Encrypted Email Providers Compared for Personal and Healthcare Use

encrypted email providers guide featured image

๐Ÿ”‘ Key Takeaways

  • Encrypted mail splits three ways: consumer inbox replacements, business tiers, HIPAA add-ons.
  • Free ProtonMail and Tuta cap at 150-200 sends daily and never include a BAA for regulated use.
  • HIPAA needs a signed BAA on the platform; personal Gmail and consumer ProtonMail do not qualify.
  • Recipient experience varies from one-click portals to password exchanges and drives response.
  • Choose on five factors: platform, volume, compliance, recipient literacy, and per-seat budget.

Encrypted email providers fall into three groups. Consumer end-to-end providers run a full replacement inbox. Business-tier platforms layer encryption on standard business mail. HIPAA-focused services add encryption and compliance controls on top of existing Gmail or Outlook accounts.

This guide covers the main providers in each group, the trade-offs on price and recipient experience, and where a dedicated encrypted email service fits the healthcare use case.

The right choice depends on the existing mail platform, the compliance requirements, and the tech literacy of the recipient population. There is no single best provider across all buyers.

Three Categories of Encrypted Email Providers

Consumer end-to-end providers include ProtonMail and Tuta. Both offer full replacement inboxes with encryption built in between users of the same platform. Both are based in Europe with strong privacy positioning.

Business-tier platforms include Microsoft 365 with Purview Message Encryption and Google Workspace with client-side encryption. Both layer encryption on the existing business mail platform and include a BAA available for HIPAA scenarios.

HIPAA-focused services include Mailhippo and similar tools that work alongside an existing Gmail or Outlook account. They add encryption, the BAA, and compliance controls without replacing the underlying mail platform.

The categories address different buyers. Consumer providers fit personal privacy needs. Business platforms fit organizations with an existing Microsoft or Google investment. HIPAA services fit practices needing compliance without an enterprise upgrade.

Free Encrypted Email Options Are Limited

Free encrypted email is available from ProtonMail Free and Tuta Free. Both offer limited storage and outbound volume that fit personal use but not business use.

ProtonMail Free offers 500 megabytes of storage and 150 outbound messages per day. Tuta Free offers 1 gigabyte of storage and 200 outbound messages per day. Both hit the limits quickly under any professional use.

Free tiers do not include a business associate agreement. Practices needing HIPAA compliance cannot use a free consumer account regardless of the encryption strength. The BAA is a separate contractual matter.

Personal Gmail, personal Outlook, and free Yahoo accounts do not offer true message-level encryption. Gmail’s confidential mode and Outlook’s basic TLS provide partial protection but do not meet HIPAA transmission requirements on their own.

encrypted email providers in article illustration one

Consumer Providers Focus on End-to-End Encryption

ProtonMail runs a full end-to-end encryption model between users of the ProtonMail platform. Messages between two ProtonMail accounts encrypt automatically. Users hold the keys client-side.

Tuta uses a similar end-to-end model between Tuta accounts. The company runs its own encryption stack and cannot decrypt user messages. Both providers publish their code as open source.

External recipients on non-ProtonMail or non-Tuta accounts receive a password-protected link. The sender shares the password through a separate channel. This creates friction for reaching regular Gmail or Outlook users.

Consumer providers fit users who value privacy and who correspond primarily with other users of the same platform. Business users sending to patients on standard email addresses often find the friction too high for daily use.

Microsoft 365 and Google Workspace Cover Business Encryption

Microsoft 365 Business Premium and higher plans include Purview Message Encryption. The sender clicks Options, then Encrypt, in the Outlook compose ribbon. Purview handles the delivery and the recipient portal.

Google Workspace Enterprise Plus and Education Plus include client-side encryption. The sender clicks a lock icon in the Gmail compose window. Content encrypts in the browser before it reaches Google servers. Keys stay outside Google through a customer-controlled key service.

Both platforms sign a BAA for business tenants. The BAA covers the platform’s handling of PHI processed on behalf of the covered entity. Consumer tiers of both platforms do not include the BAA.

Detailed setup for Microsoft Purview is in the Microsoft support guide for encrypted messages. Google client-side encryption setup is in the Google Admin console.

Example A solo therapist runs a Squarespace site and a personal Gmail address at no cost. She sees 22 patients per week and sends session summaries by email. Personal Gmail has no BAA, and Google Workspace Enterprise Plus at $30 per month is overkill for one seat. She picks a dedicated HIPAA service at $12 per month that layers encryption on her existing Gmail, includes the BAA in the base plan, and delivers messages through a one-click portal her patients open without creating any account.

