Ditch Microsoft & Google Today!
Four checks before you sign.
This HIPAA email vendor checklist covers what actually matters: if your practice or organization sends or receives Protected Health Information (PHI) by email, your email vendor needs to be part of your HHS HIPAA Security Rule compliance picture — not an afterthought. This checklist is vendor-neutral. Use it to evaluate your current provider or any provider you’re considering.
An important caveat: a signed Business Associate Agreement (BAA) alone does not make your practice HIPAA compliant. The BAA is necessary, but your own policies, staff training, and access controls matter just as much. This checklist is a starting point for a vendor conversation, not legal advice — talk to your compliance officer or legal counsel about your specific obligations.
Fill out the short form below and the full evaluation checklist will be shown here immediately.
Liberation Email — our private, U.S.-based email hosting — is built with exactly this kind of evaluation in mind. Mail Pro is $7.95/user/month, includes 25GB of mailbox storage, runs on our own U.S.-based mail servers (not a resold third party), and comes with a signed BAA as part of onboarding, not an upsell.
See Mail Pro and get a signed BAA →
Not sure where your current setup stands? Talk to us about your practice’s setup and we’ll walk through it with you.
Does every email vendor handling PHI need to sign a BAA?
Yes — under the HHS Security Rule, any vendor that creates, receives, maintains, or transmits PHI on your behalf is a business associate and must sign a BAA before you send them any PHI.
Is a signed BAA enough to make us HIPAA compliant?
No. A BAA covers the vendor relationship, but your practice still needs its own policies, staff training, access controls, and risk assessments — the BAA is one piece, not the whole picture.
What happens if we send PHI through a vendor that won’t sign a BAA?
That’s a HIPAA violation exposing your practice to real liability, regardless of whether the vendor’s email is otherwise secure — the missing BAA itself is the compliance failure.
Work through the HIPAA email vendor checklist before you sign with a new provider or renew an existing one. Ask each vendor to answer in writing, and keep the answers with your compliance records so you can show how the decision was made.
The federal Security Rule is published in 45 CFR Part 164, and it is a useful reference when you write your questions. Practical questions include:
A vendor answer is a snapshot. Revisit the HIPAA email vendor checklist when your provider changes its terms, when you add staff, or when your practice changes how it handles patient messages. Our Liberation Email page explains what we offer, and our team is available through the contact page if you want to discuss your requirements.
This page is general information, not legal advice. No email vendor can make your practice compliant on its own, and no checklist guarantees compliance, so confirm your obligations with qualified counsel or a compliance professional.