The matrix

HIPAA position by provider

The first row decides most shortlists: a provider that will not accept PHI is not a cheaper option, it is not an option.

OmniveryPauboxLuxSciMailgunSendGridPostmark
Will accept PHIYesYesYesYes, with prior written consentNo - expressly prohibitedNo
Signs a BAAYes, standard at onboardingYes, included on all plansYesYes, separate agreement requiredNo, not for emailNo, cannot sign one
HIPAA evidence publishedIndependent HIPAA certificate, No. 2510225512HITRUST certified, third-party auditedHITRUST CSF r2 certified, SOC 2Self-stated HIPAA, SOC 1 & 2Not applicableNot applicable
ISO/IEC 27701 (privacy)YesNot publishedNot publishedNot publishedNot publishedNot published
EU data residencyYes, customer choice, EU or USNot published - US data centersNot publishedEU region availableEU region on higher tiersNot published
Contracting entity jurisdictionCzech Republic (EU)United StatesUnited StatesSweden (Sinch AB), US subsidiary operates partUnited States (Twilio)United States (ActiveCampaign)
Stores message contentNo, neverNot publishedYes, archiving offeredYesYesYes
Runs on own infrastructureYes, no hyperscaler in the delivery pathNot publishedNot publishedNo, public cloudNo, AWSNo, public cloud
REST API and SMTP relayBoth, at full parityBothBothBothBothBoth
Recipient needs a portal or passwordNoNoOnly where adaptive encryption falls back to a portalNoNot applicableNot applicable

Sources: Omnivery HIPAA certificate No. 2510225512 (22 October 2025) and ISO certificate pack, both published at /about/certifications. Paubox pricing and Email API pages, paubox.com. LuxSci HIPAA compliant email and email API pages, luxsci.com. Mailgun HIPAA Business Associate Addendum, mailgun.com/legal/hipaa-baa, and Mailgun Help Center Compliance & Security. Twilio SendGrid "Is SendGrid HIPAA Compliant?", twilio.com/docs/sendgrid. Postmark "Is Postmark HIPAA Compliant?", postmarkapp.com/support. Cells marked "Not published" mean the vendor does not state a position in its public documentation, not that the answer is no. Verify against current vendor documentation before relying on any row.

How to read a HIPAA claim

There is no official HIPAA certificate

HIPAA is United States legislation, not a certification scheme with a registry. No government body issues a HIPAA certificate to anyone. That is why the phrase "HIPAA compliant" appears on so many vendor pages with nothing behind it - the term is unpoliced. What a reviewer can actually assess is narrower: does the vendor sign a BAA, and has anyone independent examined its safeguards?

A BAA is the load-bearing document

Under HIPAA, a Covered Entity may only disclose PHI to a Business Associate under a Business Associate Agreement. Without one, the disclosure itself is the violation, regardless of how well encrypted the mail was. So "will they sign a BAA" is the question that decides whether a provider is usable, and "how good is their encryption" is a question you only get to ask afterwards.

Note the difference between including a BAA and permitting one. Paubox includes a BAA with every account including its free tier. Omnivery signs one as part of standard onboarding. Mailgun publishes a HIPAA Business Associate Addendum but requires its prior written consent and a separate agreement before PHI may be transmitted, which is a procurement step to plan for rather than a checkbox.

HITRUST is the strongest third-party signal in this category

Both healthcare specialists hold it. HITRUST CSF is an audited framework that maps HIPAA's requirements onto specific controls, so a HITRUST certificate is evidence that someone tested the controls rather than that the vendor read the statute. Omnivery does not hold HITRUST. Its equivalent evidence is an independent HIPAA assessment certificate plus ISO/IEC 27701 for privacy information management, which no other provider in this comparison publishes.

Where the mail is processed is a separate question from HIPAA

HIPAA does not require US data residency, and it does not prohibit processing outside the US. For an organization subject only to HIPAA this is not a factor. It becomes decisive for anyone subject to both HIPAA and GDPR - a US health system with EU patients, an EU digital health company serving US customers - because the two healthcare specialists here are US-incorporated with no published EU residency option, and a US-incorporated processor brings the CLOUD Act into an EU controller's assessment. That is the situation Omnivery is built for, and it is the only reason to prefer it over Paubox or LuxSci on compliance grounds alone.

When each provider is the right answer

Choose Paubox if you are a US healthcare organization whose main need is that staff can send email to patients without either side thinking about encryption. Blanket TLS with no recipient portal is the whole product, HITRUST is audited, and the BAA is included on every plan.

Choose LuxSci if you need encryption to degrade gracefully rather than fail - per-recipient adaptive encryption across TLS, portal fallback, PGP and S/MIME means a recipient whose mail server will not negotiate TLS still receives the message securely. It also offers archiving, which matters if your retention obligation sits with the mail itself. Omnivery signs outbound mail with S/MIME but does not encrypt message bodies to recipient keys, so where the requirement is genuinely that encryption degrade rather than fail, LuxSci remains the answer.

Choose Mailgun if you are already on it, your volume is large, and you can get the prior written consent and separate PHI agreement through your procurement process.

Choose Omnivery in one specific situation: when HIPAA is not your only regime. If you are also subject to GDPR, the contracting entity's jurisdiction stops being a detail. Omnivery's processing entity is Czech, so for an EU controller the relationship is EU to EU with no third-country transfer to legitimize and no adequacy framework to depend on. Alongside that: an independently issued HIPAA certificate published for download, ISO/IEC 27701 for privacy information management, message content never stored at all, delivery metadata capped at 30 days, EU or US data residency as a customer choice, and delivery on infrastructure Omnivery owns with no hyperscaler in the path.