Provider Comparison at a Glance

The table below summarizes the main providers across price, encryption method, HIPAA support, and recipient experience.

ProviderEncryption MethodHIPAA BAARecipient Experience
ProtonMailEnd-to-end (same-platform)Business tier onlyPassword portal for external
TutaEnd-to-end (same-platform)Not standardPassword portal for external
Microsoft 365 PurviewPortal-based (server encrypts)Yes on business tenantPortal sign-in or passcode
Google Workspace CSEClient-side (browser encrypts)Yes on business tenantPortal with key service
MailhippoGateway encryptionYes in base planOne-click portal, no account

The comparison highlights that recipient experience varies more than encryption strength. All five options provide strong encryption. The difference is what the recipient has to do to read the message.

encrypted email providers in article illustration two

HIPAA Email Providers Bundle Compliance Into the Plan

HIPAA email providers such as Mailhippo bundle encryption, the BAA, access logs, and recipient portal into a single plan. The buyer does not have to piece together the compliance stack from separate components.

The service works alongside an existing Gmail or Outlook account. The sender writes mail in the familiar interface. Outbound mail routes through the encryption gateway. The recipient gets a one-click portal to read the message.

The BAA is signed as part of onboarding. The access logs run automatically. Practices without dedicated IT get the full compliance stack without configuring individual pieces.

The trade-off is a routing dependency on the service. Outbound mail runs through the service infrastructure. Uptime and continuity of the service become part of the practice’s operational picture.

Recipient Experience Drives Adoption for Patient Communication

The recipient experience matters more for patient communication than for internal or business partner mail. Patients have varying tech literacy. A workflow that requires the patient to install a certificate or exchange a password fails at the population level.

The one-click portal experience matches how patients already use online banking, telehealth, and pharmacy portals. The recipient clicks a link, verifies identity with a one-time passcode or sign-in, and reads the message.

Providers that offer this experience include Microsoft 365 Purview and dedicated HIPAA services. ProtonMail and Tuta external delivery requires more steps. S/MIME requires a certificate on the recipient side, which rules it out for patient use in almost all cases.

Practices building patient communication workflows should test the recipient view before selecting a provider. The sender view is not the recipient view. A five-minute test with a patient using a personal Gmail account reveals what the actual experience will be.

๐Ÿ’กPro Tip: Test the recipient view with a real patient deviceProvider marketing pages never show the recipient view. Send a test message from your shortlist candidates to a personal Gmail on an old Android phone and a personal Yahoo on an iPhone. Time the sign-in path, note any account creation prompts, and confirm attachments open on mobile. The provider that clears both tests in under 20 seconds is the one that will keep patient response rates.

Cost Differences Between Provider Categories

Pricing varies by category and by tier within each category. The list below shows current price ranges for each option.

  • ProtonMail personal plans start around $4 per month with additional storage and features.
  • Tuta personal plans start around $3 per month with similar tiering.
  • Microsoft 365 Business Premium is $22 per user per month including Purview Message Encryption.
  • Google Workspace Enterprise Plus starts around $30 per user per month for client-side encryption.
  • Dedicated HIPAA email services range from $10 to $25 per user per month depending on volume and features.

Practices already on Microsoft 365 or Google Workspace often find the incremental cost of adding encryption is a plan upgrade rather than a new subscription. Practices without an existing platform find a dedicated HIPAA service more cost-effective per seat.

HIPAA Compliance Beyond the Encryption Provider

The encryption provider covers one part of the HIPAA compliance picture. The covered entity is still responsible for the surrounding controls: access logging, workforce training, incident response, and correct configuration.

The HHS Security Rule guidance lays out the framework. Encryption is one required technical safeguard. Administrative and physical safeguards remain separate obligations.

Practices building the full posture around encrypted mail also need to cover the site, patient portal, and intake forms. See the guide on healthcare website security features for the site-side controls.

The email provider handles the mail. The site handles the intake. The portal handles the ongoing care communication. Together they form the compliant digital footprint.

Choosing a Provider Comes Down to Five Factors

The choice among providers comes down to five factors. Existing mail platform in use. Volume of encrypted mail sent. HIPAA or other compliance requirements. Recipient population and tech literacy. Budget for licensing or subscription.

