Most dental practices are not using HIPAA-compliant email and most dentists do not realize it. Standard Gmail, Yahoo, and basic Outlook accounts used without specific configuration are not HIPAA compliant and cannot be used to transmit patient information.
Here is exactly what your dental practice needs for email compliance in 2026, which platforms qualify, and what your IT provider must configure before any of them satisfy the requirement.
Using a standard consumer email account to send or receive patient appointment information, treatment details, or insurance data is a HIPAA violation.
The violation is the use of a non-compliant email service, not the exposure of data. OCR has cited dental practices for non-compliant email services discovered during complaint investigations that had nothing to do with a breach. The BAA requirement alone is sufficient grounds for a compliance finding.
A HIPAA-compliant email service for a dentist must satisfy three requirements simultaneously. All three must be met. No single requirement is sufficient on its own.
1
Business Associate Agreement signed with the email provider
The email provider must sign a BAA with the practice. A standard Microsoft 365 or Google Workspace account without a healthcare BAA does not satisfy this requirement, even if the platform supports BAAs for other customers.
2
Encryption in transit and at rest on all messages containing patient information
Messages containing patient information must be encrypted both while being transmitted and while stored. Default email encryption settings on most platforms do not satisfy this requirement without additional configuration.
3
Strong authentication controls including multi-factor authentication on all accounts
Access to email accounts must be secured with MFA. Every staff email account used for any patient communication must have MFA enabled before the account is used for any patient communication.
All three requirements must be met simultaneously. A BAA alone is not sufficient if email is not encrypted. Encryption alone is not sufficient without a BAA. MFA alone does not satisfy the BAA or encryption requirements. The email service is either fully compliant or it is not.
Three platforms qualify. Select each one to see how it meets the requirements and what your IT provider must do for it to be compliant.
Microsoft 365 Business
The most widely used HIPAA-compliant email platform in dental practices. Requires IT configuration to be compliant.
Google Workspace for Healthcare
Offers a BAA for healthcare customers with encryption included. Standard accounts without healthcare BAA activation are not compliant.
Dedicated Healthcare Email Services
Purpose-built for HIPAA compliance. BAAs, encryption, and compliant settings included by default. Minimal IT configuration required.
Check each item as your IT provider completes it. Every unchecked item means your email platform is not yet HIPAA compliant regardless of which platform you are using.
Business email accounts under a healthcare BAA-covered plan, not a consumer or standard business plan
A standard M365 Business Basic or standard Google Workspace account without healthcare BAA activation does not satisfy this requirement.
Encryption settings for both in-transit and at-rest message protection enabled and verified
Default encryption settings on most platforms do not meet the HIPAA requirement without explicit configuration by an IT provider. Verification must be documented.
Multi-factor authentication on every staff email account before the account is used for any patient communication
MFA must be enforced across all accounts, not just admin accounts. Every staff member who sends or receives patient information via email requires MFA.
Email retention policies configured to meet HIPAA's six-year documentation retention requirement
HIPAA requires documentation to be retained for six years. Default email retention policies on most platforms do not match this timeline without configuration.
Email security filtering for phishing and spam to reduce credential theft risk
Credential theft through phishing is the most common way unauthorized access to patient data occurs. Security filtering is a required safeguard, not an optional add-on.
All five configuration items complete.
Your email platform is configured to meet HIPAA requirements. Document this configuration in your Security Risk Assessment and set a calendar reminder to verify settings annually or after any platform change.
Confirms your Microsoft 365 account is on a healthcare BAA-covered plan and that the BAA is executed correctly for your practice.
Configures Microsoft Purview for in-transit and at-rest encryption and verifies the settings are active and documented.
Enrolls all staff accounts in MFA and configures Conditional Access policies to enforce it before any patient communication is sent.
Configures email retention to meet HIPAA's six-year requirement so documentation is preserved and retrievable on request.
Enables phishing and spam filtering to reduce credential theft risk across all staff email accounts.
Documents the email configuration as part of the technical component of your HIPAA Security Risk Assessment.
Ekim IT Solutions works exclusively with dental practices. We serve New England and New York with on-site support and dental practices nationwide with remote support. We configure and manage HIPAA-compliant email for dental practices with the right encryption, BAA documentation, and Microsoft 365 or Google Workspace setup so your team can email patients without putting your practice at risk.