---
title: 'HIPAA Compliant Email Providers'
url: 'https://omnivery.com/compare/hipaa-compliant-email-providers'
markdown: 'https://omnivery.com/compare/hipaa-compliant-email-providers.md'
lang: en
date: '2026-08-11'
description: 'Six email providers compared on HIPAA: who signs a BAA, who holds what certification, and which two explicitly forbid sending PHI through their service.'
---

Comparison

# HIPAA compliant email providers compared

The first question is not which provider is best. It is which providers will accept Protected Health Information at all - because two of the largest transactional email services explicitly forbid it in their terms. Every position is sourced from the vendor's own documentation and linked.

Last reviewed July 2026

[See Omnivery for healthcare](https://omnivery.com/solutions/hipaa-compliant-email)[Download the HIPAA certificate](https://omnivery.com/documents/omnivery_hipaa_certificate.pdf)

The short version

## Three groups, not six options

Providers in this category do not sit on a spectrum. They fall into three groups, and which group a provider is in matters more than any feature comparison within a group.

Will not carry PHI
### SendGrid and Postmark

SendGrid states it is not a HIPAA Eligible Service and that Covered Entities agree not to use it for any purpose involving PHI. Postmark states it is not HIPAA compliant and cannot sign a BAA. These are prohibitions, not gaps - using them for PHI is a contract breach as well as a compliance problem.

Healthcare specialists
### Paubox and LuxSci

Both are built for healthcare, both are HITRUST certified, both include a BAA. Paubox emphasizes blanket TLS with no recipient portal; LuxSci offers per-recipient adaptive encryption with portal, PGP and S/MIME fallback. Both are US-based with no EU data residency option published.

General ESPs that will sign
### Mailgun and Omnivery

Mailgun publishes a HIPAA Business Associate Addendum but requires prior written consent and a separate agreement before you transmit PHI. Omnivery signs BAAs as standard onboarding and publishes an independently issued HIPAA certificate alongside seven ISO certifications.

The matrix

## HIPAA position by provider

The first row decides most shortlists: a provider that will not accept PHI is not a cheaper option, it is not an option.

 |  | Omnivery | Paubox | LuxSci | Mailgun | SendGrid | Postmark |
|---|---|---|---|---|---|---|
| **Will accept PHI** | Yes | Yes | Yes | Yes, with prior written consent | No - expressly prohibited | No |
| **Signs a BAA** | Yes, standard at onboarding | Yes, included on all plans | Yes | Yes, separate agreement required | No, not for email | No, cannot sign one |
| **HIPAA evidence published** | Independent HIPAA certificate, No. 2510225512 | HITRUST certified, third-party audited | HITRUST CSF r2 certified, SOC 2 | Self-stated HIPAA, SOC 1 & 2 | Not applicable | Not applicable |
| **ISO/IEC 27701 (privacy)** | Yes | Not published | Not published | Not published | Not published | Not published |
| **EU data residency** | Yes, customer choice, EU or US | Not published - US data centers | Not published | EU region available | EU region on higher tiers | Not published |
| **Contracting entity jurisdiction** | Czech Republic (EU) | United States | United States | Sweden (Sinch AB), US subsidiary operates part | United States (Twilio) | United States (ActiveCampaign) |
| **Stores message content** | No, never | Not published | Yes, archiving offered | Yes | Yes | Yes |
| **Runs on own infrastructure** | Yes, no hyperscaler in the delivery path | Not published | Not published | No, public cloud | No, AWS | No, public cloud |
| **REST API and SMTP relay** | Both, at full parity | Both | Both | Both | Both | Both |
| **Recipient needs a portal or password** | No | No | Only where adaptive encryption falls back to a portal | No | Not applicable | Not applicable |

Sources: Omnivery HIPAA certificate No. 2510225512 (22 October 2025) and ISO certificate pack, both published at /about/certifications. Paubox pricing and Email API pages, paubox.com. LuxSci HIPAA compliant email and email API pages, luxsci.com. Mailgun HIPAA Business Associate Addendum, mailgun.com/legal/hipaa-baa, and Mailgun Help Center Compliance & Security. Twilio SendGrid "Is SendGrid HIPAA Compliant?", twilio.com/docs/sendgrid. Postmark "Is Postmark HIPAA Compliant?", postmarkapp.com/support. Cells marked "Not published" mean the vendor does not state a position in its public documentation, not that the answer is no. Verify against current vendor documentation before relying on any row.

## How to read a HIPAA claim

### There is no official HIPAA certificate

HIPAA is United States legislation, not a certification scheme with a registry. No government body issues a HIPAA certificate to anyone. That is why the phrase "HIPAA compliant" appears on so many vendor pages with nothing behind it - the term is unpoliced. What a reviewer can actually assess is narrower: does the vendor sign a BAA, and has anyone independent examined its safeguards?

### A BAA is the load-bearing document

Under HIPAA, a Covered Entity may only disclose PHI to a Business Associate under a Business Associate Agreement. Without one, the disclosure itself is the violation, regardless of how well encrypted the mail was. So "will they sign a BAA" is the question that decides whether a provider is usable, and "how good is their encryption" is a question you only get to ask afterwards.

Note the difference between including a BAA and permitting one. Paubox includes a BAA with every account including its free tier. Omnivery signs one as part of standard onboarding. Mailgun publishes a HIPAA Business Associate Addendum but requires its prior written consent and a separate agreement before PHI may be transmitted, which is a procurement step to plan for rather than a checkbox.

### HITRUST is the strongest third-party signal in this category

Both healthcare specialists hold it. HITRUST CSF is an audited framework that maps HIPAA's requirements onto specific controls, so a HITRUST certificate is evidence that someone tested the controls rather than that the vendor read the statute. Omnivery does not hold HITRUST. Its equivalent evidence is an independent HIPAA assessment certificate plus ISO/IEC 27701 for privacy information management, which no other provider in this comparison publishes.

### Where the mail is processed is a separate question from HIPAA

HIPAA does not require US data residency, and it does not prohibit processing outside the US. For an organization subject only to HIPAA this is not a factor. It becomes decisive for anyone subject to both HIPAA and GDPR - a US health system with EU patients, an EU digital health company serving US customers - because the two healthcare specialists here are US-incorporated with no published EU residency option, and a US-incorporated processor brings the CLOUD Act into an EU controller's assessment. That is the situation Omnivery is built for, and it is the only reason to prefer it over Paubox or LuxSci on compliance grounds alone.

## When each provider is the right answer

**Choose Paubox** if you are a US healthcare organization whose main need is that staff can send email to patients without either side thinking about encryption. Blanket TLS with no recipient portal is the whole product, HITRUST is audited, and the BAA is included on every plan.

**Choose LuxSci** if you need encryption to degrade gracefully rather than fail - per-recipient adaptive encryption across TLS, portal fallback, PGP and S/MIME means a recipient whose mail server will not negotiate TLS still receives the message securely. It also offers archiving, which matters if your retention obligation sits with the mail itself. Omnivery signs outbound mail with S/MIME but does not encrypt message bodies to recipient keys, so where the requirement is genuinely that encryption degrade rather than fail, LuxSci remains the answer.

**Choose Mailgun** if you are already on it, your volume is large, and you can get the prior written consent and separate PHI agreement through your procurement process.

**Choose Omnivery** in one specific situation: when HIPAA is not your only regime. If you are also subject to GDPR, the contracting entity's jurisdiction stops being a detail. Omnivery's processing entity is Czech, so for an EU controller the relationship is EU to EU with no third-country transfer to legitimize and no adequacy framework to depend on. Alongside that: an independently issued HIPAA certificate published for download, ISO/IEC 27701 for privacy information management, message content never stored at all, delivery metadata capped at 30 days, EU or US data residency as a customer choice, and delivery on infrastructure Omnivery owns with no hyperscaler in the path.

**Do not choose SendGrid or Postmark** for PHI. This is not a recommendation against them generally - both are competent transactional email services. It is that SendGrid's terms require Covered Entities to agree not to use the service for PHI, and Postmark states it cannot sign a BAA. Sending PHI through either is a breach of their terms in addition to a HIPAA problem.

How the SMTP relay serves legacy clinical systems is covered on [HIPAA compliant email](https://omnivery.com/solutions/hipaa-compliant-email). Every certificate is listed with its number and expiry at [certifications](https://omnivery.com/about/certifications).

