Patronum Logo
00%
Patronum Logo
menu-icon

HIPAA Email Disclaimer: Templates and How to Apply Them in Google Workspace

By Patronum

September 29, 2026

Read Time: 4 mins

A clinic manager adds a long HIPAA disclaimer to every staff signature and considers email compliance done. It isn’t. HIPAA does not require an email disclaimer at all. HHS requires “reasonable safeguards” when you email patients, and a brief risk warning when a patient asks to receive their health information by unencrypted email. A disclaimer is a useful extra layer, not the control itself.

This guide covers what HHS actually says, three templates you can adapt, and how to apply them consistently in Google Workspace. It isn’t legal advice, so check final wording with your compliance lead.

Does HIPAA require an email disclaimer?

No. The HHS FAQ on emailing patients says covered providers can communicate by email “provided they apply reasonable safeguards when doing so,” and that “the Privacy Rule does not prohibit the use of unencrypted e-mail for treatment-related communications” (HHS FAQ 570). The safeguards HHS gives as examples are practical ones, like “checking the e-mail address for accuracy before sending” and “limiting the amount or type of information disclosed.” A disclaimer isn’t on the list.

There is one situation where a warning is required. If a patient asks for a copy of their records by unencrypted email, the provider “must provide a brief warning to the individual that there is some level of risk” that their information could be read by someone else (HHS FAQ 2060). Once the patient has been warned and accepts the risk, HHS says the provider isn’t responsible for what happens in transit (HHS FAQ 2061).

On the technical side, the Security Rule requires measures to “guard against unauthorized access to electronic protected health information that is being transmitted,” with encryption listed as “addressable” (45 CFR 164.312(e)).

Why teams still use a disclaimer

A short notice does three useful things. It tells a wrong recipient what to do. It reminds patients that email carries some risk. And it keeps your wording consistent across every department. Just don’t let it stand in for the safeguards above.

3 HIPAA email disclaimer templates

1. Standard confidentiality notice (all external email)

This email may contain protected health information (PHI) that is confidential under federal law. It is intended only for the named recipient. If you received it in error, please notify the sender and delete it without copying or sharing it.

2. Patient communication notice

Email is not a secure way to share sensitive health information. Please don’t include detailed medical information in your reply. For urgent medical concerns, call [phone number] or 911.

3. Unencrypted records warning (use when a patient requests records by email)

You’ve asked to receive your health information by unencrypted email. Unencrypted email carries some risk that your information could be read by someone other than you. If you’d still like to receive it this way, please reply to confirm.

Template 3 is the one that maps to a specific HHS requirement. Send it as its own message and keep the patient’s confirmation on file, rather than burying it in a footer.

How to apply the disclaimer across Google Workspace

First, the prerequisite. Google states that “Customers who have not signed a BAA with Google must not use PHI in Google Workspace,” and that the BAA is accepted electronically in the Admin console (Google Workspace Admin Help). Gmail is on Google’s list of services covered by the BAA (Google Workspace HIPAA Included Functionality).

Then choose where the notice lives:

GoalBest toolWhy
A notice staff can’t removeGoogle Workspace Append footer (Admin console > Apps > Google Workspace > Gmail > Compliance)Users “can’t change or remove it,” and it applies per organizational unit
A consistent, branded signature with a short noticeA signature policy in PatronumOne policy per team, with names and titles pulled from the Google Directory
Encrypted delivery to specific partnersSecure transport (TLS) compliance settingMessages to listed domains “aren’t delivered, and will bounce” if TLS isn’t available

Sources: Append footer, TLS compliance, Patronum Help Center.

A few details matter here. By default, Gmail “always tries to send messages over a secure TLS connection,” but if the receiving server doesn’t support TLS, “Gmail still sends messages but the connection isn’t secure.” The TLS compliance setting closes that gap for the domains you choose. The Append footer only reaches external recipients by default, and it isn’t supported on messages encrypted with Client-side encryption (CSE).

One more point to be clear about. Google notes that third-party apps and add-ons “are not included in the Included Functionality covered by the BAA.” So use Patronum to manage signatures and branding, not as a place to handle PHI, and keep any must-not-be-removed notice in Google’s own Append footer.

Key takeaways

  • HIPAA doesn’t require an email disclaimer. It requires reasonable safeguards.
  • A brief risk warning is required when a patient asks for records by unencrypted email.
  • Sign Google’s BAA before any PHI touches Google Workspace.
  • Use Append footer for locked notices, TLS compliance for sensitive partners, and a managed signature for consistency.

FAQ

Is a HIPAA email disclaimer legally required? No. HHS requires reasonable safeguards for email and a brief warning when sending records by unencrypted email at a patient’s request. A disclaimer is good practice, not a requirement.

Can I email patients without encryption? HHS says the Privacy Rule “does not prohibit” unencrypted email for treatment communications, provided reasonable safeguards are in place. Patients can also ask to receive records by unencrypted email after being warned of the risk.

Where should a HIPAA disclaimer go? At the bottom of external email as a general notice. For record requests by unencrypted email, send the warning as a separate message and keep the patient’s confirmation.

Does Google Workspace support HIPAA compliance? Google offers a HIPAA Business Associate Agreement that covers services including Gmail. You still need to sign it and configure Google Workspace appropriately.

Keep every signature consistent

Healthcare teams often have dozens of departments and job titles to keep in line. Patronum’s email signature management lets you roll out one signature policy per team from the Google Directory, while Google’s Append footer handles the notice nobody should remove. See also our email disclaimer templates for business.

Sources

  • HHS, FAQ 570, email with patients: https://www.hhs.gov/hipaa/for-professionals/faq/570/does-hipaa-permit-health-care-providers-to-use-email-to-discuss-health-issues-with-patients/index.html
  • HHS, FAQ 2060, right to unencrypted email: https://www.hhs.gov/hipaa/for-professionals/faq/2060/do-individuals-have-the-right-under-hipaa-to-have/index.html
  • HHS, FAQ 2061, responsibility after warning: https://www.hhs.gov/hipaa/for-professionals/faq/2061/is-a-covered-entity-responsible-if-it-complies/index.html
  • eCFR, 45 CFR 164.312: https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.312
  • Google Workspace Admin Help, HIPAA compliance: https://knowledge.workspace.google.com/admin/compliance/hipaa-compliance-with-google-workspace-and-cloud-identity
  • Google Workspace, HIPAA Included Functionality: https://workspace.google.com/terms/2015/1/hipaa_functionality/
  • Google Workspace Admin Help, Append footer: https://knowledge.workspace.google.com/admin/gmail/advanced/add-a-standard-footer-to-outgoing-emails
  • Google Workspace Admin Help, TLS: https://knowledge.workspace.google.com/admin/gmail/advanced/send-email-over-a-secure-tls-connection
  • Patronum Help Center, manage multiple Gmail signatures: https://help.patronum.io/en/article/manage-multiple-gmail-signatures-8bua8j/