TL;DR
Emailing protected health information (PHI) to patients is one of the most common compliance risks in rehab clinics. The safest email is the one you never send. This guide defines what counts as PHI, explains why standard email is a poor channel for it, and gives you seven concrete strategies to stop emailing PHI altogether, with a focus on the real-world scenarios physical therapists, occupational therapists, SLPs, and chiropractors face daily.
Somewhere right now, a physical therapist is finishing up a session and thinking, “I’ll just email this exercise PDF to my patient before I forget.” It takes fifteen seconds. It feels harmless. And it might be a HIPAA violation.
The problem isn’t that email exists. The problem is that standard email was never designed to protect health information, and most rehab providers don’t realize how much PHI they’re sending through it every day. Home exercise programs, progress photos, appointment details tied to diagnoses, referral notes: all of it qualifies as protected health information the moment it’s paired with a patient identifier.
This guide is built for the rehab provider who wants to stop taking that risk. Not “how to email PHI compliantly” (most articles cover that), but how to avoid emailing PHI to patients in the first place, and what to do instead.
Exploring HIPAA-compliant tools for PTs is a good starting point if you want to see what a secure alternative looks like in practice.
What Is PHI? A Quick Reference
Protected Health Information, or PHI, is individually identifiable health information that is transmitted or maintained in any form by a covered entity or business associate. The key phrase is “individually identifiable.” Health data on its own (a set of blood pressure readings, a list of exercises) is not PHI. But the moment you attach a name, email address, date of birth, or any other identifier, it becomes protected under HIPAA.
HIPAA defines 18 specific identifiers that turn health information into PHI:
- Names
- Geographic data smaller than a state
- Dates (except year) related to an individual
- Phone numbers
- Fax numbers
- Email addresses
- Social Security numbers
- Medical record numbers
- Health plan beneficiary numbers
- Account numbers
- Certificate/license numbers
- Vehicle identifiers and serial numbers
- Device identifiers and serial numbers
- Web URLs
- IP addresses
- Biometric identifiers
- Full-face photographs and comparable images
- Any other unique identifying number or code
Why This Matters for Rehab Providers
Think about what you typically put in a patient email: their name, their exercise program, maybe a photo or video from the session, a note about their condition. That combination is PHI, full stop.
Home exercise instructions should be treated as PHI when combined with patient identifiers. This includes appointment changes tied to conditions, progress notes, images, referrals, billing details, and exercise prescriptions. A PDF with “Jane Smith, ACL Rehab Protocol, Week 4” is not just a helpful document. It’s ePHI (electronic PHI) the second it hits an email server.
Understanding how health literacy affects communication is also important here, because patients often don’t grasp these risks either.
Why Email and PHI Don’t Mix
Most top-ranking articles on this topic focus on how to email PHI safely, using encryption, business associate agreements, and access controls. That’s useful, but it misses the point of how to avoid emailing PHI to patients entirely. Before we get to the alternatives, it helps to understand why email is such a poor vehicle for health information.
Standard Email Isn’t Encrypted End-to-End
Regular email (Gmail, Outlook, Yahoo) transmits messages in a way that can be intercepted at multiple points. Even when TLS encryption protects messages in transit between servers, subject lines and metadata remain unencrypted. That means any PHI in a subject line is exposed regardless of your encryption setup.
Misdirected Emails Are the Most Common Breach Vector
What is increasingly common is that a patient’s email address gets entered into a record with errors. The email goes to the wrong person, and that counts as a breach. According to the Paubox 2025 Healthcare Email Security Report, email remains the leading attack vector for healthcare data breaches, resulting in financial penalties, compromised patient data, and increased enforcement actions.
Family Members and Coworkers Can See Patient Emails
Emails sent to a patient may be viewed by family members if the patient leaves their phone unattended, or by coworkers if the email goes to a work address. Depending on the content, this could constitute a breach if consent wasn’t obtained.
Email Disclaimers Provide Zero Legal Protection
Many providers add a “This email is confidential” footer and assume they’re covered. They aren’t. A HIPAA email disclaimer won’t absolve the sender of a violation if PHI is sent to the wrong recipient. It may reassure the intended reader, but it serves no other worthwhile legal purpose.
The Numbers Tell the Story
Healthcare data breaches have affected over 935 million individuals through January 2026. The average cost of a healthcare breach in 2025 reached $10.93 million, the highest of any industry for the fourteenth consecutive year, according to IBM’s Cost of a Data Breach Report. Most of these breaches resulted from employee negligence and noncompliance rather than external hacking.
