Last updated: 9 January 2023
Email is a critical business service for any healthcare organization. But given the sensitive medical information involved, federal privacy laws like HIPAA mean there are special requirements for any health IT system.
Security threats can come from outside as well as from within, via hackers or employees, so the best email system combines HIPAA compliant email with the ability to integrate and automate email messages via an API (application programming interface). There are many email API providers, and Mailgun is one of the most popular.
But is Mailgun HIPAA compliant?
Mailgun was launched in 2010 as an API-based email delivery service, allowing companies to build email into their existing applications rather than building an email system from scratch.
With a decade of experience in the email and API space, the San Antonio-based firm has offerings that run the gamut from user-friendly email templates and analytics to more technical tools like email and IP reputation tracking and mass email services.
Today, Mailgun and its 200 global employees provide email solutions for many household names, including Microsoft, Johnson & Johnson, Etsy, Lyft, and Github.
Mailgun has a HIPAA Business Associate Addendum, which reveals that Mailgun can serve as a business associate for covered entities like healthcare providers, health plans, and healthcare clearinghouses.
However, section 2D states:
There appears to be some legal aikido at work here. On the one hand, Mailgun is correct in that as a business associate, they must notify customers when impermissible disclosure of protect health information (PHI) occurs. Yet on the other, they readily admit that by using their service, customers may very well be exposing PHI by transmitting plain text email in an unsecured fashion. In addition, they make no attempt to monitor whether this happens or not.
Another are of acute concern when it comes to HIPAA compliance is section 5.3:
If HIPAA compliance is a requirement for your organization, this is not a reassuring message.
On the one hand, Mailgun will enter into a BAA with healthcare organizations. On the other hand, if you read the fine print, the BAA does not cover much as it relates to Mailgun's ability to provide HIPAA compliant email.
SEE ALSO: Hacking and Human Error: Two Enemies of HIPAA Compliance
Mailgun is technically HIPAA compliant because it will sign a BAA, but it leaves all of the heavy lifting on the customer, from determining how to limit the information sent via its service, to ensuring email encryption, to providing recipients adequate disclaimers.
Email encryption is the preferred method for securing electronic protected health information (ePHI) to maintain HIPAA compliance.
Paubox Email API encrypts every email by default, so unlike Mailgun users, our customers don't have to limit what information they share with patients. And with our patented technology, our solution ensures HIPAA compliance even when an email recipient doesn't support encryption.
SEE ALSO: Why Healthcare Businesses Choose the Paubox Email API
With our HITRUST CSF certified product, patients receive encrypted emails directly to their inboxes—no passwords or portals required. Easy to implement with clear documentation, a developer’s experience is as seamless as the email recipient’s.