HIPAA Training for PFT Lab Respiratory Therapists: How to Email Spirometry Curves Externally, Securely and Compliantly

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

HIPAA Training for PFT Lab Respiratory Therapists: How to Email Spirometry Curves Externally, Securely and Compliantly

Kevin Henry

HIPAA

August 23, 2026

6 minutes read
Share this article
HIPAA Training for PFT Lab Respiratory Therapists: How to Email Spirometry Curves Externally, Securely and Compliantly

HIPAA Email Compliance Requirements

Email can be used to share spirometry curves when you treat it as Protected Health Information (PHI) and apply reasonable and appropriate safeguards. Flow-volume loops, numeric spirometry values, interpretations, dates of service, and patient identifiers are all PHI once they can be linked to an individual.

Follow the Minimum Necessary Standard: send only the data the recipient needs. If a referring provider requires a flow-volume loop and FEV1/FVC, avoid sending entire PFT batteries, screenshots with demographic banners, or raw device exports unless clinically necessary.

Complete and document Risk Assessments that cover email transmission, mobile access, and attachment handling. Define policies for PHI-free subject lines, standardized disclaimers that exclude PHI, retention periods, and incident reporting. Verify that any external recipient can receive your message securely before you send.

Use a pre-send checklist: confirm recipient identity, validate destination address, remove excess identifiers from images, encrypt in transit and at rest, separate the password from the message if using file-level encryption, and record the transmission in your audit trail.

Encryption Methods for Emailing PHI

Encrypt in transit using modern Transport Layer Security (TLS) and enforce it for external domains when possible. If a recipient’s server cannot negotiate strong TLS, switch to a secure message portal or an alternative encrypted delivery method rather than downgrading to plaintext.

When you need End-to-End Encryption, use standards such as S/MIME or OpenPGP so only the intended recipient can decrypt the message. For recipients without E2EE, a secure portal with multi-factor authentication (MFA) or an expiring, access-controlled secure link provides comparable protection and auditability.

File-level encryption is effective for attachments like spirometry PDFs or CSV files. Protect attachments with AES-256 encryption, share the passphrase via a separate channel (phone call or text), and avoid PHI in file names. Ensure devices used to send PHI have full-disk encryption enabled.

Practical workflow for spirometry curves: export the curve as a PDF from the PFT system; crop or redact unnecessary identifiers; apply the Minimum Necessary Standard; choose the strongest delivery option the recipient supports (E2EE or secure portal); verify the recipient’s address; send the password separately if using file encryption; document the send for Audit Logging.

Business Associate Agreements with Email Providers

A Business Associate Agreement (BAA) is required with any vendor that creates, receives, maintains, or transmits PHI on your behalf. If your email service stores mail, scans content, archives messages, or provides a secure portal, it is a business associate and must sign a BAA before you send PHI.

Review BAAs for breach notification timelines, permitted uses, subcontractor obligations, encryption commitments, audit rights, and termination procedures that ensure PHI is returned or destroyed. Remember that a BAA enables compliant use but does not replace your own safeguards or staff training.

Do not use consumer email services or plug-ins that will not sign a BAA. If multiple vendors touch a message—filtering, DLP, archiving—each must be covered by a BAA.

Implementing Access Controls and Audit Logs

Apply Access Controls that enforce least privilege. Issue unique user IDs, require strong authentication (preferably MFA), and restrict who can email externally or attach PHI. Use role-based permissions so only authorized staff can export spirometry data from the PFT system.

Enable Data Loss Prevention (DLP) rules to flag or block messages containing PHI patterns when sent outside approved domains. Require device encryption, screen locks, and mobile device management for any phone or tablet used to access email with PHI.

Turn on Audit Logging across your email platform and secure portal. Capture sender, recipient, timestamps, delivery status, encryption method, and any policy overrides. Retain logs according to your organization’s records policy to support investigations, quality checks, and legal holds.

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Staff Training on Email Security

Provide role-specific training for respiratory therapists that covers recognizing PHI in spirometry curves, the Minimum Necessary Standard, and when to use encrypted email versus a secure portal. Emphasize PHI-free subject lines, correct attachment handling, and verifying recipient identity before sending.

Rehearse a simple sending checklist: confirm clinical need; de-identify or limit data; select encryption method; verify address; send password separately if used; document in the record; and monitor for delivery/receipt. Include phishing awareness, reporting procedures for misdirected emails, and periodic competency refreshers.

For provider-to-provider sharing related to treatment, HIPAA generally permits disclosure without patient authorization when safeguards are in place. For provider-to-patient email, inform patients of risks, honor their preferred communication channel, and document consent or acknowledgment—especially if sending to an unencrypted personal inbox.

Record consent in the EHR, including the patient’s chosen address, what types of information may be emailed, and any restrictions. Use secure portals by default when feasible, and apply the Minimum Necessary Standard regardless of the consent pathway.

Selecting HIPAA-Compliant Email Services

Choose services that will execute a BAA and provide robust security features: enforced TLS, optional End-to-End Encryption, secure portals with MFA, at-rest encryption, Access Controls, DLP, and comprehensive Audit Logging. Look for message expiration, recall options, legal hold, retention controls, and reporting that proves policy compliance.

Prioritize administrative tools that make the secure choice the easy choice: automatic TLS enforcement for trusted partners, policy-based encryption triggers for PHI, blocked external forwarding, and alerts on misaddressed messages. Validate capabilities during a pilot, document Risk Assessments, train staff, then monitor and tune policies after go-live.

In summary, you can email spirometry curves securely by applying the Minimum Necessary Standard, encrypting in transit and at rest, executing BAAs with your vendors, enforcing Access Controls with strong Audit Logging, training staff on a clear send workflow, documenting patient consent where appropriate, and selecting services designed for HIPAA compliance.

FAQs.

What encryption standards are required for emailing spirometry data?

HIPAA is technology-neutral, but you should use strong, widely accepted standards. Enforce TLS 1.2 or higher for transport; use End-to-End Encryption with S/MIME or OpenPGP when feasible; and protect attachments with AES-256. Prefer FIPS-validated cryptographic modules and require MFA for portal access.

How do Business Associate Agreements affect email use?

A BAA contractually binds your email and security vendors to safeguard PHI, notify you of breaches, limit permitted uses, and manage subcontractors. Without a BAA, you should not transmit PHI through that vendor. A BAA complements—rather than replaces—your own policies, training, and technical controls.

What training should respiratory therapists receive for HIPAA compliance?

Training should cover identifying PHI in spirometry outputs, applying the Minimum Necessary Standard, selecting the right encryption method, PHI-free subject lines and file names, verifying recipients, sending passwords via a separate channel, documenting transmissions for Audit Logging, phishing awareness, and incident reporting.

For treatment-related provider-to-provider sharing, HIPAA generally allows disclosure without patient authorization when safeguards are in place. For emailing patients directly—especially to personal, potentially unencrypted inboxes—obtain and document their preference or consent and use secure alternatives when appropriate.

Share this article

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Related Articles