What HIPAA Actually Says About Email
Here’s the part that surprises many providers: HIPAA does not ban emailing PHI. The Privacy Rule does not prohibit the use of unencrypted email for treatment-related communications between providers and patients. But it sets a high bar for safeguards, and the practical reality is that most small clinics can’t meet that bar with standard email.
The Privacy Rule and Minimum Necessary Standard
The HIPAA Minimum Necessary standard requires covered entities and business associates to restrict uses and disclosures of PHI to the minimum amount necessary to achieve the purpose. There’s an exception for treatment communications between providers, and for disclosures to the patient who is the subject of the information. But “minimum necessary” still governs what you include in any email, and practitioners routinely violate it by sending full treatment notes when a simple “your appointment is confirmed” would suffice.
An AHIMA survey found that 38% of respondents were unsure if their employer had even adopted a definition for the minimum necessary standard. That’s a training failure.
The Security Rule: Encryption Is “Addressable” but Practically Required
HIPAA classifies encryption as an “addressable” safeguard, meaning you can choose an alternative if you document why. In practice, failing to encrypt ePHI is cited as a factor in 48% of HIPAA fines. The distinction between “addressable” and “required” has become mostly academic.
Patient Consent Doesn’t Eliminate Your Obligations
If a patient requests to receive information by email after being informed of the risks, HIPAA allows it. But that consent must be documented specifically, kept current, and stored in the EHR. A general intake form signature is not enough. Failing to track these authorizations could lead to a workforce member unintentionally violating HIPAA.
The Minimum Necessary Standard: Often Overlooked
This concept deserves its own section because it’s almost never discussed in email compliance articles, yet it directly governs what providers should and shouldn’t include in any communication.
The standard is simple in concept: share only the minimum PHI needed to accomplish the task. In practice, it means:
- Appointment reminders should include the date and time, not the diagnosis or treatment type.
- Follow-up emails should reference an account number, not the patient’s full name and condition.
- HEP delivery should happen through a channel that doesn’t require embedding identifiers in the message body.
The minimum necessary standard does not apply to disclosures between providers for treatment purposes, or to the patient themselves requesting their own information. But it applies to virtually everything else, including how you structure internal communications and referral emails.
7 Ways to Avoid Emailing PHI to Patients
This is the core of the article. Rather than teaching you how to email PHI compliantly, these strategies help you stop emailing PHI altogether.
1. Use HIPAA-Compliant In-App Messaging Instead of Email
The most direct replacement for email is a secure messaging platform built for healthcare. Patient portals integrated with your EHR, or standalone apps with end-to-end encryption and audit trails, keep PHI inside a protected environment. Messages, images, exercise videos, and care plans stay within the app rather than traveling through email servers.
Practitioners on Reddit frequently describe the “personal Gmail workaround” problem: solo PTs who use personal email or text to send HEPs because their EMR lacks a patient-facing communication tool. This is the highest-risk scenario, and it’s the most common one in small practices.
See pricing for HIPAA-compliant plans that include in-app messaging, video, and care plan delivery.
Secure messaging bridges the gap between convenience and compliance. If your clinic is juggling sensitive conversations through fragmented channels (emails, texts, voicemails), adopting a single secure platform reduces both risk and administrative burden. For a deeper look at this approach, read about improving patient communication with portals.
2. Send Secure Links, Not Raw Content
When you must notify a patient about something, send a link to a secure portal rather than embedding PHI in the email body. The patient clicks the link, authenticates with a one-time code or login, and views the information in a protected environment. The email itself contains no health information.
This approach is especially useful for sharing exercise videos with patients after a session. Instead of attaching a PDF with their name and diagnosis, you direct them to the app where their personalized program lives.
3. Strip All Identifiers from Non-Clinical Emails
If you send administrative emails (appointment reminders, billing notices, pre-visit paperwork), remove every identifier you can. Use account numbers instead of names. Reference “your upcoming appointment” instead of “your ACL follow-up.” Never include Social Security numbers, dates of birth, or full addresses.
This is the minimum necessary standard in action. The goal is to make any email that does leave your system essentially useless to an unintended recipient.
4. Keep PHI Out of Subject Lines
Email subject lines and metadata are not encrypted, even when the message body is. They remain visible for routing and filtering purposes. A subject line reading “John Smith, Rotator Cuff Rehab Progress Update” is a violation waiting to happen. Use generic subjects: “Your care plan update” or “New message from [clinic name].”
5. Never Use Personal Email Accounts
Emailing ePHI to or from a personal email account is a HIPAA violation regardless of the intention, whether it’s to get help with a spreadsheet, complete work at home, or catch up on a backlog. This applies to providers and staff equally. Any emailing of ePHI to a personal account could be considered theft, and the repercussions can be far more severe than losing a job.
