Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

U.S. hospitals can use email to communicate electronic protected health information (ePHI), but no single product or encryption setting makes email HIPAA-compliant by itself. The hospital should first document an organization-specific risk analysis, then apply layered safeguards for recipients, access, transmission, integrity, staff behavior, vendors, and incident response.

Can hospitals send patient information by email?

Yes. HHS Office for Civil Rights (OCR) says the HIPAA Security Rule does not expressly prohibit email. Its email FAQ, last reviewed July 26, 2013, states: “The Security Rule allows for e-PHI to be sent over an electronic open network as long as it is adequately protected.” The FAQ does not prescribe one universal configuration; the hospital must select and document protections appropriate to its systems and risks. Read HHS OCR’s email and Security Rule FAQ.

Patient-facing email is also permitted with reasonable safeguards. HHS OCR’s patient-email FAQ, also last reviewed July 26, 2013, says providers may communicate electronically with patients if they apply reasonable safeguards. Examples include checking the email address and limiting the amount or type of information sent in unencrypted email when needed to reasonably protect privacy. Read HHS OCR’s patient-email FAQ.

These are U.S. federal HHS/OCR guidance statements, not a determination that a particular hospital’s email system complies. Actual duties depend on the hospital’s architecture, workflows, contracts, risk analysis, applicable state law, and other requirements. Do not treat patient consent alone as a substitute for the hospital’s Security Rule safeguards.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Start with a documented risk analysis

Before choosing controls or approving an email workflow, identify where ePHI is created, received, stored, sent, and accessed. Include staff devices and accounts, mail servers, integrations, backups, external recipients, and service providers. Consider threats to confidentiality, integrity, and availability, including inadvertent data entry, network attacks, malware, unauthorized access, and location-specific natural or environmental events.

HHS OCR describes risk analysis as foundational to the Security Rule and calls for an accurate and thorough assessment. The methods and measures should fit the organization and its environment; a checklist copied from another hospital is not a substitute for evaluating local systems and workflows. Record the risks, chosen protections, ownership, and rationale, then address identified risks through ongoing risk management. See HHS OCR’s Guidance on Risk Analysis and its explanation of risk analysis and risk management.

Rank #2
Thetis BIOFP Plus FIDO2 Fingerprint Security Key Hardware Passkey with USB Type C/Biometric/FIDO Certified, 2FA / MFA Authenticator App Device, Works for Window, macOS, Linux, Gmail, Github
  • FIDO2 Certified Passkey Authentication: Officially FIDO2 certified for secure, passwordless login on supported platforms. Use modern passkeys with hardware-backed protection. Please verify your intended service supports FIDO2 hardware keys before purchase.
  • Precision Fingerprint Sensor: Built-in high-accuracy biometric fingerprint sensor ensures fast, convenient authentication while preventing unauthorized access. No PIN reuse, no shared secrets—only your fingerprint unlocks the key.
  • Strong Hardware 2FA/MFA Security: Enhances account protection with physical-presence and biometric verification, helping defend against phishing, credential theft, and account takeovers.
  • USB-C Wired Compatibility (No NFC): Designed for stable USB-C authentication on desktops and laptops, including Windows, macOS, and Linux systems. Ideal for users and enterprises that prefer wired-only security keys.
  • Durable Aluminum Shield, Portable Design: Features the same precision aluminum protective shield for long-term durability. Compact, lightweight, battery-free, and network-free-built for everyday carry and professional environments.

Build safeguards around the message lifecycle

Verify recipients and limit disclosure

  • Check the complete address before sending, especially when autocomplete presents similar names or domains. Use an address-confirmation step for patient communications where appropriate.
  • Confirm that each recipient needs the information for the communication’s purpose. Avoid unnecessary details, attachments, or broad distribution lists.
  • For unencrypted patient email, limit the amount or type of information where needed to reasonably protect privacy. Use an approved secure-message workflow or another suitable channel when the content or risk calls for stronger protection.
  • Record and honor reasonable patient requests for confidential communications by alternative means or at alternative locations, following institutional procedures.

Control access and protect integrity

Restrict mailboxes and administrative privileges to authorized users, and remove access when roles change or staff leave. Protect credentials and devices, and use controls appropriate to prevent unauthorized access to messages in transit and at rest. Consider how the system prevents or detects improper changes, supports reliable delivery, and preserves the integrity of attachments and message content.

Assess transmission protections and encryption

Evaluate the actual routes email takes, including open networks, external recipients, mobile access, and any secure-message links. Select transmission protections based on the documented risk and the capabilities of the systems and recipients. Encryption can be an important safeguard, but it is not a blanket compliance claim: assess how it is applied, who can access keys or content, and whether protection remains effective through the full workflow.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Kingston IronKey Vault Privacy 50 128GB Encrypted USB
  • FIPS 197 with XTS-AES 256-bit Encryption: Provides business-grade security with hardware-based encryption to protect your sensitive data
  • Brute Force and BadUSB Attack Protection: Safeguards against unauthorized access attempts and malicious USB attacks with digitally-signed firmware
  • Multi-Password Option with Complex/Passphrase modes: Offers flexible password configuration options to meet various security requirements and user preferences
  • New Passphrase Mode: Enhanced security feature allowing users to create longer, more memorable password phrases for easier access without compromising protection
  • Dual Read-Only (Write-Protect) Settings: Enables write protection functionality to prevent accidental data modification or deletion when needed

HHS breach guidance gives encryption a specific role in determining whether ePHI has been rendered unusable, unreadable, or indecipherable to unauthorized individuals under that guidance. It also addresses the status of keys and processes. That analysis does not mean that any service marketed as “encrypted email” satisfies every HIPAA obligation or resolves every incident. See HHS guidance on rendering unsecured PHI unusable.

