Ditch Microsoft & Google Today!

How to vet an email vendor

Four checks before you sign.

Shortlist vendors
Check encryption
Review agreements
Decide

Does Your Email Vendor Actually Meet HIPAA? A Vendor Evaluation Checklist

This HIPAA email vendor checklist covers what actually matters: if your practice or organization sends or receives Protected Health Information (PHI) by email, your email vendor needs to be part of your HHS HIPAA Security Rule compliance picture — not an afterthought. This checklist is vendor-neutral. Use it to evaluate your current provider or any provider you’re considering.

An important caveat: a signed Business Associate Agreement (BAA) alone does not make your practice HIPAA compliant. The BAA is necessary, but your own policies, staff training, and access controls matter just as much. This checklist is a starting point for a vendor conversation, not legal advice — talk to your compliance officer or legal counsel about your specific obligations.

What’s in this HIPAA email vendor checklist

  • Whether your vendor will actually sign a Business Associate Agreement (BAA), and what it covers
  • Encryption, access control, and audit-log requirements under the HHS Security Rule
  • Questions to ask before switching or renewing an email vendor handling PHI

Get the full checklist

Fill out the short form below and the full evaluation checklist will be shown here immediately.

Name(Required)

Where Liberation Technology Services fits

Liberation Email — our private, U.S.-based email hosting — is built with exactly this kind of evaluation in mind. Mail Pro is $7.95/user/month, includes 25GB of mailbox storage, runs on our own U.S.-based mail servers (not a resold third party), and comes with a signed BAA as part of onboarding, not an upsell.

See Mail Pro and get a signed BAA →

Not sure where your current setup stands? Talk to us about your practice’s setup and we’ll walk through it with you.

HIPAA email vendor checklist: frequently asked questions

Does every email vendor handling PHI need to sign a BAA?
Yes — under the HHS Security Rule, any vendor that creates, receives, maintains, or transmits PHI on your behalf is a business associate and must sign a BAA before you send them any PHI.

Is a signed BAA enough to make us HIPAA compliant?
No. A BAA covers the vendor relationship, but your practice still needs its own policies, staff training, access controls, and risk assessments — the BAA is one piece, not the whole picture.

What happens if we send PHI through a vendor that won’t sign a BAA?
That’s a HIPAA violation exposing your practice to real liability, regardless of whether the vendor’s email is otherwise secure — the missing BAA itself is the compliance failure.

How to use this HIPAA email vendor checklist in 2026

Work through the HIPAA email vendor checklist before you sign with a new provider or renew an existing one. Ask each vendor to answer in writing, and keep the answers with your compliance records so you can show how the decision was made.

HIPAA email vendor checklist vendor review steps diagram

Questions to ask every email vendor

The federal Security Rule is published in 45 CFR Part 164, and it is a useful reference when you write your questions. Practical questions include:

  • Will you sign a business associate agreement before any PHI is sent?
  • How is mail encrypted in transit and at rest?
  • What access and audit logs are available, and how long are they kept?
  • How are accounts removed when a staff member leaves?

Keeping the HIPAA email vendor checklist current

A vendor answer is a snapshot. Revisit the HIPAA email vendor checklist when your provider changes its terms, when you add staff, or when your practice changes how it handles patient messages. Our Liberation Email page explains what we offer, and our team is available through the contact page if you want to discuss your requirements.

HIPAA email vendor checklist review schedule diagram

This page is general information, not legal advice. No email vendor can make your practice compliant on its own, and no checklist guarantees compliance, so confirm your obligations with qualified counsel or a compliance professional.

Ready to get started with a HIPAA-compliant email vendor?

Which plan are you interested in?(Required)
Name(Required)
Phone