Comparison
The first question is not which provider is best. It is which providers will accept Protected Health Information at all - because two of the largest transactional email services explicitly forbid it in their terms. Every position is sourced from the vendor's own documentation and linked.
Last reviewed July 2026
The short version
Providers in this category do not sit on a spectrum. They fall into three groups, and which group a provider is in matters more than any feature comparison within a group.
SendGrid states it is not a HIPAA Eligible Service and that Covered Entities agree not to use it for any purpose involving PHI. Postmark states it is not HIPAA compliant and cannot sign a BAA. These are prohibitions, not gaps - using them for PHI is a contract breach as well as a compliance problem.
Both are built for healthcare, both are HITRUST certified, both include a BAA. Paubox emphasizes blanket TLS with no recipient portal; LuxSci offers per-recipient adaptive encryption with portal, PGP and S/MIME fallback. Both are US-based with no EU data residency option published.
Mailgun publishes a HIPAA Business Associate Addendum but requires prior written consent and a separate agreement before you transmit PHI. Omnivery signs BAAs as standard onboarding and publishes an independently issued HIPAA certificate alongside seven ISO certifications.
The matrix
The first row decides most shortlists: a provider that will not accept PHI is not a cheaper option, it is not an option.
| Omnivery | Paubox | LuxSci | Mailgun | SendGrid | Postmark | |
|---|---|---|---|---|---|---|
| Will accept PHI | Yes | Yes | Yes | Yes, with prior written consent | No - expressly prohibited | No |
| Signs a BAA | Yes, standard at onboarding | Yes, included on all plans | Yes | Yes, separate agreement required | No, not for email | No, cannot sign one |
| HIPAA evidence published | Independent HIPAA certificate, No. 2510225512 | HITRUST certified, third-party audited | HITRUST CSF r2 certified, SOC 2 | Self-stated HIPAA, SOC 1 & 2 | Not applicable | Not applicable |
| ISO/IEC 27701 (privacy) | Yes | Not published | Not published | Not published | Not published | Not published |
| EU data residency | Yes, customer choice, EU or US | Not published - US data centers | Not published | EU region available | EU region on higher tiers | Not published |
| Contracting entity jurisdiction | Czech Republic (EU) | United States | United States | Sweden (Sinch AB), US subsidiary operates part | United States (Twilio) | United States (ActiveCampaign) |
| Stores message content | No, never | Not published | Yes, archiving offered | Yes | Yes | Yes |
| Runs on own infrastructure | Yes, no hyperscaler in the delivery path | Not published | Not published | No, public cloud | No, AWS | No, public cloud |
| REST API and SMTP relay | Both, at full parity | Both | Both | Both | Both | Both |
| Recipient needs a portal or password | No | No | Only where adaptive encryption falls back to a portal | No | Not applicable | Not applicable |
Sources: Omnivery HIPAA certificate No. 2510225512 (22 October 2025) and ISO certificate pack, both published at /about/certifications. Paubox pricing and Email API pages, paubox.com. LuxSci HIPAA compliant email and email API pages, luxsci.com. Mailgun HIPAA Business Associate Addendum, mailgun.com/legal/hipaa-baa, and Mailgun Help Center Compliance & Security. Twilio SendGrid "Is SendGrid HIPAA Compliant?", twilio.com/docs/sendgrid. Postmark "Is Postmark HIPAA Compliant?", postmarkapp.com/support. Cells marked "Not published" mean the vendor does not state a position in its public documentation, not that the answer is no. Verify against current vendor documentation before relying on any row.
HIPAA is United States legislation, not a certification scheme with a registry. No government body issues a HIPAA certificate to anyone. That is why the phrase "HIPAA compliant" appears on so many vendor pages with nothing behind it - the term is unpoliced. What a reviewer can actually assess is narrower: does the vendor sign a BAA, and has anyone independent examined its safeguards?
Under HIPAA, a Covered Entity may only disclose PHI to a Business Associate under a Business Associate Agreement. Without one, the disclosure itself is the violation, regardless of how well encrypted the mail was. So "will they sign a BAA" is the question that decides whether a provider is usable, and "how good is their encryption" is a question you only get to ask afterwards.
Note the difference between including a BAA and permitting one. Paubox includes a BAA with every account including its free tier. Omnivery signs one as part of standard onboarding. Mailgun publishes a HIPAA Business Associate Addendum but requires its prior written consent and a separate agreement before PHI may be transmitted, which is a procurement step to plan for rather than a checkbox.
Both healthcare specialists hold it. HITRUST CSF is an audited framework that maps HIPAA's requirements onto specific controls, so a HITRUST certificate is evidence that someone tested the controls rather than that the vendor read the statute. Omnivery does not hold HITRUST. Its equivalent evidence is an independent HIPAA assessment certificate plus ISO/IEC 27701 for privacy information management, which no other provider in this comparison publishes.
