EnglishEspañol

HIPAA Compliant Email Services: Encrypted Email for Healthcare (2026)

By Recording Law Editorial TeamReviewed September 23, 202614 min read
HIPAA Compliant Email Services: Encrypted Email for Healthcare (2026)

Updates

Updated HIPAA penalty amounts to the current inflation-adjusted figures, clarified which technical safeguards are required versus addressable, corrected breach-notification citations, and corrected the proposed Security Rule's Federal Register publication date.

Governing law re-checked for recent changes

Governing law re-checked for recent changes

Sources and References

  1. 45 CFR 164.312 - Technical Safeguards (HIPAA Security Rule)(ecfr.gov).gov
  2. HHS FAQ: Does the Security Rule Allow Sending ePHI in Email?(hhs.gov).gov
  3. HHS Summary of the HIPAA Security Rule(hhs.gov).gov
  4. HHS HIPAA Security Rule NPRM Fact Sheet (December 2024)(hhs.gov).gov
  5. HHS Breach Notification Rule(hhs.gov).gov
  6. 45 CFR 164.404 - Notification to Individuals (Breach Notification)(ecfr.gov).gov
  7. HHS Encryption FAQ(hhs.gov).gov
  8. NIST SP 800-66 Rev. 2: Implementing the HIPAA Security Rule(csrc.nist.gov).gov
  9. HHS OCR HIPAA Enforcement: Phishing Attack Settlement ($600,000)(hhs.gov).gov
  10. Google Workspace HIPAA Implementation Guide(services.google.com)
  11. Proton Business Associate Agreement(proton.me)
  12. 45 CFR 102.3 - Civil Monetary Penalty Inflation Adjustments(ecfr.gov)
  13. 45 CFR 164.406 - Notification to the Media(ecfr.gov)
  14. 45 CFR 164.408 - Notification to the Secretary(ecfr.gov)
  15. HIPAA Security Rule NPRM, 90 FR 898 (Jan. 6, 2025)(federalregister.gov)
Share: