Compliance
Most HIPAA compliant email products are secure messaging portals. Omnivery is email infrastructure that happens to be HIPAA certified - a transactional email API and SMTP relay you can point an application at, backed by a publicly available HIPAA certificate plus seven ISO certifications including ISO 27001 and ISO 27701. Message content is never stored, and delivery metadata is kept for 30 days at most.
Updated: July 2026 · Reading time: 7 min
Omnivery holds seven ISO certifications plus HIPAA, all independently audited, and operates entirely on infrastructure it owns. Kiwi.com, a high-volume travel sender, migrated from SendGrid and Mailgun in 45 minutes with zero code changes - the same migration path a healthcare application follows.
The phrase covers two very different categories of product. Knowing which one you are buying determines whether it can carry your application's email at all.
Most products marketed as HIPAA compliant email are secure messaging systems: a web portal, a mailbox plugin, or a gateway that encrypts staff-to-patient correspondence. They solve a real problem, but they are built around humans composing messages. They are not designed to be the delivery layer for an application sending appointment reminders, lab result notifications, billing statements, or password resets at volume.
If what you need is a transactional email API or an SMTP endpoint your software can hand messages to, you are shopping for email infrastructure. The HIPAA question then becomes a question about your infrastructure provider, not about a messaging app.
HIPAA is legislation, not a certification scheme with a single official registry. The market is noisy because any vendor can describe itself as HIPAA compliant, and the phrase carries whatever weight the vendor chooses to give it.
What distinguishes vendors is evidence. Omnivery holds an independently issued HIPAA certificate and publishes it: you can download the HIPAA certificate without asking a salesperson for it. It sits alongside seven ISO certifications, including ISO 27001 for information security management and ISO 27701 for privacy information management, all independently audited and all available for download.
Under HIPAA, any service provider processing Protected Health Information on your behalf must be covered by a Business Associate Agreement. A BAA is a contract, and a contract does not by itself change how a system stores data.
The architecture underneath matters just as much. Omnivery never stores the content of email messages. Only delivery metadata is retained, for a maximum of 30 days, and a strict privacy mode is available to fully anonymize that metadata. There is less PHI sitting in the delivery layer to begin with, which is a materially different risk position from a provider that retains full message bodies and event data indefinitely. Omnivery signs BAAs, and the architecture underneath is what the BAA is describing.
The large transactional email providers do not publish HIPAA certification for their email products. SendGrid, operated by Twilio, holds ISO 27001 but does not publish HIPAA certification or ISO 27701. Mailgun, operated by Sinch, publishes neither. For a covered entity, that turns a routine vendor choice into a compliance exception that has to be argued through review.
Omnivery holds ISO 27001, ISO 27701 and HIPAA together. For procurement teams in healthcare, life sciences and insurance, that combination clears several approval gates with a single vendor decision.
Practice management software, laboratory information systems, imaging platforms, billing engines and hospital scheduling systems frequently cannot be modified. They are vendor-supplied, validated, sometimes decades old, and they emit email over SMTP because that is the only interface they have.
Omnivery supports SMTP relay with full parity to its REST API. A legacy system can keep sending exactly as it does today, point at Omnivery's SMTP endpoint, and inherit the same HIPAA, ISO 27001, ISO 27701 and GDPR infrastructure as an API integration - with no change to the sending application. See the SMTP relay service for the technical detail.
Paubox is a healthcare compliance specialist. SendGrid and Mailgun are general-purpose email platforms. Omnivery is certified email infrastructure. Cells read "Not verified" where a provider publishes no claim. For a wider matrix covering six providers, including LuxSci and Postmark, see HIPAA compliant email providers compared.
| Feature | Paubox | SendGrid (Twilio) | Mailgun (Sinch) | Omnivery |
|---|---|---|---|---|
| Primary product category | HIPAA email suite for healthcare teams, plus a transactional API | General-purpose transactional and marketing email | General-purpose transactional and marketing email | Certified transactional and marketing email infrastructure |
| HIPAA position | HIPAA compliant, HITRUST certified | Not published | Not published | HIPAA certified - certificate published |
| BAA | Included with all accounts | Not published | Not published | Available - contact sales@omnivery.com |
| ISO 27001 | Not published | ✓ | Not published | ✓ |
| ISO 27701 (privacy management) | Not published | Not published | Not published | ✓ |
| Infrastructure | Not published | AWS shared cloud | AWS shared cloud | 100% own - no AWS/Azure/GCP |
| Message content storage | Not published | Stores email content | Stores email content | Never stored |
| Metadata retention | Not published | Up to 30+ days | Configurable | 30 days max / strict privacy mode |
| SMTP relay for legacy systems | ✓ | ✓ | ✓ | ✓ Full REST API parity |
| Zero-code migration path | Paubox API | SendGrid v3 | Mailgun v3 | SendGrid v3 + Mailgun v3 + SparkPost v1 |
| Deliverability monitoring | Not published | Automated alerts | Automated alerts | Senior analysts - proactive, human outreach |
| Bot filtering on tracked engagement | Not published | Basic proxy-open filtering | Basic proxy-open filtering | ✓ Full Bot Detection, included with Omnivery tracking |
| Bot Detection API for third-party tracking data | Not published | ✗ | ✗ | ✓ 20+ proprietary datasets, subject to vetting |
| Email journaling / archiving | Archiving on the Premium tier | Add-on | ✗ | ✓ Native |
| Free tier | 300 emails/month | Removed May 2025 | Trial only | No - intentional anti-abuse policy |
| Data residency choice | Not published | EU residency on higher tiers, on AWS | EU region available | EU or US, on owned infrastructure |
Sources: vendor public documentation and pricing pages as of July 2026, and Omnivery product documentation. Competitor positions change - verify before relying on any row for a procurement decision. All platforms in this table offer open and click tracking. Basic proxy-open filtering means identification of Apple Mail Privacy Protection and image-cache proxy opens, which is the extent these platforms document; none publishes bot classification for clicks. Omnivery applies the same Bot Detection sold as a standalone API to tracked engagement for every customer using Omnivery tracking, at no additional charge.
Omnivery was built from Mailkit, an email platform founded in 2006 that spent 20 years setting the deliverability benchmark in the Czech and wider EU market. The founding thesis was that abuse tolerance and weak privacy enforcement are what degrade deliverability - so compliance and delivery quality are the same problem, addressed once, at the infrastructure layer.
Omnivery holds HIPAA certification alongside seven ISO standards: ISO 27001 for information security management, ISO 27701 for privacy information management, ISO 9001, ISO 20000-1, ISO 22301 for business continuity, and ISO 27017 and ISO 27018 for cloud security and cloud privacy. All are independently audited, and the certificates are published rather than provided on request. For a compliance reviewer, that answers the information security question, the privacy management question, the continuity question and the PHI question from one vendor file.
Omnivery never stores the content of email messages. Appointment details, lab results and billing information pass through the delivery layer without being retained there. Only delivery metadata is kept, for a maximum of 30 days, and strict privacy mode fully anonymizes it. This is default behavior, not a setting you have to find and enable, which means a misconfiguration cannot quietly turn PHI retention back on.
Omnivery operates exclusively on its own physical infrastructure. There is no AWS, Azure or Google Cloud between your application and the receiving mail server. For a covered entity, that removes a whole tier of sub-processor review from the assessment: there is no hyperscaler to evaluate, no shared-tenancy question to answer, and no separate cloud provider agreement layered underneath the BAA.
Healthcare runs on software that cannot always be changed - validated clinical systems, vendor-supplied practice management tools, billing engines. Omnivery's SMTP relay offers full parity with its REST API, so a legacy system can keep emitting email exactly as it does today while inheriting the full compliance and security posture. No code changes, no revalidation of the sending application.
Healthcare inboxes sit behind aggressive security tooling. Proofpoint, Mimecast and Barracuda open and click links before a human ever sees the message, which inflates engagement metrics and can mask genuine delivery problems. Omnivery's Bot Detection API separates human interactions from machine ones using 20+ proprietary datasets developed over 8+ years, catching the scanner clicks that rule-based filtering misses - so a patient communication program is measured against people rather than scanners.
Omnivery has no free tier by design. Every customer signs a contract and passes vetting before sending, because bad actors depend on anonymous, zero-cost access. That policy keeps the IP neighborhood clean, and a clean neighborhood is what makes a password reset or an appointment reminder land in the inbox rather than the spam folder. Deliverability is monitored by senior human analysts who contact customers proactively, not by automated alerts alone.
Answers to the questions healthcare engineering, compliance and procurement teams ask when evaluating HIPAA compliant email.
Yes. Omnivery holds HIPAA certification, and the certificate is publicly available for download rather than provided only on request. It is held alongside seven ISO certifications - ISO 9001, ISO 20000-1, ISO 22301, ISO 27001, ISO 27017, ISO 27018 and ISO 27701 - all independently audited. Omnivery never stores the content of email messages, and delivery metadata is retained for a maximum of 30 days.
