HIPAA Audit Requirements for Emailing Pulmonary Spirometry Curves to Outside Pulmonologists

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

HIPAA Audit Requirements for Emailing Pulmonary Spirometry Curves to Outside Pulmonologists

Kevin Henry

HIPAA

June 20, 2026

9 minutes read
Share this article
HIPAA Audit Requirements for Emailing Pulmonary Spirometry Curves to Outside Pulmonologists

Emailing pulmonary spirometry curves to an outside pulmonologist can be compliant when you treat those files as Protected Health Information (PHI) and apply HIPAA’s Privacy, Security, and Breach Notification Rules. Below is a practical, audit‑ready framework that focuses on what auditors expect to see when PHI is transmitted by email for treatment purposes.

HIPAA Privacy Rule Compliance

Spirometry flow–volume loops, curves, and related test reports become PHI when they are linked to identifiers (for example, name, date of birth, medical record number). Under the Privacy Rule, disclosures for treatment—such as sending spirometry curves to a consulting outside pulmonologist—are permissible without Patient Authorization. You must still verify the recipient’s identity and role in the patient’s care before disclosure.

When email or any vendor system is involved in handling PHI, ensure appropriate Business Associate Agreements are in place with the service providers that store, process, or transmit PHI on your behalf (for example, cloud email, secure messaging platforms, archiving, or DLP tools). The receiving pulmonologist is another covered health care provider, not your business associate, but your technology vendors likely are.

Apply your organization’s policies and procedures, limit disclosures to the clinical purpose, and train your workforce on PHI Transmission Security expectations. State Privacy Regulations may impose additional or faster notification timelines, consent nuances, or content requirements. Treat this overview as general guidance; consult your compliance and legal teams for jurisdiction‑specific applications.

Implementing Reasonable Safeguards

Administrative safeguards

  • Verify the recipient before sending: confirm the pulmonologist’s identity, correct email address, and involvement in the patient’s treatment.
  • Use approved channels only; prohibit forwarding PHI to personal email accounts and disable auto‑complete where feasible for PHI messages.
  • Adopt a standard operating procedure (SOP) for emailing spirometry curves, including pre‑send checklists and a second‑person review for high‑risk transmissions.
  • Train staff on recognizing PHI, avoiding PHI in subject lines, and handling misdirected email incidents quickly.
  • Define retention and deletion rules for sent mail and attachments containing PHI.

Technical safeguards

  • Require multi‑factor authentication (MFA) for all email accounts that can access PHI.
  • Enable data loss prevention (DLP) to detect PHI patterns and enforce encryption or secure portal delivery automatically.
  • Turn on audit logging for send/receive events, policy overrides, and message recalls; retain logs for audit.
  • Harden configurations: disable legacy protocols, enforce strong passwords, and block auto‑forwarding to external domains.

Physical and operational safeguards

  • Secure endpoints with full‑disk encryption and mobile device management (remote wipe, screen‑lock policies).
  • Restrict access to spirometry testing systems and export functions to authorized roles only.
  • Store PHI attachments on approved, encrypted storage; avoid desktop downloads when possible.

Encryption Best Practices

HIPAA’s Security Rule treats encryption as an “addressable” Technical Safeguard: you must implement it where reasonable and appropriate, or document a comparable alternative and the risk reasoning. For email, encryption is now the industry baseline for PHI Transmission Security.

In‑transit encryption (TLS)

  • Force modern TLS (1.2/1.3) for SMTP; disallow downgrade to cleartext. If the recipient does not support TLS, route via a secure message portal instead of sending unencrypted email.
  • Use MTA‑STS/TLS reporting to ensure recipients consistently negotiate encrypted sessions.
  • Digitally sign messages where practical to strengthen integrity and authenticity.

End‑to‑end options (S/MIME, PGP) and secure portals

  • Prefer S/MIME or equivalent end‑to‑end encryption for provider‑to‑provider transmission when both sides can manage keys; this prevents unintended recipients from reading a misdirected message.
  • Use a secure portal for recipients without end‑to‑end capability; deliver a notification email that contains no PHI and requires authenticated portal access.

Attachment and at‑rest protection

  • Encrypt attachments (for example, AES‑256 within an encrypted PDF or ZIP) when end‑to‑end options are unavailable; share passcodes by a separate channel (phone/SMS).
  • Use FIPS 140‑2/140‑3 validated crypto modules where available and manage keys centrally; rotate keys periodically.
  • Ensure servers, laptops, and mobile devices storing PHI are encrypted at rest; enforce screen locks and remote wipe.

Operational hardening for email

  • Implement SPF, DKIM, and DMARC to reduce spoofing and phishing risks that could expose PHI.
  • Strip PHI from subject lines; keep identifiers only within encrypted content or secure portals.
  • Quarantine outbound messages that contain unusually large exports or multiple patient records pending review.

For disclosures to an outside pulmonologist for treatment, HIPAA does not require Patient Authorization. You may send the spirometry curves for consultation, diagnosis, or care coordination, subject to reasonable safeguards and your Security Rule controls.

Unencrypted emails to patients (or to a third party designated by the patient) may be sent when the patient prefers that method and you have advised them of the increased risk; document the patient’s preference and your discussion. For provider‑to‑provider transmissions, patient consent is not a substitute for inadequate security—use encryption or a documented, risk‑based alternative.

If the purpose is not treatment (for example, research without a waiver, marketing, or certain disclosures to non‑providers), you must obtain a valid, written Patient Authorization that meets HIPAA content requirements before emailing PHI.