Practices already on Microsoft 365 or Google Workspace often add encryption at the platform level. The incremental cost is an upgrade. The workflow stays inside the existing tools.

Practices without a business mail investment often pick a HIPAA-focused service. The service bundles encryption, BAA, and portal into one plan. No enterprise upgrade required.

Consumer providers fit personal use and cross-provider testing. Business users typically outgrow the free tiers within weeks. Related reading covers specific provider comparisons: best encrypted email providers, secure encrypted email providers, encrypted email, best free encrypted email providers, hipaa encrypted email healthcare providers, and free hipaa compliant email providers.

Practices pairing the encryption provider decision with a wider healthcare digital strategy work with a healthcare marketing agency that coordinates mail, site, and portal into a single compliant footprint.

What Is Encrypted Email and How Does It Protect Your Messages

Email feels quick and easy. You type a message, hit send, and it appears in someoneโ€™s inbox. For many practices and small businesses, that message can hold patient details, invoices, reports, or HR questions.

Regular email does not always keep those details private. In many cases, it works a bit like a postcard. Systems that handle the message can read it on the way.

Encrypted email changes this. It scrambles the content so only the right person can read it. For a broader overview of secure messaging, visit the main guide to encrypted email on MailHippo.

Encrypted email in plain language

Think of a normal email as open text on a screen. Mail servers and some people on weak networks can see that text. If the message contains health or financial information, it can pose a real risk.

An encrypted email works more like a locked envelope. Your email tool encrypts the message before it leaves your device. Only someone with the right digital key or login can turn that data back into readable words.

You do not need to deal with the math or the keys yourself. Modern tools handle those parts in the background. You still write and send emails familiarly. If you want more background on the core idea, you can read the MailHippo guide on what email encryption is.

How encrypted email works

What happens before the message is sent

Before you send an encrypted email, your system generates a key pair. One key is public and safe to share. The other key is private and stays tied to you.

Your email service often creates and stores these keys when you first set up secure mail. The private key lives inside your account or device. The public key is the piece that other people use when they send you protected messages.

When you write to someone, your tool may pull that personโ€™s public key from a directory or from their profile. That public key lets your system scramble the message so only its matching private key can unlock it.

What happens during delivery

Once you press send, your email program encrypts the message body. In many systems, it protects the attachments at the same time. To anyone watching the traffic, the content now appears to be random characters.

The message then travels through the normal email network. It passes through several servers that relay it to the recipientโ€™s inbox. Those servers can move the data, yet they cannot read the hidden parts.

Many providers use a method called TLS between servers. TLS wraps the connection in a secure tunnel. That step helps on public Wiโ€‘Fi and shared networks. For a deeper walkthrough of these stages, you can read the MailHippo article on how email encryption works later.

How the recipient opens and reads the message

When the message reaches the other person, their tool spots that the content is encrypted. It uses their private key or a secure account to decrypt the scrambled data. This happens very fast.

From their point of view, the process feels simple. They open the email, enter a password or code if asked, and read the message. Some systems use a secure web page, so the person clicks a link and signs in to view the content.

Many patients and non-technical users can handle this with no trouble once they see it. The complex work sits behind a clean, friendly screen.

Encrypted email vs regular email

Regular email often leaves the content open to more systems. Many providers scan messages to filter spam and malware. Logs on servers can hold copies of full messages for some time.

In that setup, anyone who gains access to those systems can read the text. That might be an attacker, a rogue staff member, or someone who guessed a weak password for simple scheduling notes that might not worry you. For treatment plans or bank details, it should.

An encrypted email protects the content from these kinds of eyes. The servers may still hold the data, yet they see scrambled text instead of clear words. Only the right person with the right key or login sees the real message.

Encrypted email vs secure email

People often talk about encrypted email and secure email as if they were the same. They link together, yet they do not mean the same thing.

Encrypted email focuses on the privacy of the message body and attachments. The goal is simple. Scramble the content so only the right person can read it.

Secure email is a wider idea. It can cover spam filters, virus checks, strong passwords, and staff training. A service might call itself โ€œsecureโ€ and still use only light encryption. To see a clear side-by-side view, you can read MailHippoโ€™s guide on secure email vs encrypted email.

Main types of email encryption

TLS

TLS stands for Transport Layer Security. It protects the path between mail servers. Think of it as a safe tunnel that links one system to another.

Most modern providers use TLS when they talk to each other. People who watch the network traffic see scrambled data, not clear text. That reduces the impact of snooping on public networks.