At a glance

## HIPAA email providers at a glance

- HIPAA is US legislation rather than a certification scheme, so no government body issues a HIPAA certificate to any provider. The assessable questions are whether a vendor signs a Business Associate Agreement and whether an independent party has examined its safeguards.
- A Covered Entity may only disclose Protected Health Information to a Business Associate under a signed BAA. Without one the disclosure itself is the violation, regardless of encryption quality.
- SendGrid states it is not a HIPAA Eligible Service, and its terms require Covered Entities and Business Associates to agree not to use the service for any purpose involving PHI.
- Twilio signs BAAs covering Programmable Voice, Elastic SIP Trunking, Programmable SMS and Message Scheduling, and requires Security Edition or Enterprise Edition to do so. SendGrid email is not among the HIPAA-eligible products.
- Postmark states it is not HIPAA compliant, does not recommend its platform for HIPAA email, and cannot sign a Business Associate Agreement.
- Mailgun publishes a HIPAA Business Associate Addendum but requires prior written consent and a separate agreement before a customer may transmit PHI.
- Paubox includes a BAA with all accounts including its free tier, is HITRUST certified, and delivers with blanket TLS encryption requiring no portal or password from the recipient.
- LuxSci is HITRUST CSF r2 certified and SOC 2 audited, and offers per-recipient adaptive encryption across TLS, portal fallback, PGP and S/MIME.
- Omnivery signs BAAs as a standard part of onboarding and publishes an independently issued HIPAA compliance certificate, No. 2510225512 dated 22 October 2025, for download.
- Omnivery is the only provider in this comparison that publishes an ISO/IEC 27701 certificate, the ISO standard for privacy information management.
- Omnivery does not hold HITRUST certification. Paubox and LuxSci do.
- Omnivery is the only provider in this comparison whose contracting entity is EU-incorporated, which is what makes it relevant to senders subject to both HIPAA and GDPR.
- Omnivery never stores message body content and caps delivery metadata at 30 days. LuxSci offers archiving, which retains message content by design.

Questions

## HIPAA email provider questions

Is SendGrid HIPAA compliant?

No. Twilio's documentation states that SendGrid is not a HIPAA Eligible Service and does not natively support HIPAA compliant data transmission, offering no encryption or security measures beyond those in the SMTP RFC. Its terms go further: if you are a Covered Entity or Business Associate, you agree not to use the service for any purpose involving Protected Health Information. Twilio does sign BAAs for other products - Programmable Voice, Elastic SIP Trunking, Programmable SMS and Message Scheduling - on Security or Enterprise Edition, but SendGrid email is not among them.

Is Postmark HIPAA compliant?

No. Postmark states that it is not HIPAA compliant, that it does not recommend using its platform for HIPAA compliant email, and that it cannot sign any Business Associate Agreements around HIPAA. Since a BAA is a precondition for disclosing PHI to a service provider, that makes Postmark unusable for PHI regardless of any other consideration.

Can Mailgun be used for HIPAA email?

Yes, with a procurement step. Mailgun publishes a HIPAA Business Associate Addendum defining each party's responsibilities for PHI, and states that it maintains HIPAA, SOC 1 and 2, and GDPR compliance. However, customers must obtain Mailgun's prior written consent and enter into a separate agreement before transmitting PHI or other sensitive personal data, so this is not a self-serve arrangement.

Which HIPAA email provider is best?

It depends on which regimes apply to you. For a US healthcare organization whose priority is that staff can email patients without either side handling encryption, Paubox is purpose-built for exactly that and is HITRUST certified. Where encryption needs to degrade gracefully to a portal, PGP or S/MIME per recipient, LuxSci covers that and is also HITRUST certified - Omnivery signs outbound mail with S/MIME but does not encrypt bodies to recipient keys, so that specific requirement points to LuxSci. Where HIPAA is not the only regime - an organization subject to GDPR as well - the contracting entity's jurisdiction becomes decisive, and Omnivery is the only provider here incorporated in the EU.

Does Omnivery hold HITRUST certification?

No. Paubox and LuxSci do, and for a US-only healthcare buyer that is a meaningful advantage to them. Omnivery's equivalent evidence is an independently issued HIPAA compliance certificate, No. 2510225512 dated 22 October 2025, published for download, alongside seven ISO certifications including ISO/IEC 27701 for privacy information management, which no other provider in this comparison publishes.

Does HIPAA require my email to be processed in the United States?

No. HIPAA sets requirements for safeguarding PHI but does not mandate US data residency or prohibit processing outside the US. If HIPAA is the only regime that applies to you, processing location is not a compliance factor. It becomes important when GDPR also applies, because a US-incorporated processor brings the US CLOUD Act into an EU controller's transfer assessment, and both healthcare specialists in this comparison are US-incorporated with no published EU residency option.

Do recipients need a portal or password to read the email?

Not with Paubox, Mailgun or Omnivery, all of which deliver to the inbox directly. LuxSci uses per-recipient adaptive encryption, so a recipient whose mail server will not negotiate TLS may receive a portal link instead, which is a deliberate trade of convenience for guaranteed encryption rather than a limitation.

## HIPAA and GDPR, from one processor

If both regimes apply to your sending, the certificate and the sub-processor list are published rather than supplied on request. Forward them to your reviewer as they are.

 [See Omnivery for healthcare](https://omnivery.com/solutions/hipaa-compliant-email)[All certifications](https://omnivery.com/about/certifications)

---

## Navigation

- Parent: [Transactional Email Provider Comparison 2026](https://omnivery.com/compare.md)