HIPAA does not require US data residency, and it does not prohibit processing outside the US. For an organization subject only to HIPAA this is not a factor. It becomes decisive for anyone subject to both HIPAA and GDPR - a US health system with EU patients, an EU digital health company serving US customers - because the two healthcare specialists here are US-incorporated with no published EU residency option, and a US-incorporated processor brings the CLOUD Act into an EU controller's assessment. That is the situation Omnivery is built for, and it is the only reason to prefer it over Paubox or LuxSci on compliance grounds alone.
Choose Paubox if you are a US healthcare organization whose main need is that staff can send email to patients without either side thinking about encryption. Blanket TLS with no recipient portal is the whole product, HITRUST is audited, and the BAA is included on every plan.
Choose LuxSci if you need encryption to degrade gracefully rather than fail - per-recipient adaptive encryption across TLS, portal fallback, PGP and S/MIME means a recipient whose mail server will not negotiate TLS still receives the message securely. It also offers archiving, which matters if your retention obligation sits with the mail itself. Omnivery signs outbound mail with S/MIME but does not encrypt message bodies to recipient keys, so where the requirement is genuinely that encryption degrade rather than fail, LuxSci remains the answer.
Choose Mailgun if you are already on it, your volume is large, and you can get the prior written consent and separate PHI agreement through your procurement process.
Choose Omnivery in one specific situation: when HIPAA is not your only regime. If you are also subject to GDPR, the contracting entity's jurisdiction stops being a detail. Omnivery's processing entity is Czech, so for an EU controller the relationship is EU to EU with no third-country transfer to legitimize and no adequacy framework to depend on. Alongside that: an independently issued HIPAA certificate published for download, ISO/IEC 27701 for privacy information management, message content never stored at all, delivery metadata capped at 30 days, EU or US data residency as a customer choice, and delivery on infrastructure Omnivery owns with no hyperscaler in the path.
Do not choose SendGrid or Postmark for PHI. This is not a recommendation against them generally - both are competent transactional email services. It is that SendGrid's terms require Covered Entities to agree not to use the service for PHI, and Postmark states it cannot sign a BAA. Sending PHI through either is a breach of their terms in addition to a HIPAA problem.
How the SMTP relay serves legacy clinical systems is covered on HIPAA compliant email. Every certificate is listed with its number and expiry at certifications.
At a glance
Questions
No. Twilio's documentation states that SendGrid is not a HIPAA Eligible Service and does not natively support HIPAA compliant data transmission, offering no encryption or security measures beyond those in the SMTP RFC. Its terms go further: if you are a Covered Entity or Business Associate, you agree not to use the service for any purpose involving Protected Health Information. Twilio does sign BAAs for other products - Programmable Voice, Elastic SIP Trunking, Programmable SMS and Message Scheduling - on Security or Enterprise Edition, but SendGrid email is not among them.
No. Postmark states that it is not HIPAA compliant, that it does not recommend using its platform for HIPAA compliant email, and that it cannot sign any Business Associate Agreements around HIPAA. Since a BAA is a precondition for disclosing PHI to a service provider, that makes Postmark unusable for PHI regardless of any other consideration.
Yes, with a procurement step. Mailgun publishes a HIPAA Business Associate Addendum defining each party's responsibilities for PHI, and states that it maintains HIPAA, SOC 1 and 2, and GDPR compliance. However, customers must obtain Mailgun's prior written consent and enter into a separate agreement before transmitting PHI or other sensitive personal data, so this is not a self-serve arrangement.
It depends on which regimes apply to you. For a US healthcare organization whose priority is that staff can email patients without either side handling encryption, Paubox is purpose-built for exactly that and is HITRUST certified. Where encryption needs to degrade gracefully to a portal, PGP or S/MIME per recipient, LuxSci covers that and is also HITRUST certified - Omnivery signs outbound mail with S/MIME but does not encrypt bodies to recipient keys, so that specific requirement points to LuxSci. Where HIPAA is not the only regime - an organization subject to GDPR as well - the contracting entity's jurisdiction becomes decisive, and Omnivery is the only provider here incorporated in the EU.
No. Paubox and LuxSci do, and for a US-only healthcare buyer that is a meaningful advantage to them. Omnivery's equivalent evidence is an independently issued HIPAA compliance certificate, No. 2510225512 dated 22 October 2025, published for download, alongside seven ISO certifications including ISO/IEC 27701 for privacy information management, which no other provider in this comparison publishes.
No. HIPAA sets requirements for safeguarding PHI but does not mandate US data residency or prohibit processing outside the US. If HIPAA is the only regime that applies to you, processing location is not a compliance factor. It becomes important when GDPR also applies, because a US-incorporated processor brings the US CLOUD Act into an EU controller's transfer assessment, and both healthcare specialists in this comparison are US-incorporated with no published EU residency option.
Not with Paubox, Mailgun or Omnivery, all of which deliver to the inbox directly. LuxSci uses per-recipient adaptive encryption, so a recipient whose mail server will not negotiate TLS may receive a portal link instead, which is a deliberate trade of convenience for guaranteed encryption rather than a limitation.
If both regimes apply to your sending, the certificate and the sub-processor list are published rather than supplied on request. Forward them to your reviewer as they are.