TLS helps a lot with messages that move between servers. It does not always protect the message when it sits in an inbox. For that part, you need other forms of encryption or secure storage.

End-to-end encryption

End-to-end encryption protects the message from one device to another device. Only the sender and the intended recipient can read it in clear form.

The sender uses the recipientโ€™s public key to encrypt the content. The recipient uses their private key to decrypt it again. Systems in the middle see only scrambled characters.

This method offers strong privacy. Older tools made it feel difficult. Newer services hide most of the setup and offer simple buttons, such as โ€œsend secure,โ€ on your normal mail screen.

PGP

PGP stands for Pretty Good Privacy. It is one of the oldest standards for secure email. Many privacy-minded users still rely on it.

With PGP, each user creates a public key and a private key. They share the public key so others can send them an encrypted email. They guard the private key so only they can open those messages.

Classic PGP tools can feel technical. Newer services sometimes run PGP in the background and present a clean interface. That way, staff gain strong protection without having to handle key files by hand.

S or MIME

S or MIME means Secure or Multipurpose Internet Mail Extensions. Many large companies and health networks use this method.

S/MIME can encrypt email content. It can also add a digital signature that proves who sent the message and that no one changed it along the way.

Outlook, Apple Mail, and other common programs support S/MIME. IT teams usually handle the setup since it involves certificates. After setup, users send and read email as they always do.

What parts of an email are protected

Message body

The body of the email holds the main text. In most encrypted email systems, this part is directly protected. The text is scrambled before it leaves your device.

Anyone who intercepts the message without the right key sees only a block of nonsense. That makes a big difference when the content carries names, diagnoses, or account numbers.

Some services keep the body encrypted even when stored on servers. Others decrypt it only when you open the email. In both cases, the aim stays the same. Keep sensitive text away from prying eyes.

Attachments

Attachments often carry the most private details. Think of Xโ€‘rays, treatment plans, financial reports, or ID scans. Good encrypted email tools protect these files too.

Many systems encrypt attachments along with the body. The files travel and sit on servers in scrambled form. The recipientโ€™s tool decrypts them when the person opens or downloads them.

Some services let you add extra controls to attachments. You can limit downloads, add expiry dates, or grant view-only access through a secure portal. Those options give more control over where the files go next.

Subject line and metadata

The subject line often stays in plain text. Email systems use it for sorting, searching, and phone alerts. That subject can appear on servers and in logs.

Metadata includes who sent the email, who received it, and when it was sent. Systems use that data to route and track messages. Parts of that data usually remain visible.

For that reason, avoid sensitive details in the subject line. Keep names, dates of birth, and medical notes inside the body or attachments. Encryption then has something useful to protect.

Why do people use encrypted email?

Personal privacy

Many people feel uneasy about how open regular email can be. Messages can hold scans of IDs, bank details, or family matters. A leak can lead to stress, fraud, or simple embarrassment.

Encrypted email offers a calmer way to share private details. The content stays hidden from most systems that touch it. Attackers who grab a copy face strong math, not clear text.

This helps when you travel, work from home, or use shared Wiโ€‘Fi. Even if someone taps the network, they gain very little from the scrambled data.

Work and business use

Teams share important information every day by email. Quotes, contracts, payroll data, and staff reviews all move that way. Plain email leaves those details more exposed.

Encrypted email protects these exchanges. Clients and partners see that you treat their information with care. That builds trust and supports long-term relationships.

Many insurers and industry groups now expect some form of email encryption for sensitive data. Using it in daily work makes it easier to pass audits and meet policy terms.

Sensitive documents and regulated data

Some information comes with strict legal rules. Health records and some personal data sit in this group. Dental and medical practices know this well.

Regulations such as HIPAA and GDPR ask you to protect data in transit and at rest. Email encryption plays a clear role here. It helps you send records and reports without exposing them.

Many contracts with hospitals, labs, or insurers also mention encryption. A good encrypted email service provides a clear way to meet those terms and demonstrate due care.

When encrypted email makes sense

Encrypted email makes sense any time a message could cause harm if it leaked. Think of patient charts, lab results, payment details, and legal issues. Those messages deserve more protection than a simple postcard-style email.

Look at the emails that move through your practice in a typical week. Many may feel routine. Under the surface, they hold names, dates, and health or money details for real people.

A simple habit can help. If you feel worried seeing the message on a notice board, treat it as a good candidate for encryption.

