If you're taking HIPAA compliance training and searching for answers, you're in the right place. This guide answers the most common HIPAA email encryption test questions โ and explains what your training probably didn't tell you about choosing a secure email service.
โ YES โ True. Encrypting sensitive information IS an example of a technical safeguard under HIPAA.
If your HIPAA training test asks "encrypting sensitive information is an example of a technical safeguard" โ the answer is TRUE.
HIPAA divides security requirements into three categories:
| Category | What It Covers | Example |
|---|---|---|
| Administrative Safeguards | Policies and procedures | Security training, risk assessments |
| Physical Safeguards | Physical access to data | Locked server rooms, workstation security |
| Technical Safeguards | Technology that protects data | Encryption, access controls, audit logs |
Encryption falls under Technical Safeguards (specifically 45 CFR ยง 164.312). It's the technology that converts readable data into unreadable code that can only be unlocked with the right key. HIPAA requires covered entities to implement encryption โ or document why they chose not to.
You need to encrypt an email containing PHI whenever it's transmitted electronically outside your organization's internal network.
If your HIPAA test asks "you need to encrypt an email containing phi" โ the key distinction is between internal and external transmission.
PHI (Protected Health Information) is any health data that can be tied to an individual โ names, dates of birth, medical record numbers, treatment information, and 15 other identifiers defined by HIPAA.
Under the HIPAA Security Rule:
Simply put: if PHI leaves your organization's network, it must be encrypted in transit.
Emails containing patient information sent to outside agencies must be encrypted in transit, include only the minimum necessary information, and be covered by a Business Associate Agreement (BAA) with the receiving organization.
If your test asks "emails containing patient information sent to outside agencies should" โ there are three requirements:
If a breach occurs and patient information is exposed, HIPAA requires notification to affected patients within 60 days โ and to the Department of Health and Human Services within 60 days for breaches affecting fewer than 500 people, or immediately for larger breaches.
Not all encrypted email services are HIPAA-compatible. For an email service to be used for PHI, it must offer a Business Associate Agreement and support encryption that meets HIPAA standards. Here are the top options:
Proton Mail uses zero-access encryption โ emails are encrypted on your device and even Proton can't read them. Proton offers a BAA on its business and enterprise plans, making it HIPAA-compatible for healthcare organizations. Because Proton is based in Switzerland with all data stored on Swiss servers, PHI benefits from both HIPAA protections and Swiss privacy law โ a combination no US-based provider can match.
Proton Mail offers end-to-end encryption with BAA support on business plans.
Explore Proton for Business โWe may earn a commission if you upgrade to a paid plan.
PBHS Secure Email is a HIPAA-compliant secure email service purpose-built for dental practices. At $13/month, it's designed for dental offices that need to share PHI with labs, specialists, and patients without worrying about compliance.
PBHS Secure Email works from any browser โ no software to install โ and includes features like encrypted attachments and read receipts. The ADA (American Dental Association) partnership often waives setup fees for members.
If you're a dental practice looking for a simple, compliance-first email solution, PBHS is worth considering. But if you want a full encrypted productivity suite โ email, calendar, cloud storage, and VPN โ Proton Mail's business plans offer more capability for a comparable price.
Hushmail offers HIPAA-compatible plans with a signed BAA, built-in secure web forms for collecting patient information, and encrypted messaging. Starting at $5.99/month, it's a solid option for solo practitioners and small clinics. However, Hushmail is not open source and lacks the full ecosystem of tools that Proton provides.
Common HIPAA test questions โ quick answers:
| Encrypting sensitive information is an example of a technical safeguard? | TRUE โ |
| You need to encrypt an email containing PHI when? | When sent outside your organization |
| Emails containing patient information sent to outside agencies should? | Be encrypted, minimum necessary, BAA in place |
| What makes an email service HIPAA-compliant? | BAA + encryption that meets HIPAA standards |
| Breach notification timeline? | 60 days to patients, immediate for 500+ |
HIPAA email compliance comes down to three things: encrypt your emails, work with providers who sign a BAA, and share only the minimum information necessary. Chances are your HIPAA training test is asking exactly these questions โ and now you have the answers.
For healthcare workers who also value personal privacy โ or for organizations wanting an encrypted email provider that meets HIPAA standards while offering more than just compliance โ Proton encrypted email is the strongest option available.
Proton Mail โ end-to-end encrypted, Swiss privacy, BAA available on business plans.
Try Proton Mail Free โWe may earn a commission if you upgrade to a paid plan.