Practitioners on LinkedIn have shared stories of well-meaning staff forwarding patient lists to home accounts to “work over the weekend.” Every one of those forwards is a reportable incident.
6. Document Patient Communication Preferences
Before you communicate electronically with any patient, record their preferred method, their verified contact information, and their informed consent (or refusal) for electronic communication. Store this in the EHR. Review it periodically.
This documentation serves two purposes. First, it protects you if a patient later claims they didn’t consent. Second, it forces a conversation about alternatives. When you explain the risks of email and offer a secure app instead, many patients will choose the safer option.
7. Train Staff at Least Annually and at Onboarding
According to a HIMSS Cybersecurity Survey, 67% of healthcare organizations have not completed a current, comprehensive security risk analysis, the number one HIPAA requirement. Training gaps are the root cause of most email-related breaches.
Training should cover what counts as PHI, why email is risky, what alternatives exist, and what to do if someone sends PHI by mistake. It should happen at onboarding and at least once per year. For a look at how much time clinicians already lose to administrative work (and why they resort to shortcuts like email), see how much time providers waste on admin tasks.
What Happens If You Email PHI Without Safeguards
The consequences are real and scaled to culpability.
Civil Penalty Tiers (2026)
| Violation Level | Penalty Range Per Violation |
|---|---|
| Unknowing | $145 to $36,379 |
| Reasonable cause | $1,455 to $72,757 |
| Willful neglect (corrected) | $14,548 to $72,757 |
| Willful neglect (not corrected) | $72,757 to $2,190,294 |
Source: HIPAA Journal penalty structure
Enforcement Is Increasing
The HHS Office for Civil Rights (OCR) resolved 21 enforcement actions in 2025, the second-highest annual total on record. OCR applies the same compliance standards whether the entity is a solo practice or a large health system. Small practices are not exempt.
In extreme cases, criminal penalties apply. Individuals who wrongfully disclose PHI face fines of up to $50,000 and up to a year of imprisonment.
The Most Common Triggers
The violations that most frequently result in fines are failure to conduct a risk analysis (71% of cases), insufficient access controls (54%), and failure to encrypt ePHI (48%). Email-related breaches touch all three.
Secure Alternatives to Email for Rehab Providers
Knowing how to avoid emailing PHI to patients requires having something better to use. Here are the practical alternatives, ranked by effectiveness.
HIPAA-Compliant Messaging Apps
Purpose-built healthcare communication apps with end-to-end encryption, access controls, and audit trails. These replace email, text, and voicemail with a single secure channel. Patients receive a notification to open the app, where they view their message, exercise video, or care plan.
In-App HEP Delivery
This is the biggest win for rehab providers specifically. Instead of creating a PDF, attaching a patient’s name, and emailing it, you build the home exercise program inside a HIPAA-compliant app. The patient accesses it on their phone. No email required, no PHI exposed. If you’re still using printout-based HEP tools, explore alternatives to emailing HEP PDFs that keep everything within a secure environment.
Patient Portal Delivery
EHR-integrated portals allow patients to log in and view messages, lab results, care plans, and appointment details. The communication stays within the portal’s encrypted environment rather than traveling through email.
Encrypted Email as a Last Resort
If you absolutely must use email, use a HIPAA-compliant email service that encrypts messages end-to-end, requires a BAA, and provides access controls. But even encrypted email doesn’t solve the misdirected-address problem, and it doesn’t prevent PHI from appearing in subject lines or metadata.
Comparison Table
| Feature | Standard Email | Encrypted Email | Patient Portal | HIPAA Messaging App |
|---|---|---|---|---|
| End-to-end encryption | No | Yes | Yes | Yes |
| BAA available | Rarely | Yes | Yes | Yes |
| Prevents misdirection | No | No | Yes (login required) | Yes (login required) |
| Supports video/photos | Yes (unsecured) | Yes | Limited | Yes |
| Audit trail | No | Partial | Yes | Yes |
| PHI in subject line risk | High | Medium | None | None |
| Requires patient app/login | No | Sometimes | Yes | Yes |
For clinics ready to move away from email-based workflows, solutions for single and multi-location practices can handle the transition.
Related HIPAA Terms: A Mini-Glossary
ePHI (Electronic Protected Health Information)
PHI that is created, received, stored, or transmitted in electronic form. Any email containing PHI automatically becomes ePHI and falls under the HIPAA Security Rule’s requirements for encryption, access controls, and audit trails.
