Glossary

HIPAA

HIPAA

HIPAA is a U.S. federal law enacted in 1996 that governs how protected health information (PHI) is stored, accessed, and transmitted. It applies to healthcare providers, insurers, and any business handling PHI on their behalf (called business associates). 

For email senders, HIPAA compliance means: 

  • You cannot include PHI in email unless the message is encrypted end-to-end 
  • You may need a Business Associate Agreement (BAA) with your email provider 
  • Logs, storage, and handling of email data must follow HIPAA security rules 
  • Marketing emails related to healthcare may require explicit patient consent 

Mailgun is not HIPAA-compliant by default. Senders who need to handle PHI should consult legal counsel before using any ESP – and should not use Mailgun to transmit or store PHI without a signed BAA. 

Create beautiful, responsive emails in minutes.

Email made easy.