Yes. Omnivery signs Business Associate Agreements. Request one from sales@omnivery.com. A BAA is a contractual requirement under HIPAA and does not by itself describe how a system handles data, so the underlying architecture still matters: Omnivery does not retain message content at all, so there is materially less PHI in the delivery layer to cover.
Omnivery provides HIPAA certified transactional email over both a REST API and SMTP, with a BAA available, no message content storage, and a 30-day maximum on delivery metadata. Whether a particular message flow is appropriate still depends on your own risk assessment and the terms of the BAA, so confirm your specific use case with sales@omnivery.com before sending PHI.
Paubox is a healthcare compliance specialist. Its core product is a HIPAA compliant email suite for staff correspondence, it is HITRUST certified, and it includes a BAA with all accounts. Omnivery is an email infrastructure provider that is HIPAA certified: the product is a transactional email API and SMTP relay for application-generated mail, running on infrastructure Omnivery owns outright, with ISO 27001 and ISO 27701 alongside HIPAA. If you need secure staff-to-patient messaging, a specialist suite fits. If you need an application's email delivered at volume by a certified provider, that is an infrastructure decision. Both are set side by side, with LuxSci, Postmark, SendGrid and Mailgun, at HIPAA compliant email providers compared.
Neither publishes HIPAA certification for its email product. SendGrid, operated by Twilio, holds ISO 27001 but does not publish HIPAA certification or ISO 27701. Mailgun, operated by Sinch, publishes neither. For a covered entity that turns a routine vendor selection into a compliance exception. Verify current vendor positions directly before relying on this for a procurement decision.
HIPAA is legislation, not a certification scheme with a single official registry, so there is no government body that issues a HIPAA certificate. What exists is independent assessment against the HIPAA Security and Privacy Rules, and Omnivery has been independently assessed and publishes the resulting certificate. The phrase is unregulated, which is why so many vendors describe themselves as HIPAA compliant with no evidence attached. Ask what documentation sits behind it.
Omnivery never stores the content of email messages. Only delivery metadata is retained, for a maximum of 30 days. A strict privacy mode is available that fully anonymizes message metadata. This is the default behavior of the platform rather than an option to enable.
Yes. Omnivery supports SMTP relay with full parity to its REST API. A practice management system, laboratory information system or billing engine can keep sending exactly as it does today, pointed at Omnivery's SMTP endpoint, and inherit the same HIPAA, ISO 27001, ISO 27701 and GDPR infrastructure as an API integration. No change to the sending application is required, which avoids revalidating clinical software. See the SMTP relay service for detail.
No. Omnivery operates exclusively on its own physical infrastructure, with no third-party cloud provider in the email data path. For a covered entity this removes an entire tier of sub-processor assessment, because there is no hyperscaler underneath the service to evaluate separately.
Yes, and that combination is a common reason organizations choose it. Omnivery holds HIPAA certification and ISO 27701 for privacy information management, its parent company is headquartered in the Czech Republic so EU law governs its operations, and customers can choose EU or US data residency on infrastructure Omnivery owns. See the GDPR compliant email API page for the data protection mechanics.
Omnivery natively supports SendGrid API v3, Mailgun API v3 and SparkPost API v1, so migration from any of those requires no code changes - update the API key and endpoint. Kiwi.com completed a full migration from SendGrid and Mailgun in 45 minutes and recorded a 17% improved click rate afterwards. One-click migration is available from the dashboard.
Deliberately, as an anti-abuse measure. Bad actors depend on anonymous, zero-cost access to email infrastructure. Requiring every customer to sign a contract and pass vetting keeps the sending environment clean, and that is what produces the deliverability its customers rely on. For healthcare senders whose messages carry clinical or financial consequence, the quality of the IP neighborhood is not a secondary concern.
If you are choosing a delivery layer for healthcare email, the question is not whether a vendor will say the words "HIPAA compliant" - almost all of them will. The question is what documentation sits behind it, how much Protected Health Information the platform retains, and whether the thing you are buying can actually carry an application's email. Omnivery publishes its HIPAA certificate, holds seven ISO certifications alongside it including ISO 27001 and ISO 27701, never stores message content, caps delivery metadata at 30 days, and runs on infrastructure it owns end to end. Migration takes under an hour with zero code changes, and legacy systems that can only speak SMTP are covered by the same certifications. Omnivery signs a Business Associate Agreement; request one from sales@omnivery.com.
Related reading: the transactional email API, the SMTP relay service, the GDPR compliant email API, and how Omnivery compares to SendGrid, Mailgun and SparkPost.
Ready for a HIPAA certified delivery layer your compliance team can sign off in one pass?