Covered Entity
A health plan, healthcare clearinghouse, or healthcare provider that transmits health information electronically. If you’re a PT, OT, SLP, or chiropractor who bills electronically, you are a covered entity and HIPAA applies to you.
Business Associate Agreement (BAA)
A legally required contract between a covered entity and any third-party vendor that creates, receives, maintains, or transmits PHI on the entity’s behalf. If your email provider handles PHI and you don’t have a BAA with them, you’re in violation.
Breach Notification Rule
HIPAA requires covered entities to notify affected individuals, HHS, and (in some cases) the media within 60 days of discovering a breach affecting 500 or more individuals. Smaller breaches must be reported annually. An email sent to the wrong address triggers this rule.
De-Identification (Safe Harbor Method)
The process of removing all 18 HIPAA identifiers from a dataset so it no longer qualifies as PHI. De-identified data can be shared freely. This is relevant when you want to send general exercise information without it being subject to HIPAA, though it requires removing every identifier, not just the obvious ones.
FAQ
Does my home exercise program count as PHI?
Yes, when it’s combined with any patient identifier. A generic list of exercises for “rotator cuff rehabilitation” is not PHI. But a PDF titled “Jane Smith, Rotator Cuff Protocol, Week 3” absolutely is. The same applies to exercise videos recorded during a session that show the patient’s face or are tagged with their name. This is one of the biggest blind spots in rehab compliance, and it’s why learning how to avoid emailing PHI to patients matters so much for therapists specifically.
Is it a HIPAA violation if the patient emails me first?
Not automatically. If a patient initiates email communication, you can respond, but you should still apply reasonable safeguards. Limit the PHI in your reply, don’t include the original message in your response, and avoid adding information beyond what the patient asked about. Document that the patient initiated the exchange. And whenever possible, redirect them to a secure channel for ongoing communication.
Can I email appointment reminders?
Yes, if the reminder contains only administrative information: the date, time, and location. Do not include the type of appointment, the provider’s specialty (which implies the condition), or any clinical details. Keep subject lines generic. Better yet, use your EHR’s automated reminder system or a HIPAA-compliant messaging app.
Do personal trainers need to worry about PHI?
It depends. Personal trainers are generally not covered entities under HIPAA. However, when a trainer works with a covered entity (a hospital wellness program, a clinic-based fitness program tied to a group health plan), HIPAA may apply. Even outside HIPAA, trainers should protect client health information under state privacy laws and professional ethics standards. More details on this are available on the personal trainers and fitness page.
What if my patient gives verbal consent to receive email?
Verbal consent is better than nothing, but it’s weak protection. HIPAA requires that you inform the patient of the risks and document their preference. A verbal agreement with no written record leaves you exposed if a breach occurs and the patient claims they never consented. Use a written or electronic consent form, store it in the EHR, and review it periodically.
What’s the difference between PHI and ePHI?
PHI covers health information in any form: paper, verbal, electronic. ePHI is specifically the electronic subset, information created, received, stored, or transmitted digitally. Email, text messages, EHR records, and cloud-stored documents all contain ePHI. The HIPAA Security Rule applies specifically to ePHI and requires technical safeguards like encryption and access controls.
My EMR doesn’t have a patient-facing messaging tool. What do I do?
This is extremely common, especially in solo and small-group practices. Practitioners on Reddit describe this as the main reason they default to personal email or text for sending HEPs. The solution is a standalone HIPAA-compliant messaging and HEP app that works alongside your EMR. You build care plans, send secure messages, and share videos through the app while using your EMR for clinical documentation. For guidance on preventing PHI leaks through text as well, read the guide to stopping PHI leaks through SMS.
How often should I train staff on email and PHI policies?
At minimum, annually and at every new hire’s onboarding. But given that email is the number one attack vector for healthcare breaches, quarterly refreshers (even brief ones) are worth the investment. Focus on practical scenarios: what to do when a patient asks for records by email, how to verify an address before sending, and how to report a misdirected message immediately.
The simplest way to avoid emailing PHI to patients is to give yourself a better option. When your clinic has a secure, easy-to-use communication channel that patients actually like, the temptation to “just email it real quick” disappears.