What encrypted email does not do

It does not stop every security risk.

Encrypted email deals with one part of the problem. It protects the content in transit and often in storage. Other risks still exist.

If someone steals a password, they may open encrypted messages after login. Malware on a device can capture data once it appears in clear text on the screen. Poor password habits can undo strong tech.

You still need strong passwords, multi-factor login, updates, and staff training. Encryption works best as one layer in a wider set of controls.

It does not hide every detail of a message.

Encryption usually hides the body and attachments. It does not always hide the subject line or who sent and received the email. That pattern can still give clues.

Someone might see heavy traffic between your practice and a law firm. They may not see the content, yet they can guess that something is going on.

Good practice keeps true private details in the protected parts only. That means inside the body and files, not in the subject or address list.

It may need to be set up on both sides.

Strongly encrypted email often requires some setup for both the sender and the recipient. That might mean keys, secure accounts, or a portal login.

Modern tools try to make this simple. Many send a short notice email with a link. The patient or client clicks to create a password or enter a code, then reads the message on a secure page.

When you pick a service, test this from a non-technical user’s view. Ask yourself whether a busy patient could follow the steps without help.

How do people get encrypted email?

Built-in options in common email tools

Many popular email platforms now include encryption options. Microsoft 365 and Google Workspace both offer ways to send protected messages.

Staff often click a โ€œprotectโ€ or โ€œencryptโ€ option in the compose window. The platform then handles the rest. It might use S or MIME, a secure portal, or background rights controls.

This approach keeps tools familiar. People stay in Outlook, Gmail, or similar apps. Admins set the rules once, and users gain simple buttons.

Third-party email services

Some providers focus only on secure, encrypted email. MailHippo sits in this group. These services design tools for health care, legal, and finance teams that send sensitive data every day.

Staff sign in to a secure portal or use add-ons in their usual mail client. They choose which messages need protection. The service hosts the secure content and sends the recipient a notice.

These platforms often add tracking, secure file sharing, and policy rules. That gives you more control over who can open each message and for how long.

Browser tools and add-ons

Some users add encryption through browser extensions. These tools often bring PGP or similar methods into webmail accounts.

Power users may like the control this gives. For busy practices, it can feel complex. Each person must manage their own keys and settings.

For team use, any add-ons should go through your IT partner. That way, the practice keeps control of access and backups.

How to tell if an email may be encrypted

Your email program often shows small signs when a message is encrypted. You may see a padlock near the address line. You may see a label such as โ€œsecureโ€ or โ€œencrypted messageโ€ near the top.

If your system uses a portal, your inbox may show only a short notice email. That notice holds a link to a secure page. The private content appears only after you sign in.

If you feel unsure, ask your IT contact to send you a test encrypted email. They can point out the icons and wording that your system uses.

Common questions

What is an encrypted email?

An encrypted email is a message that has been scrambled with strong math. Only someone with the right key or login can read it in clear text. Everyone else sees random characters or cannot open it.

The goal is simple. Keep sensitive information private during the trip and in storage. That helps protect your patients, clients, and staff.

Is an encrypted email safe?

A well-designed, encrypted email is very hard to break with current tools. Attackers who grab a copy of a protected message face a huge task.

Safety still depends on the way people use the system. Weak passwords, shared accounts, and infected devices can still cause trouble. Good practice includes strong logins and updates.

Are emails encrypted by default?

Many providers use TLS between mail servers by default. That gives some protection for messages in transit.

Most services do not use full end-to-end encryption for every message without extra setup. You often need to turn on features or use a secure service. For a deeper look at this, you can read MailHippoโ€™s guide, which asks whether emails are encrypted by default.

Can encrypted emails be forwarded?

People can usually click forward on an encrypted email. The result depends on the system.

Portal-based tools often send only a link. Forwarding passes on that link, not the content. New readers still need the right login to open the message.

Someone can copy and paste the decrypted text into a new plain email. That action removes the protection. Staff training and clear rules help reduce this risk.

Read next

If you want to dig deeper into the core idea behind all of this, take a look at MailHippoโ€™s guide on what email encryption is. It explains the concept in simple terms and shows where it fits within your broader security plan.

For a closer look at the step-by-step journey of a protected message, you can read about how email encryption works. That article walks through each stage from send to receive.

If you still feel unsure about the wording around secure email, you can read “secure email vs. encrypted email.” That guide compares the two terms and helps you decide what your practice really needs.