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Applying Minimum Necessary Standard

The Minimum Necessary Standard generally applies to uses and disclosures for payment and health care operations, and to most internal workforce access. It does not apply to disclosures for treatment between providers. Even so, auditors expect you to practice data minimization whenever feasible.

  • Send only the spirometry curves and directly relevant test metadata (test date/time, calibration notes, patient identifiers needed for matching, and the ordering clinician).
  • Avoid attaching the entire chart or unrelated diagnostics; include concise clinical context in the encrypted body or cover sheet rather than lengthy notes.
  • Remove extraneous identifiers (for example, full address or SSN) that are not required for the consult.
  • When a full dataset is unnecessary, consider de‑identifying or limiting to the data set necessary for the pulmonologist’s review.

Maintaining Documentation and Records

Auditors focus heavily on documentation. Maintain the following artifacts and keep them current; retain HIPAA documentation for at least six years from creation or last effective date.

  • Risk analysis covering email workflows for spirometry reports and attachments, plus a risk management plan with assigned owners and timelines.
  • Policies and procedures for PHI Transmission Security, acceptable use, encryption, incident response, Right of Access, and sanction policy.
  • Business Associate Agreements with any vendors that store, transmit, or process PHI (email platform, secure portal, archiving, DLP, mobile device management).
  • Encryption decisions and configurations (TLS enforcement, portal use, S/MIME deployment, key management, passcode exchange procedures).
  • Training records for staff who handle pulmonary testing data and email PHI.
  • Access and audit logs showing who sent what, to whom, when; include policy override justifications.
  • Patient requests and authorizations: Right‑of‑Access requests, preferences for unencrypted email (if applicable), and any consent or restriction records.
  • Incident and breach logs, risk assessments, mitigation steps, and notifications sent.
  • State Privacy Regulations tracker noting stricter state requirements (for example, shorter breach timelines or additional notice recipients) and how your policy satisfies them.

Addressing Breach Notification Requirements

If an email containing PHI is impermissibly disclosed (for example, sent to the wrong recipient) and the PHI is unsecured, the Breach Notification Rule presumes a breach unless a documented risk assessment shows a low probability of compromise. Strong encryption with intact keys can qualify as “secured,” often eliminating notification duties, but you must evaluate each incident.

Practical response sequence

  • Contain and investigate: attempt message recall only if reliable; otherwise contact the unintended recipient to request deletion; preserve logs and evidence.
  • Risk assessment (four factors): type and volume of PHI; who received it; whether it was actually viewed or acquired; and mitigation in place (for example, confirmed deletion, contractual controls).
  • Determine breach status: if not low probability of compromise, treat as a breach of unsecured PHI.
  • Individual notice: provide written notice without unreasonable delay and no later than 60 days after discovery; include what happened, what PHI was involved, protective steps the individual can take, your mitigation, and contact details.
  • Regulatory notice: for breaches affecting 500 or more residents of a state/jurisdiction, notify HHS and prominent media without unreasonable delay and within 60 days; for fewer than 500, log and submit to HHS no later than 60 days after the end of the calendar year.
  • Business associate duties: BAs must notify you without unreasonable delay (and no later than 60 days) so you can meet your obligations; your BAA may require faster internal reporting.
  • State Privacy Regulations: follow the shortest applicable deadline and any additional content or attorney‑general notice requirements; HIPAA does not preempt stricter state Data Breach Notification laws.
  • Post‑incident hardening: update risk analysis, refine DLP and encryption rules, retrain staff, and document all corrective actions.

Conclusion

To meet HIPAA audit expectations when emailing spirometry curves, anchor your program in Privacy Rule permissibility for treatment, document your Security Rule controls—especially encryption and access management—minimize the data you send, maintain complete records and BAAs, and prepare for Data Breach Notification with a tested incident process. Doing these consistently will let you share needed clinical data with outside pulmonologists while protecting patient trust and complying with both HIPAA and relevant state requirements.

FAQs.

What are reasonable safeguards for emailing PHI?

Verify the recipient’s identity and address, keep PHI out of subject lines, force TLS or use a secure portal when TLS is unavailable, require MFA on mail accounts, and enable DLP to detect PHI and enforce encryption automatically. Log transmissions, restrict auto‑forwarding, encrypt endpoints at rest, and train staff on incident reporting and pre‑send checks.

For provider‑to‑provider emails sent for treatment, HIPAA does not require patient consent—yet you should use encryption or a documented, risk‑based alternative. If a patient prefers unencrypted email to themselves or a designated third party, you may honor the request after advising them of risks and documenting their preference; this does not excuse inadequate security for routine provider‑to‑provider exchanges.

How should breaches involving emailed PHI be reported?

Act quickly: contain and investigate, perform the four‑factor risk assessment, and if a breach of unsecured PHI is likely, notify affected individuals without unreasonable delay and within 60 days. Report to HHS within 60 days if 500+ individuals are affected (and notify media); for fewer than 500, submit to HHS no later than 60 days after the calendar year ends. Follow any stricter state Data Breach Notification timelines and content requirements.

What documentation is necessary for HIPAA email compliance?

Keep your risk analysis and risk management plan, policies and procedures for PHI Transmission Security, encryption settings and decisions, Business Associate Agreements, training records, email/audit logs, patient requests and authorizations, incident and breach assessments, and evidence of corrective actions. Retain HIPAA documentation for at least six years from creation or last effective date.

Share this article

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Related Articles