Do not choose SendGrid or Postmark for PHI. This is not a recommendation against them generally - both are competent transactional email services. It is that SendGrid's terms require Covered Entities to agree not to use the service for PHI, and Postmark states it cannot sign a BAA. Sending PHI through either is a breach of their terms in addition to a HIPAA problem.

How the SMTP relay serves legacy clinical systems is covered on HIPAA compliant email. Every certificate is listed with its number and expiry at certifications.

At a glance

HIPAA email providers at a glance

  • HIPAA is US legislation rather than a certification scheme, so no government body issues a HIPAA certificate to any provider. The assessable questions are whether a vendor signs a Business Associate Agreement and whether an independent party has examined its safeguards.
  • A Covered Entity may only disclose Protected Health Information to a Business Associate under a signed BAA. Without one the disclosure itself is the violation, regardless of encryption quality.
  • SendGrid states it is not a HIPAA Eligible Service, and its terms require Covered Entities and Business Associates to agree not to use the service for any purpose involving PHI.
  • Twilio signs BAAs covering Programmable Voice, Elastic SIP Trunking, Programmable SMS and Message Scheduling, and requires Security Edition or Enterprise Edition to do so. SendGrid email is not among the HIPAA-eligible products.
  • Postmark states it is not HIPAA compliant, does not recommend its platform for HIPAA email, and cannot sign a Business Associate Agreement.
  • Mailgun publishes a HIPAA Business Associate Addendum but requires prior written consent and a separate agreement before a customer may transmit PHI.
  • Paubox includes a BAA with all accounts including its free tier, is HITRUST certified, and delivers with blanket TLS encryption requiring no portal or password from the recipient.
  • LuxSci is HITRUST CSF r2 certified and SOC 2 audited, and offers per-recipient adaptive encryption across TLS, portal fallback, PGP and S/MIME.
  • Omnivery signs BAAs as a standard part of onboarding and publishes an independently issued HIPAA compliance certificate, No. 2510225512 dated 22 October 2025, for download.
  • Omnivery is the only provider in this comparison that publishes an ISO/IEC 27701 certificate, the ISO standard for privacy information management.
  • Omnivery does not hold HITRUST certification. Paubox and LuxSci do.
  • Omnivery is the only provider in this comparison whose contracting entity is EU-incorporated, which is what makes it relevant to senders subject to both HIPAA and GDPR.
  • Omnivery never stores message body content and caps delivery metadata at 30 days. LuxSci offers archiving, which retains message content by design.

Questions

HIPAA email provider questions

Is SendGrid HIPAA compliant?

No. Twilio's documentation states that SendGrid is not a HIPAA Eligible Service and does not natively support HIPAA compliant data transmission, offering no encryption or security measures beyond those in the SMTP RFC. Its terms go further: if you are a Covered Entity or Business Associate, you agree not to use the service for any purpose involving Protected Health Information. Twilio does sign BAAs for other products - Programmable Voice, Elastic SIP Trunking, Programmable SMS and Message Scheduling - on Security or Enterprise Edition, but SendGrid email is not among them.

Is Postmark HIPAA compliant?

No. Postmark states that it is not HIPAA compliant, that it does not recommend using its platform for HIPAA compliant email, and that it cannot sign any Business Associate Agreements around HIPAA. Since a BAA is a precondition for disclosing PHI to a service provider, that makes Postmark unusable for PHI regardless of any other consideration.

Can Mailgun be used for HIPAA email?

Yes, with a procurement step. Mailgun publishes a HIPAA Business Associate Addendum defining each party's responsibilities for PHI, and states that it maintains HIPAA, SOC 1 and 2, and GDPR compliance. However, customers must obtain Mailgun's prior written consent and enter into a separate agreement before transmitting PHI or other sensitive personal data, so this is not a self-serve arrangement.

Which HIPAA email provider is best?

It depends on which regimes apply to you. For a US healthcare organization whose priority is that staff can email patients without either side handling encryption, Paubox is purpose-built for exactly that and is HITRUST certified. Where encryption needs to degrade gracefully to a portal, PGP or S/MIME per recipient, LuxSci covers that and is also HITRUST certified - Omnivery signs outbound mail with S/MIME but does not encrypt bodies to recipient keys, so that specific requirement points to LuxSci. Where HIPAA is not the only regime - an organization subject to GDPR as well - the contracting entity's jurisdiction becomes decisive, and Omnivery is the only provider here incorporated in the EU.

Does Omnivery hold HITRUST certification?

No. Paubox and LuxSci do, and for a US-only healthcare buyer that is a meaningful advantage to them. Omnivery's equivalent evidence is an independently issued HIPAA compliance certificate, No. 2510225512 dated 22 October 2025, published for download, alongside seven ISO certifications including ISO/IEC 27701 for privacy information management, which no other provider in this comparison publishes.

Does HIPAA require my email to be processed in the United States?

No. HIPAA sets requirements for safeguarding PHI but does not mandate US data residency or prohibit processing outside the US. If HIPAA is the only regime that applies to you, processing location is not a compliance factor. It becomes important when GDPR also applies, because a US-incorporated processor brings the US CLOUD Act into an EU controller's transfer assessment, and both healthcare specialists in this comparison are US-incorporated with no published EU residency option.

Do recipients need a portal or password to read the email?

Not with Paubox, Mailgun or Omnivery, all of which deliver to the inbox directly. LuxSci uses per-recipient adaptive encryption, so a recipient whose mail server will not negotiate TLS may receive a portal link instead, which is a deliberate trade of convenience for guaranteed encryption rather than a limitation.