How to Email Patients Securely: What You Can and Can't Send (2027)
How to email patients securely in 2027: what HIPAA allows, the patient's right to unencrypted email, minimum necessary, consent wording and a safe default.
By ClinikEHR Team
Duration
14 MINSHow to email patients securely: HIPAA doesn't ban email with patients. HHS says providers may email patients "provided they apply reasonable safeguards," and a patient who asks for their records by unencrypted email has a right to get them once you've warned them of the risk. In practice, that means using a secure portal link for anything clinical by default, sending plain email only to patients who have agreed to it, checking the address, and keeping every message to what it actually needs to say.
This guide covers what HHS actually says, what's safe to send, consent wording you can adapt, and how ClinikMail handles patient email.
Quick Answer
- Email is allowed with reasonable safeguards (HHS FAQ, opened September 2026).
- Patients can ask for unencrypted email. You must warn them briefly of the risk and confirm they still want it. If they say yes, you must comply (HHS FAQ 2060, opened September 2026).
- You can't force patients onto insecure channels. HHS says a covered entity "is not permitted to require" a patient to accept unsecure methods.
- Safe default: a short notification email with the clinical content behind a secure portal link. Use plain email only with recorded consent, and keep it brief.
Patient email with a safe default built in
What HHS Actually Says About Emailing Patients
Three HHS pages answer most of the questions clinics ask.
1. Email is allowed, with safeguards. HHS's FAQ says the Privacy Rule "does not prohibit the use of unencrypted e-mail for treatment-related communications," but that "other safeguards should be applied," such as "limiting the amount or type of information disclosed." The examples it gives are checking the address before sending and sending an alert to confirm the address first.
2. If the patient emails first, HHS says you "can assume (unless the patient has explicitly stated otherwise) that e-mail communications are acceptable." If you think the patient doesn't understand the risks, you can explain them and let the patient decide.
3. Patients can choose unencrypted email for their records. Under the right of access, HHS says individuals "have a right to receive a copy of their PHI by unencrypted e-mail" if they ask. You "must provide a brief warning" about the risk and confirm they still want it, and "if the individual says yes, the covered entity must comply."
Patients can also ask you to use alternative means of communication under the confidential-communications right (45 C.F.R. § 164.522(b)), and HHS notes you should accommodate reasonable requests. If a patient finds unencrypted email unacceptable, you should offer a more secure option.
Minimum Necessary: What It Does and Doesn't Cover
HHS's minimum necessary guidance (opened September 2026) requires covered entities to take "reasonable steps to limit the use or disclosure of, and requests for, protected health information to the minimum necessary." Two exceptions matter for email: the standard doesn't apply to disclosures to the patient themselves or to disclosures to another provider for treatment.
So for an email to the patient, minimum necessary isn't the rule doing the work. HHS's email FAQ still tells you to limit what goes into unencrypted email as a reasonable safeguard. When your email goes to anyone else, such as a family member, an employer or a payer, minimum necessary applies in full unless an exception covers it.
A practical test before you press Send: if this email were forwarded to the patient's employer or read over their shoulder, what would it reveal? Take out anything the message doesn't need.
What You Can and Can't Send
This table is practice guidance based on the HHS pages above, not a legal rule.
| Usually fine by plain email | Send through the portal (or plain email only with consent) | Don't email |
|---|---|---|
| Appointment date, time and location | Test results and their meaning | Passwords, full card numbers or ID numbers |
| "Please call us to reschedule" | Diagnoses, medications, treatment plans | Another patient's information |
| Forms to complete (as a secure link) | Therapy or behavioral health details | Anything to an address you haven't verified |
| Billing reminders without clinical detail | Records the patient requested | Group emails with visible recipients (use Bcc or individual sends) |
| Office hours and practice updates | Referral letters and clinical documents | Sensitive detail in the subject line |
Two habits prevent most email incidents. Verify the address against the one on the patient's record. Keep subject lines generic, like "A message from your clinic," because subject lines show up in notifications and on lock screens.
Consent Wording You Can Adapt
Record consent before you switch a patient to plain email, and record it again if they withdraw it. Here's original wording to adapt with your compliance advisor:
Email communication consent. You've asked us to send information about your care by regular email. Regular email isn't private in transit: someone who can get into your mailbox, your device or the network between us may be able to read it. We'll keep emails as short as we can and never ask you for passwords or payment details by email. You can change your mind at any time by telling any member of our team, and we'll go back to sending you secure messages through the patient portal. Do you still want us to use regular email?
☐ Yes, use regular email for: ☐ appointment details ☐ results and clinical updates ☐ copies of my records Patient name, date, and how consent was given (in person / signed / via portal)
Keep it on the patient's record, dated and attributed to the staff member who took it.
A 6-Step Patient Email Policy
- Default to secure messages through the patient portal for anything clinical.
- Record consent before sending any clinical content by plain email.
- Verify every address against the patient record, especially for shared family addresses.
- Keep it brief. Put only what's necessary in the body and keep the subject line generic.
- File the conversation on the chart so the care team sees it.
- Train staff yearly and review a few sent messages each quarter.
For boundaries and response times, see our guide on handling client emails without burnout.
Worked Examples: Five Everyday Patient Emails
Rules are easier to apply to real messages. Here's how the guidance above plays out in five situations a front desk meets every week.
1. An appointment reminder. Plain email is usually fine. Keep it to the date, time, location and a way to reschedule, for example: "Your appointment at Riverside Clinic is on Tuesday at 2:30pm. Reply or call us if you need to change it." Leave out the reason for the visit and the clinician's specialty, which can reveal more than the patient would like.
2. Test results are ready. Send a short notification with a generic subject line and put the results behind the secure portal link. If the patient has consented to plain email for results, you can send them directly, but keep the message focused and suggest a call or visit for anything that needs explaining.
3. A patient emails first, asking about side effects. HHS says you can assume email is acceptable when the patient starts the conversation, unless they've told you otherwise. Reply briefly, move clinical detail to the portal or a call, and link the thread to the patient's chart so the prescriber sees it. If the question sounds urgent, phone the patient rather than waiting for a reply.
4. A family member asks for a copy of records. Don't reply to the address that wrote in just because the name sounds right. Check who is entitled to the records under your policy and state law, confirm their identity, and send only to an address you've verified.
5. A patient asks for their records by regular email. This is the right-of-access case. Give the brief risk warning, confirm they still want plain email, record their answer, and send. You can still offer the portal as a more secure alternative, but you can't insist on it.
Common Mistakes, and How to Avoid Them
Most patient-email incidents are small human slips rather than hacks. Autocomplete picks the wrong person: two patients with similar names sit side by side in the address suggestions, so slow down on the To line and check it against the record. Reply-all on a family thread: a spouse or parent was copied once and keeps receiving updates they were never meant to see. Old addresses: a patient changed email a year ago and the old address still sits in someone's contacts, so update the record whenever a patient tells you. The wrong attachment: open every attachment before you send it, or better, share documents through the portal. Visible group recipients: a clinic newsletter sent with everyone in the To field exposes who your patients are, so use Bcc or send individually.
If a message does go to the wrong person, tell your privacy lead straight away. Write down what was sent, to whom and when, and let them decide what, if anything, has to be reported. Don't rely on "recall message" features, which often don't work once an email has left your system.
Product Insight: ClinikMail's Two Patient-Email Modes
ClinikMail is HIPAA-compliant and covered by our BAA. When you write to a patient, it gives you two modes to choose from for each message:
- Secure message (default). The patient gets a short email that says a secure message is waiting, with a button to open it in their portal. The email itself carries no subject line and no clinical detail. They read and reply in the portal.
- Direct email (with recorded consent). Direct email only unlocks after you record the patient's consent and how they gave it: they told you, they signed for it, or they agreed in the portal. Every new message still starts on secure message, so plain email is a deliberate choice each time.
- A warning before sensitive detail goes out in plain text, with the secure option one click away.
- Chart linking. Link the thread to the patient and it appears on their timeline.
Secure messages need your clinic's client portal switched on. They go to one patient at a time and don't carry attachments yet, so share files from the patient's record in the portal instead. See pricing (Mail is on every plan, Free included), patient management and client privacy controls.
Frequently Asked Questions (FAQs)
1. Is it HIPAA compliant to email patients?
Yes, with reasonable safeguards. HHS says providers may email patients, including by unencrypted email, provided they apply safeguards such as verifying addresses and limiting the information they send.
2. Can a patient ask me to send their records by regular email?
Yes. HHS says patients have a right to receive a copy of their PHI by unencrypted email if they ask. You must give a brief warning about the risk and confirm they still want it.
3. Do I need written consent to email a patient?
HHS asks for a warning and confirmation rather than a specific form. Recording consent on the patient's record, with the date and who took it, is good practice and makes it easier to show later.
4. Does minimum necessary apply to emails to patients?
The minimum necessary standard doesn't apply to disclosures to the patient themselves. HHS still advises limiting what you put in unencrypted email as a reasonable safeguard.
5. What should never go in an email subject line?
Diagnoses, test names, medications or anything clinical. Subject lines appear in notifications and on lock screens, so keep them generic.
6. How does ClinikMail handle patient email?
By default it sends the patient a secure portal link and keeps the clinical content out of the email. Direct email becomes available only after you record the patient's consent.
Conclusion
Emailing patients is allowed, and patients can even insist on plain email for their records once they've been warned. The safe way to do it is simple: default to a secure portal link, record consent before sending clinical detail in plain email, verify every address, and keep messages and subject lines short. ClinikMail builds that default into every message you send to a patient.
Key takeaways:
- HHS allows email with patients when reasonable safeguards are in place
- Patients have a right to unencrypted email for their records after a brief risk warning
- You can't require patients to accept insecure channels
- Minimum necessary doesn't cover disclosures to the patient, but limiting content is still a safeguard
- ClinikMail defaults to a secure portal link and unlocks direct email only after consent is recorded
Ready to make secure patient email the default? Try ClinikEHR free, see our pricing, or book a free demo.
Disclaimer: This article summarizes HHS guidance in plain English and is not legal advice. State laws and your own risk analysis may require more. Confirm your policy with a compliance advisor. ClinikEHR and its authors shall not be held liable for any decisions made based on the information provided herein.
Related Articles
- HIPAA-Compliant Email for Healthcare Providers: 2027 Buyer's Guide
- Is Gmail HIPAA Compliant? What Clinics Must Do in 2027
- How to Handle Client Emails Without Burning Out
- 7 Best Patient Communication & Secure Messaging Tools in 2027
- Consent & Intake Form Templates for Private Practice
- HIPAA-Compliant Messaging 2027: Email vs Portal vs Secure Chat
Stay in the loop
Subscribe to our newsletter for the latest updates on healthcare technology, HIPAA compliance, and exclusive content delivered straight to your inbox.