHI is involved. HHS is direct about what's owed in that case: the provider needs "satisfactory assurances, in the form of a contract," before handing that data over.

That contract is the BAA. It's not a formality or an upsell. It's the vendor accepting legal responsibility for how it handles PHI, including breach notification if something goes wrong. If a platform won't sign one, it doesn't matter how good the rest of the product is. It doesn't belong in the stack.

The consent side, briefly

Getting the data handling right doesn't automatically mean you're clear to contact someone. HIPAA governs what you can do with PHI once you have permission to use it. A separate law, the TCPA, governs whether you're allowed to text or call someone at all, and it has its own consent requirements that don't overlap cleanly with HIPAA's. We've written more on the two law problem for patient texting if that's the piece you're missing. For email, the short version is that satisfying HIPAA is necessary but not sufficient. Consent is its own checklist.

Where this actually goes wrong

A few patterns show up repeatedly in practices that get this wrong, and none of them involve anyone acting carelessly on purpose.

  • Merge fields that pull in appointment type, procedure, or diagnosis data directly into the email body, on a platform with no BAA behind it.
  • Subject lines or preview text that reference a condition or treatment, which is more identifiable than the same detail buried in the body.
  • List segments named and built around diagnosis or procedure, which means the PHI exists in the platform's own metadata even if it never appears in the email itself.
  • A staff member exporting a patient list to a personal or shared Gmail account to send a one off campaign, because the sanctioned tool felt like too much friction for a small batch.

Every one of those is a normal, well intentioned shortcut. That's what makes them common.

What this looks like done right

PatientCampaign signs a BAA on every plan, and email and SMS both run on the same compliant infrastructure, so a campaign can reference visit history or treatment type without anyone needing to route around the platform to make it work. We put together a fuller comparison against Mailchimp and a shorter answer on Mailchimp specifically if you're auditing what you're on today. If you want to see how the segmentation and consent handling actually works, we can walk through it.