HIPAA Obligations for Freestanding Imaging Centers When Emailing Results to Patients

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

HIPAA Obligations for Freestanding Imaging Centers When Emailing Results to Patients

Kevin Henry

HIPAA

August 22, 2026

9 minutes read
Share this article
HIPAA Obligations for Freestanding Imaging Centers When Emailing Results to Patients

HIPAA Email Communication Guidelines

As a freestanding imaging center, you may email imaging results to patients if you apply reasonable safeguards to protect Protected Health Information (PHI). HIPAA permits email as a communication channel, provided you evaluate risks, implement appropriate controls, and document your decisions under the HIPAA Security Rule. Your policies should explain when email is appropriate, how you verify patient identity, and how you handle unencrypted requests.

Encryption Requirements under the Security Rule are “addressable,” not automatically mandatory. That means you must assess whether encryption is reasonable and appropriate for Secure Email Transmission in your environment. If you adopt encryption, define how and when it is enforced. If you do not, document a risk analysis, implement equivalent alternative measures, and justify why encryption is not reasonable—keeping in mind that encryption in transit (for example via TLS or S/MIME) is the industry baseline for safeguarding ePHI.

Before sending results, confirm the patient’s preferred email address, avoid PHI in the subject line, and consider using secure attachments (for example, password-protected PDFs) or a secure message portal for high‑sensitivity results. Train your workforce to recognize phishing, verify addresses, and follow downtime or fallback procedures if secure services are unavailable.

Implementing Reasonable Safeguards

Administrative safeguards

  • Conduct and document a risk analysis for emailing results, covering threats like misaddressed mail, account compromise, and mobile access.
  • Publish clear procedures for verifying patient identity, validating email addresses, and responding to patient requests for unencrypted delivery.
  • Execute and maintain Business Associate Agreements with any vendor that creates, receives, maintains, or transmits PHI, including email, portal, and cloud storage providers.
  • Deliver role‑based training that explains Secure Email Transmission practices, breach reporting, and sanctions for violations.
  • Perform periodic audits—spot check sent emails, review logs, and test address verification steps.

Technical safeguards

  • Use transport encryption (TLS) at a minimum; implement end‑to‑end options such as S/MIME or PGP for results with higher sensitivity or for high‑risk scenarios.
  • Enable multifactor authentication for email and portals; enforce strong passwords and device encryption for endpoints that access PHI.
  • Deploy data loss prevention (DLP) rules to flag PHI in subject lines, block external sends to unverified addresses, and require encryption for attachments containing PHI.
  • Harden administrator access, monitor for anomalous logins, and retain audit logs consistent with your HIPAA Security Rule documentation.

Physical and process controls

  • Adopt a “pause and verify” step before sending, including double‑checking recipient addresses and attachments.
  • Minimize visible PHI: no PHI in subject lines, use neutral filenames (for example, “Your Results.pdf” rather than “MRI_Brain_John_Doe_08-15-2026.pdf”).
  • Separate cover messages from attachments; if possible, require a one‑time passcode or password exchange delivered via a different channel (text/phone).
  • Maintain a tested process for misdirected emails, including prompt breach risk assessment and patient notification if required.

Patients have a right to receive copies of their records, including imaging results, by email if the format is readily producible. You generally do not need a Patient Authorization to email results directly to the patient under this right of access. An authorization may be required for disclosures outside treatment, payment, and health care operations when not directed by the patient. If a patient asks you to email results to a third party, follow your right‑of‑access procedure for patient‑directed disclosures and document the request.

Unencrypted email preference

  • Advise the patient of the risks of unencrypted transmission (for example, possible interception or unauthorized access on shared devices).
  • Confirm the patient still prefers unencrypted delivery and verify the exact email address to use.
  • Document the patient’s preference (date, time, what you explained, the address confirmed). Written acknowledgment is best practice, though documented verbal confirmation is acceptable if your policy allows.
  • Allow the patient to revoke or change their preference at any time and record the update in your EHR or communication system.

Practical documentation tips

  • Use a standardized form or EHR template to capture the risks explained, the patient’s choice, and the verified address.
  • Note any special handling (for example, split reports, password‑protected attachments) and confirm delivery or bounce handling.

HIPAA sets a federal floor, but you must also follow state laws that are more protective of privacy. Some states impose tighter rules for specific categories—such as mental health, HIV/STI, genetic information, or reproductive health—affecting how and to whom you can email results. When state law is more stringent than HIPAA, you apply the state standard.

Create and maintain a state‑law matrix that maps sensitive result types to additional consent or segregation requirements, including any special notice or authorization language. Train staff to route sensitive categories through enhanced workflows (for example, encryption required, portal‑only delivery unless the patient insists on email, or additional identity verification). Coordinate with counsel to keep this matrix updated and to align your procedures with multi‑state operations.