{ “@context”: “https://schema.org”, “@type”: “FAQPage”, “@id”: “#faq”, “mainEntity”: [ { “@type”: “Question”, “@id”: “#faq-question-1”, “name”: “Does my home exercise program count as PHI?”, “acceptedAnswer”: { “@type”: “Answer”, “text”: “Yes, when it’s combined with any patient identifier. A generic list of exercises for \”rotator cuff rehabilitation\” is not PHI. But a PDF titled \”Jane Smith, Rotator Cuff Protocol, Week 3\” absolutely is. The same applies to exercise videos recorded during a session that show the patient’s face or are tagged with their name. This is one of the biggest blind spots in rehab compliance, and it’s why learning how to avoid emailing PHI to patients matters so much for therapists specifically.” } }, { “@type”: “Question”, “@id”: “#faq-question-2”, “name”: “Is it a HIPAA violation if the patient emails me first?”, “acceptedAnswer”: { “@type”: “Answer”, “text”: “Not automatically. If a patient initiates email communication, you can respond, but you should still apply reasonable safeguards. Limit the PHI in your reply, don’t include the original message in your response, and avoid adding information beyond what the patient asked about. Document that the patient initiated the exchange. And whenever possible, redirect them to a secure channel for ongoing communication.” } }, { “@type”: “Question”, “@id”: “#faq-question-3”, “name”: “Can I email appointment reminders?”, “acceptedAnswer”: { “@type”: “Answer”, “text”: “Yes, if the reminder contains only administrative information: the date, time, and location. Do not include the type of appointment, the provider’s specialty (which implies the condition), or any clinical details. Keep subject lines generic. Better yet, use your EHR’s automated reminder system or a HIPAA-compliant messaging app.” } }, { “@type”: “Question”, “@id”: “#faq-question-4”, “name”: “Do personal trainers need to worry about PHI?”, “acceptedAnswer”: { “@type”: “Answer”, “text”: “It depends. Personal trainers are generally not covered entities under HIPAA. However, when a trainer works with a covered entity (a hospital wellness program, a clinic-based fitness program tied to a group health plan), HIPAA may apply. Even outside HIPAA, trainers should protect client health information under state privacy laws and professional ethics standards. More details on this are available on the [personal trainers and fitness page](https://ac-health.com/personal-trainers-fitness-instructors/).” } }, { “@type”: “Question”, “@id”: “#faq-question-5”, “name”: “What if my patient gives verbal consent to receive email?”, “acceptedAnswer”: { “@type”: “Answer”, “text”: “Verbal consent is better than nothing, but it’s weak protection. HIPAA requires that you inform the patient of the risks and document their preference. A verbal agreement with no written record leaves you exposed if a breach occurs and the patient claims they never consented. Use a written or electronic consent form, store it in the EHR, and review it periodically.” } }, { “@type”: “Question”, “@id”: “#faq-question-6”, “name”: “What’s the difference between PHI and ePHI?”, “acceptedAnswer”: { “@type”: “Answer”, “text”: “PHI covers health information in any form: paper, verbal, electronic. ePHI is specifically the electronic subset, information created, received, stored, or transmitted digitally. Email, text messages, EHR records, and cloud-stored documents all contain ePHI. The HIPAA Security Rule applies specifically to ePHI and requires technical safeguards like encryption and access controls.” } }, { “@type”: “Question”, “@id”: “#faq-question-7”, “name”: “My EMR doesn’t have a patient-facing messaging tool. What do I do?”, “acceptedAnswer”: { “@type”: “Answer”, “text”: “This is extremely common, especially in solo and small-group practices. Practitioners on Reddit describe this as the main reason they default to personal email or text for sending HEPs. The solution is a standalone HIPAA-compliant messaging and HEP app that works alongside your EMR. You build care plans, send secure messages, and share videos through the app while using your EMR for clinical documentation. For guidance on preventing PHI leaks through text as well, read the [guide to stopping PHI leaks through SMS](https://ac-health.com/how-to-stop-phi-leaking-through-sms-hipaa-guide/).” } }, { “@type”: “Question”, “@id”: “#faq-question-8”, “name”: “How often should I train staff on email and PHI policies?”, “acceptedAnswer”: { “@type”: “Answer”, “text”: “At minimum, annually and at every new hire’s onboarding. But given that email is the number one attack vector for healthcare breaches, quarterly refreshers (even brief ones) are worth the investment. Focus on practical scenarios: what to do when a patient asks for records by email, how to verify an address before sending, and how to report a misdirected message immediately. — The simplest way to avoid emailing PHI to patients is to give yourself a better option. When your clinic has a secure, easy-to-use communication channel that patients actually like, the temptation to \”just email it real quick\” disappears. > Ready to stop emailing PHI? [Talk to the AC Health team](https://ac-health.com/contact-us/) about setting up HIPAA-compliant messaging for your practice.” } } ] }Ready to stop emailing PHI? Talk to the AC Health team about setting up HIPAA-compliant messaging for your practice.


