Email and PHI in a dental practice
The front desk will forward an x-ray. Plan for that sentence.
Journal · Academy · C·09 | Last reviewed: October 1, 2026 | 3 min read | By CyberDental Group LLC, Hialeah, Florida
Short answer: HIPAA does not ban email, but it requires safeguards. Use encrypted email for PHI, sign a BAA with the email provider, turn on MFA, block auto-forwarding to personal accounts, train staff to recognize phishing, and have a written policy for the moment the front desk forwards an x-ray. Patients can request unencrypted email after being warned of the risk.
At a glance
| HIPAA stance | Email allowed with reasonable and appropriate safeguards |
| Provider requirement | BAA with the email platform |
| Core controls | Encryption, MFA, DLP rules, auto-forward blocking, training |
| Patient preference | Individuals can opt for unencrypted email after being warned |
| Top threat | Phishing and business email compromise |
Can a dental practice use email for PHI?
Yes, with safeguards. HIPAA does not prohibit email; it requires reasonable and appropriate protections based on your risk analysis. The practical standard is encrypted transmission, an email platform covered by a BAA, strong authentication and a policy staff can actually follow.
What happens when the front desk forwards an x-ray?
It will happen. A referral needs a radiograph; an insurer asks for documentation; a patient requests records. The question is whether it happens through a safe path or an improvised one. A written policy should answer:
- Which channel is approved for sending PHI (encrypted email, patient portal, secure file transfer).
- Who may send records, and to whom.
- What to verify before sending: the right recipient, the minimum necessary information, the right patient.
- What to do after a mistake: a misdirected email is a potential incident to be reported internally immediately. See Florida data-breach notification for dental practices.
What controls should be in place?
- A BAA with the email provider, such as Microsoft or Google, with a plan configured for it. See Microsoft 365 for dental practices.
- MFA on every mailbox. See MFA for dental practices.
- Encryption for outbound PHI: enforced TLS between mail servers where available and message-level encryption for sensitive content.
- Data loss prevention (DLP) rules that flag or block patterns such as Social Security numbers and insurance IDs.
- Auto-forward blocking to external addresses, a favorite attacker tactic after compromising a mailbox.
- Advanced phishing protection and link/attachment scanning.
- Retention and audit logging, so incidents can be investigated.
What if a patient asks to receive records by regular email?
Under HHS guidance, an individual can choose to receive their own information by unencrypted email, provided the practice has warned them of the risk and they still prefer it. Document the request and the warning. The patient's choice does not relax your obligations for everything else.
What is the biggest email threat in a dental office?
Phishing and business email compromise. A convincing "invoice" or "shared document" leads to a stolen password, then a mailbox rule that forwards everything to an attacker. Staff training, MFA and EDR together address most of it. See What EDR does in an operatory.
What should the practice document?
The email policy, the approved channels, the BAA, training records, and any incident. Documentation is what turns "we do this" into "we can show we do this." See Risk analysis vs risk management.
Frequently asked questions
Is it HIPAA-compliant to email x-rays to another dentist?
It can be if sent through an approved, encrypted channel with appropriate safeguards and a BAA with the email provider, sending only the minimum necessary information to the right recipient.
Can patients receive PHI by regular email?
Yes, if the patient requests it after being informed of the risks of unencrypted email. Document the request.
What should we do if PHI was emailed to the wrong person?
Report it internally right away, attempt to recall or contain it, document what happened, and evaluate whether it is a reportable breach with qualified guidance.
Sources and further reading
Related in the Journal
- Microsoft 365 for dental practices
- MFA for dental practices
- Florida data-breach notification for dental practices
- The nephew-does-the-IT myth
About CyberDental
CyberDental Group LLC is a dental-exclusive managed IT and cybersecurity provider headquartered in Hialeah, Florida. Founded in 2016 by Mr. Dimitri Lopez, it supports 1,000+ licensed dental practices, has completed 250+ dental office IT build-outs, and operates a dental-only HelpDesk. Plans are priced per location: Remote $350/month, Priority $650/month, Ultimate $1,200/month; Concierge is quoted for multi-location groups and DSOs. CyberDental signs a Business Associate Agreement (BAA) with every practice it serves.
- HelpDesk: (954) 639-7049
- Email: support@cyberdental.co
- Address: 480 W 84th Street, Suite B106, Hialeah, FL 33014
- Website: cyberdentalgroup.com