Skip to main content
Can We Send That? Email Compliance Questions Your Team Is Already AskingRegulatory Framework
6 min readFor Business Associate Compliance Teams

Can We Send That? Email Compliance Questions Your Team Is Already Asking

Your marketing team wants to launch a patient engagement campaign. Your IT lead is worried about encryption. Your privacy officer is asking whether you need authorization. And someone from billing just forwarded a draft that mentions a discount on labs.

These questions land in compliance inboxes every week, and the answers aren't always straightforward. Email sits at the intersection of HIPAA's Privacy and Security Rules, the CAN-SPAM Act's commercial messaging requirements, and your organization's operational needs. Get it wrong, and you're looking at regulatory exposure, patient complaints, or both.

Below are the questions we hear most often from compliance teams managing email programs at covered entities and business associates.

Does a patient's general consent to receive emails satisfy both HIPAA and CAN-SPAM?

No. CAN-SPAM generally doesn't require advance consent for commercial email, but HIPAA may require a specific written authorization before PHI is used or disclosed for marketing. A general consent to treatment or a patient's failure to unsubscribe doesn't become a valid HIPAA marketing authorization.

Here's the distinction: CAN-SPAM governs the mechanics of commercial messaging (accurate headers, working unsubscribe links, physical postal address). HIPAA governs whether you're permitted to use or disclose PHI in the first place. A checkbox on your intake form saying "Yes, send me emails" might satisfy CAN-SPAM's implied consent framework, but it won't satisfy HIPAA's requirement for a specific, signed authorization that describes the marketing purpose and the PHI you'll use.

If your campaign uses PHI and qualifies as marketing under the Privacy Rule, you need a valid HIPAA authorization that's separate from your general consent forms. Document your determination for each campaign type and keep copies of signed authorizations on file.

Can an email comply with CAN-SPAM but still violate HIPAA?

Yes. Accurate sender information, a postal address, and an unsubscribe link don't give you permission to use PHI for marketing. You still need a HIPAA-permitted purpose or valid authorization, and you must apply appropriate privacy and security safeguards.

Consider a scenario where your vendor builds a perfectly formatted promotional email: clear subject line, working opt-out, physical address in the footer. It checks every CAN-SPAM box. But if that email uses patient names, diagnoses, or treatment history to promote a new service, and you don't have authorization, you've violated the Privacy Rule regardless of CAN-SPAM compliance.

The reverse is also true: an email can comply with HIPAA but still violate CAN-SPAM. HIPAA permission or authorization doesn't replace CAN-SPAM's requirements for commercial messages. Both frameworks apply when you're sending marketing emails that contain PHI.

What happens when an appointment reminder also advertises a discounted service?

CAN-SPAM examines the subject line, placement, and overall emphasis to determine whether the mixed message is primarily commercial. If the primary purpose is commercial, CAN-SPAM's requirements apply even if the message also includes transactional content.

The Federal Trade Commission looks at factors like what a reasonable recipient would interpret as the message's primary purpose. If your subject line reads "Your appointment on Thursday" but 80% of the email body promotes a discounted wellness package, the FTC may classify it as commercial. That triggers CAN-SPAM obligations: accurate headers, a clear opt-out mechanism, and your physical postal address.

From a HIPAA perspective, you also need to assess whether the promotional portion qualifies as marketing. Appointment reminders and treatment communications are generally permissible uses under the Privacy Rule. But if you're cross-selling an unrelated service, you may need authorization depending on how you're using PHI to target or personalize the offer.

Document your analysis. If the promotional content is incidental and doesn't use PHI for targeting, you may be able to treat the message as operational. If it's a true marketing campaign wrapped around a reminder, treat it as such and secure authorization.

Does a HIPAA marketing authorization replace the CAN-SPAM unsubscribe process?

No. CAN-SPAM opt-outs and HIPAA authorization revocations are separate rights governed by different requirements.

Under CAN-SPAM, recipients have the right to unsubscribe from commercial emails, and you must honor that request within ten business days. This applies even if the recipient previously consented or enrolled in a program. The opt-out mechanism must be clear, conspicuous, and functional for at least 30 days after sending.

Under HIPAA, individuals can revoke a marketing authorization at any time by submitting a written revocation. Once you receive it, you can't use or disclose PHI for that marketing purpose going forward. But revocation doesn't apply retroactively to disclosures you already made in reliance on the authorization.

Your email platform needs to support both processes. A CAN-SPAM unsubscribe removes the recipient from your commercial mailing list. A HIPAA revocation stops you from using their PHI for that marketing activity. They're not interchangeable, and honoring one doesn't satisfy the other.

How do we personalize emails without creating compliance risk?

Personalization requires correct information and thoughtful application of patient data. Double-check contact information, audience segments, and campaign rules before distributing communications.

Sending different preventive care information based on age or documented eligibility is a common personalization tactic. But if a patient is placed in the wrong segment, they may receive irrelevant information or be inadvertently exposed to sensitive information intended for another individual. In September 2025, St. John's Riverside Hospital became aware of potential unauthorized access to a limited number of employee email accounts affecting 2,238 individuals, a reminder that email security failures can expose PHI at scale.

Test your campaign logic before launch. Verify recipient email addresses against your system of record. Create a review process for campaigns that include PHI, especially those that use diagnosis codes, treatment history, or medication lists to personalize content. If your segmentation rules are complex, document them and have a second reviewer validate the logic.

Personalization also means respecting preferences. Patients should be allowed to update their communication preferences or unsubscribe from commercial messages. Honoring these requests demonstrates that your organization respects their time and autonomy.

Do we need to encrypt every email that mentions a patient?

It depends on whether the email contains PHI and whether you're transmitting it outside your organization's secure environment. The HIPAA Security Rule requires covered entities to implement technical safeguards to protect ePHI in transit, including encryption where appropriate.

If you're sending appointment reminders, test results, or care coordination messages that contain PHI to patients or other covered entities, encryption is the standard safeguard. TLS encryption ensures that the message remains protected while in transit. If your email platform doesn't support TLS or your recipient's system can't receive encrypted messages, you need an alternative like a secure patient portal.

Internal emails between workforce members within your organization's network may not require the same level of encryption if your network is already secured. But the moment PHI leaves your control, encryption should be your default.

Don't confuse encryption with authorization. Encrypting a marketing email doesn't give you permission to use PHI for marketing. It's a security safeguard, not a substitute for Privacy Rule compliance.

Where do we go from here?

Start by mapping your current email campaigns to HIPAA's use and disclosure framework. Identify which messages are treatment communications, which are operational, and which qualify as marketing. For marketing campaigns, determine whether you need authorization or whether an exception applies.

Then audit your CAN-SPAM compliance: accurate sender information, working unsubscribe links, and a physical postal address in every commercial message. Make sure your email vendor can support both HIPAA security requirements and CAN-SPAM's technical mandates.

Finally, document your determinations. When your marketing team proposes a new campaign, your compliance review should produce a written record: Does this use PHI? Is it marketing? Do we need authorization? Is it a commercial message under CAN-SPAM? That documentation protects you if OCR or the FTC comes asking questions later.

Email compliance isn't a one-time checklist. It's an ongoing process of reviewing campaigns, updating consent mechanisms, and training your teams on the rules that apply when healthcare meets digital marketing.

You Might Also Like