Log activity and maintain recovery capability

Use audit controls to record and review relevant information-system activity, with attention to access, unusual sending patterns, and administrative changes. Include email and connected systems in incident response, backup, and recovery planning. HHS safeguard materials identify training, access controls, incident response, audit controls, backup and recovery, and encryption where reasonable and appropriate as parts of a broader protection program—not as alternatives to risk analysis. See HHS information on HIPAA safeguards.

Rank #4
Adesso AKB-140FB Wired Low Profile Desktop Keyboard
  • Fingerprint reader with Windows Hello: Built-in biometric sensor enables you to log in, access sensitive data, or authorize transactions in just 0.05 seconds with 360-degree all-round detection, supporting up to 10 registered fingerprint IDs for multiple users
  • AES-256 encrypted biometric security: Protects stored fingerprint data using matching on chip technology with AES-256, SHA-256, ECC-256, and TRNG protocols, achieving a false acceptance rate of less than 1 in 100,000 and a false rejection rate under 1.8 percent
  • Low-profile membrane keys for all-day comfort: Slim, streamlined key design provides a quiet and smooth typing experience that requires minimal pressing force, reducing finger fatigue during extended typing sessions at home or in the office
  • 12 dedicated shortcut hotkeys: Includes 5 internet hotkeys for Homepage, Email, Back, Forward, and Search plus 7 multimedia hotkeys for Play/Pause, Stop, Previous Track, Next Track, Volume Down, Volume Up, and Mute for quick access
  • USB-C connection with USB-A adapter included: Full-size 104-key US layout keyboard connects via USB-C and comes with a USB-C to USB-A adapter for broad compatibility with Windows 11 and Windows 10 systems, measuring 18.3 x 6.5 x 1.3 inches and weighing just 1.5 pounds

Make safe handling part of the clinical workflow

Policies work only if staff can follow them during care. Train clinicians and administrative staff on the approved ways to communicate patient information, what to verify before sending, and how to report mistakes or suspicious activity. Practical measures can include confirming recipients before sending, pausing on unexpected autocomplete suggestions, checking attachment contents, and using approved secure-message tools for workflows that require them.

Define who may use shared mailboxes, how delegated access is approved, and how access is reviewed. Make the incident-reporting route easy to find and usable without blame-driven delay. These are operational ways to implement the hospital’s selected safeguards; the right procedures depend on the risk analysis and local system design.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Cryptnox FIDO2 Security Key NFC Smart Card for 2FA MFA Passwordless Login
  • FIDO2 CERTIFIED: FIDO Alliance Certified FIDO2 v2.1 and CTAP Level 1 for 2FA and MFA on Google Microsoft Apple GitHub login.gov AGOV SwissID and any WebAuthn service
  • PASSKEY READY: Works as a hardware passkey for passwordless sign-in where the service enables it and as a U2F and WebAuthn security key everywhere else
  • CERTIFIED SECURITY: NXP JCOP 4.5 secure element rated Common Criteria EAL6+ (augmented)
  • TAP OR INSERT: Dual NFC ISO 14443 and contact ISO 7816 interface in an ID-1 format smart card that is passive and battery-free
  • BUILT TO LAST: Passive smart card made in Switzerland designed by Swiss company Cryptnox and backed by a 2 year manufacturer warranty
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Choose the communication channel for the use case

There is no HHS-designated best email product or universal best channel. Compare ordinary email with safeguards, secure messaging, and other approved channels against the actual workflow. Patient preference matters: providers should consider reasonable requests for confidential communications, while still protecting ePHI under the hospital’s obligations.

Evaluation question What the hospital should compare
Recipient and identity How recipients are authenticated, how addresses are verified, and how likely address errors are in the workflow.
Protection How confidentiality and integrity are protected in transit and at rest, including access to content and keys.
Usability Whether clinicians and patients can reliably use the channel without creating unsafe workarounds or delays.
Audit and response What activity can be logged and reviewed, and how suspected misdirection or compromise can be investigated.
System fit How the channel integrates with hospital systems and supports the intended care communication.
Vendor and operations Vendor access, BAA scope, retention, data return, availability, backup, disclosure limits, cost, and operational burden.

Use those criteria as a local decision framework, not as an official HHS ranking. For patient-access requests involving unencrypted delivery, follow current HHS access guidance and institutional counsel; those requests are a distinct scenario and should not be used to justify ordinary staff email practices.

Govern cloud email and messaging providers

If a cloud provider creates, receives, maintains, or transmits ePHI for the hospital, determine what the actual service does and assess the risks associated with its use. An appropriate business associate agreement (BAA) is required when the provider is acting as a business associate. Review the service and contract rather than assuming a provider’s general security claims establish that the hospital has met its own duties.

Check that service-level terms align with the BAA and HIPAA responsibilities. Relevant topics include security roles, availability, backups, incident handling, retention, data return, and limits on use or disclosure. The hospital remains responsible for understanding how the service affects its risk analysis. Read HHS OCR’s cloud-service FAQ, last reviewed January 9, 2023.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Prepare for misdirected or compromised email

When a message may have gone to the wrong recipient or an account may be compromised, staff should report it promptly through institutional procedures. The privacy and security teams should investigate what information was involved, who could access it, what protections applied, and whether the event triggers breach-notification duties. Do not infer breach status from encryption alone; apply the relevant facts and HHS guidance to the incident.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.