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Ensuring Patient Access Rights

Format, timeliness, and accessibility

You must provide results in the format the patient requests if readily producible—email is typically feasible. If you cannot produce the exact format, offer a reasonably similar alternative and explain why. Respond within the HIPAA‑required timeframe and avoid unnecessary barriers, such as forcing portal enrollment when the patient asks for email.

Verify identity using your standard intake or call‑back procedure before releasing results. If the patient requests an accessible format (for example, large print or plain‑language summaries), accommodate reasonable requests and document how you met the need.

Fees and scope

Any fee for electronic copies must be reasonable and cost‑based. For emailed results, costs are usually limited to labor for retrieval and preparing the message or attachment. If a patient requests broader records (for example, the designated record set), clarify scope and deliver only what was requested unless the patient asks for more.

Third‑party directives

If a patient directs you to send results to someone else (for example, a family member or a personal app), capture the request in writing, including the recipient and destination address. Apply safeguards, verify details, and document completion.

Using Secure Platforms

Choosing the right channel

Default to secure options for routine delivery, such as a patient portal or encrypted email, then honor patient choices. Portals reduce risk by keeping PHI off open networks and provide audit trails, while Secure Email Transmission supports patients who prefer inbox delivery. Offer both, explain trade‑offs, and record the patient’s selection.

Vendor management and Business Associate Agreements

  • Use reputable email, portal, and cloud vendors willing to sign Business Associate Agreements and support your compliance needs.
  • Validate Encryption Requirements: encryption at rest and in transit, key management practices, logging, data residency, and incident response commitments.
  • Review service configurations—enable TLS enforcement, disable legacy protocols, and use domain‑based message authentication (SPF, DKIM, DMARC) to reduce spoofing.

Operational reliability

  • Implement bounce handling and undeliverable workflows to prevent silent failures and prompt follow‑up with the patient.
  • Maintain versioning and retention for reports; track what was sent, to whom, and when, to support audits and patient inquiries.
  • Test disaster recovery for your secure platforms so you can continue timely patient access during outages.

Applying Minimum Necessary Standard

Know when it applies—and when it does not

The Minimum Necessary Standard applies to many uses, disclosures, and requests for PHI—but not to disclosures to the individual patient under the right of access. When you email results directly to the patient (or to a third party at the patient’s direction under the access right), minimum necessary does not limit the content the patient is entitled to receive. Still, practice data minimization to reduce risk.

Practical data‑minimization steps

  • Share only what the patient requested (for example, the finalized radiology report and key images), not unrelated prior encounters.
  • Keep PHI out of subject lines and filenames; avoid including identifiers that are not necessary for the patient’s purpose.
  • Redact internal routing notes or quality control comments that are not part of the requested record, unless the patient specifically asks for them and they are within the designated record set.
  • When emailing other parties for payment or operations, apply Minimum Necessary by tailoring the data set to the task.

Conclusion

To meet HIPAA obligations when emailing imaging results, build your program on three pillars: honor the patient’s access rights, apply reasonable safeguards aligned with the HIPAA Security Rule, and operationalize choices through secure platforms and Business Associate Agreements. Default to encryption, document exceptions when patients prefer unencrypted delivery, and consistently apply Minimum Necessary where it applies. With clear procedures and training, you can deliver timely results while protecting privacy.

FAQs

What safeguards are required when emailing imaging results to patients?

Use layered safeguards: verify identity and the exact email address, avoid PHI in subject lines, and send results via encrypted channels (for example, TLS with optional S/MIME). Add administrative controls—documented policies, workforce training, and audits—and technical measures like MFA, device encryption, and DLP. Keep a misdirected‑email response plan and log what you send.

Explain the risks of unencrypted transmission in clear terms, confirm the patient still prefers unencrypted delivery, and verify the destination address. Record the patient’s acknowledgment (ideally in writing) in your EHR or a standardized form. Note that this preference can be changed or revoked at any time, and update your records accordingly.

Are there specific state regulations affecting email transmission of imaging results?

Yes. States may impose stricter privacy rules, especially for sensitive categories such as mental health, HIV/STI, genetic, or reproductive health information. When state law is more protective than HIPAA, follow the state standard. Maintain a state‑law matrix, build enhanced workflows (for example, encryption‑required), and train staff on state‑specific requirements.

What are the risks of sending PHI via unencrypted email?

Unencrypted email can be intercepted, accessed on unsecured devices, or exposed if a mailbox is compromised or an address is mistyped. These risks increase with sensitive results or shared devices. If a patient prefers unencrypted delivery after you explain these risks, document the preference and still apply safeguards like neutral subject lines and verified addresses.

Share this article

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Related Articles