top of page

Patient Consent Does Not Waive HIPAA Email Encryption

Writer: Author: Venus Caruso
Author: Venus Caruso
18 minutes ago
6 min read

Does patient consent waive HIPAA email encryption? No.

A patient’s request to receive unencrypted email does not eliminate a covered entity’s or business associate’s duty to safeguard electronic protected health information ("ePHI") under the HIPAA Security Rule.

A common compliance error is to treat a signed form, a checked box, or a verbal “email is fine” as permission to send protected health information without encryption. That error confuses two different parts of HIPAA. The Privacy Rule can support a narrow, properly documented patient preference for how a patient is contacted. The Security Rule, however, still requires a reasonable and appropriate transmission safeguard, and a written decision if encryption is not used.

Does Patient Consent Eliminate HIPAA Email Encryption Requirements?

No. Patient consent does not waive HIPAA email encryption requirements.

HIPAA separates two questions:

  1. May the organization send this information to this person, in this way? That is a Privacy Rule question.

  2. How must ePHI be protected while it is created, stored, or transmitted? That is a Security Rule question.

A patient’s preference answers only the first question, and only for communications to that patient. It does not answer the second.

What 45 C.F.R. § 164.522(b) Allows for Unencrypted Email

45 C.F.R. § 164.522(b) gives an individual the right to request that a covered entity communicate confidential protected health information by alternative means or at alternative locations.

OCR guidance has recognized that a patient may prefer ordinary email after being told that unencrypted email can be intercepted or read by others who use the same account or device. If those conditions are met, the covered entity may honor the request. The request should be documented. The minimum necessary standard still applies. The accommodation is a patient-directed communication preference. It is not a general license to stop encrypting email across the practice.

What the HIPAA Security Rule Still Requires for Email

45 C.F.R. § 164.312(e)(2)(ii) makes encryption of ePHI in transit an addressable implementation specification. Addressable does not mean optional.

Under 45 C.F.R. § 164.306(d)(3), the organization must determine whether encryption is reasonable and appropriate. If it is, encryption must be implemented. If it is not implemented, the organization must document why and implement an equivalent alternative measure if reasonable and appropriate.

For email containing ePHI, encryption is almost always reasonable and appropriate. A chart note that “the patient consented to email” is not a risk analysis. It is not a documented addressable-specification decision.

What Patient Consent Cannot Do Under HIPAA

Consent does not accomplish the following.

Consent does not waive the Security Rule

The Security Rule applies to the organization’s systems, workforce, and transmission methods. A patient’s preference about one inbound mailbox does not excuse missing encryption controls, access controls, audit logs, or a current risk analysis. The organization remains responsible for ePHI it creates, receives, maintains, or transmits in ordinary operations.

Consent does not authorize unencrypted email to third parties

A request that the practice send records to the patient’s personal email address is not authorization to send the same information unencrypted to a specialist, laboratory, billing vendor, employer, family member, or another patient. Those transmissions require appropriate safeguards. If a vendor handles ePHI for the organization, a Business Associate Agreement is required under 45 C.F.R. § 164.502(e) and § 164.504(e).

Consent does not replace a Business Associate Agreement

An email platform, encryption gateway, or archiving vendor that handles ePHI for a covered entity is a business associate. Patient consent does not remove that contract requirement.

Informal permission is not a documented HIPAA request

OCR investigations look to records. A verbal remark that “email is fine,” a checked box with no risk warning, or a generic intake form that never describes the risk of unencrypted transmission is weak. If the organization relies on the confidential-communications pathway, the patient file should show that the risk was explained, that the patient still requested unencrypted email, that the address was verified, that the scope was defined, and that the patient may revoke the request.

How to Document a Patient Request for Unencrypted Email

Honor the preference as an exception. Do not treat it as the default rule for all mail.

  • Identify the request as a confidential-communications preference under 45 C.F.R. § 164.522(b), or as an informed choice after a risk warning.

  • Warn the individual that unencrypted email can be read by others with access to the account or device and can be intercepted in transit if encryption is not used.

  • Record the date, the staff member who obtained the request, the exact email address, whether the request is one-time or ongoing, and any limits on the content.

  • Apply the minimum necessary standard.

  • Permit patient revocation and document it promptly.

  • Do not extend the exception to vendors, other providers, or workforce-to-workforce email.

What to Include in the HIPAA Risk Analysis for Email

The risk analysis should address email as a transmission method and record the organization’s encryption decision in accordance with 45 C.F.R. § 164.306(d)(3) and § 164.312(e)(2)(ii).

Policies should state when encryption is required, who may approve an unencrypted patient-requested transmission, and how that approval is stored.

Training should correct any consent misconception by name. If encryption is not implemented for any class of transmissions, the written rationale required by § 164.306(d)(3) must exist before the first message is sent.

Why “The Patient Consented” Is Not a Defense

The OCR has not treated “the patient said email was acceptable” as a complete defense to Security Rule noncompliance. Recent enforcement activity has continued to emphasize incomplete risk analyses, weak technical safeguards, and policies that do not match actual operations. Email remains a recurring breach vector.

A documented patient preference may explain one outbound message to that patient. It will not explain an unencrypted practice-wide mail flow, a missing Business Associate Agreement, or the absence of a risk analysis that evaluated transmission security.

The proposed Security Rule update that would narrow the distinction between required and addressable specifications is not final. Until a final rule is published and effective, the current addressable framework governs. That framework already requires a documented decision. Patient consent does not fill a missing analysis.

HIPAA Email Consent Compliance Checklist

  • Confirm that the email platform and any related vendor are covered by a current Business Associate Agreement.

  • Adopt encryption or an equivalent secure-delivery method as the ordinary method for electronic protected health information.

  • Draft a short patient-preference form that includes the risk warning, the address, the scope, and revocation language.

  • Prohibit reliance on verbal consent alone.

  • Train workforce members that consent is not a waiver of encryption for third-party or internal transmissions.

  • Store the Security Rule analysis and the Privacy Rule preference forms so each can be produced separately.

HIPAA Unencrypted Email FAQ

Is encryption required for HIPAA-compliant email?

Under the current Security Rule, encryption in transit is addressable, not labeled “required.” For email containing ePHI, encryption is ordinarily reasonable and appropriate. It must therefore be implemented or replaced by an equivalent, documented measure. Treating addressable as optional is a common error.

Can a patient request unencrypted email under HIPAA?

Yes. A patient may request communications by unencrypted email after being advised of the risks. A covered entity may honor that request for communications to that patient. The request does not require or permit the covered entity to send unencrypted ePHI to other recipients.

Does a general consent form authorize unencrypted HIPAA email?

Generally, no. A treatment consent or a generic permission to “contact me by email” that does not describe the security risk, identify the address, or define scope is not a reliable substitute for a Security Rule safeguard or a documented confidential-communications request.

If the practice uses a patient portal, is an email encryption policy still needed?

Yes. A portal reduces some email volume. It does not eliminate referrals, records requests, billing correspondence, or staff messages that still leave the organization by email. Those transmissions remain subject to the Security Rule.

Does patient consent replace a Business Associate Agreement for email?

No. If a vendor handles ePHI for the organization, a Business Associate Agreement is required. The patient’s communication preference does not create or replace that contract.

Closing Remarks

Patient consent is not a HIPAA encryption waiver. Section 164.522(b) and related OCR guidance create a narrow, documented pathway for sending unencrypted email to a patient who understands the risk and still prefers that method. That pathway does not displace the Security Rule, does not authorize unencrypted disclosures to third parties, and does not replace a Business Associate Agreement or a current risk analysis.


If you would like to explore how Venus Caruso can assist with your HIPAA compliance needs, reach out to schedule a complimentary consultation using the contact form.

This post provides general information only. It is not, and should not be, construed as legal advice or a legal opinion on any particular matter or set of facts. Reading this post does not create an attorney-client relationship. Laws and regulations can change, and specific situations may require different approaches. Do not act or refrain from acting based solely on this post. Always consult a qualified attorney for advice tailored to your specific circumstances.


Back to Top

BACK TO TOP

The information contained on this website is provided for informational purposes only. Nothing stated in or contained on this website should be taken as legal advice or a legal opinion for any individual matter. Your use of this website, review of information on this website, sending or receiving mail to or from carusolawoffice.com, or contacting the firm via the website's contact form or by email to the firm or Venus Caruso does not create an attorney-client relationship with Caruso Law PLLC or Venus Caruso. No attorney-client relationship is formed with Caruso Law PLLC unless and until both Caruso Law PLLC and the prospective client have signed a written engagement letter.  

Hiring a lawyer is an important decision and should not be solely based on advertisements. 

CARUSO LAW PLLC

1645 Palm Beach Lakes Blvd.

West Palm Beach, FL 33401

Available by Appointment

​

​E: contact@carusolawoffice.com
T: (561) 437-2972

Caruso Law Favicon White+Blue _edited.pn
Gold colored badge logo with black text saying "Florida Trend's Florida Legal Elite"
  • X
  • LinkedIn

© 2023-2026 Caruso Law PLLC

bottom of page