Signature guide

HIPAA email disclaimer — templates and honest guidance

A HIPAA disclaimer at the bottom of every outbound email is standard practice at every healthcare organisation — but it's often confused with actual PHI protection, which requires encryption, not text. This is the plain-English guide: three tested disclaimer templates you can copy, what a disclaimer really does, and the two mistakes covered entities most commonly make.

Live example

One of ten built-in Looks. Every element is editable in the builder — colors, photo, links, tagline.

Preview
ToReferring clinic
SubjectPatient referral
Thanks, Maya
Maya Chen
Customer Success Lead · Wren
Wren
Emaya@flywithwren.com
T+1 415 555 0188
Wflywithwren.com

Step-by-step

  1. 1

    Template 1 — Standard covered-entity disclaimer

    "CONFIDENTIALITY NOTICE: This email and any attachments may contain information that is confidential and protected by federal and state privacy laws, including but not limited to the Health Insurance Portability and Accountability Act of 1996 (HIPAA). This information is intended only for the use of the individual or entity named above. If you are not the intended recipient, any dissemination, distribution, or copying of this communication is strictly prohibited. If you have received this email in error, please notify the sender immediately by reply email and delete all copies of the original message."
  2. 2

    Template 2 — Shorter, still compliant

    "This message and any attachments may contain protected health information (PHI) under HIPAA and is intended solely for the addressee. If you have received it in error, please notify the sender and delete all copies."

    Shorter disclaimers work better on mobile and don't get truncated by Gmail's "clip message" feature (which triggers around 102KB of email).
  3. 3

    Template 3 — Business associate variant

    "This email is sent by a business associate of a covered entity under HIPAA. It may contain protected health information intended only for the recipient identified above. Any unauthorised review, use, disclosure, or distribution is prohibited. If you are not the intended recipient, please notify the sender and delete this email and any attachments."
  4. 4

    Understand what the disclaimer actually does (and doesn't)

    A disclaimer is a good-faith notice. It does NOT: encrypt the email, prevent misuse by an unintended recipient, or replace the requirement to send PHI via a secure/encrypted channel. It DOES: establish that you notified recipients of confidentiality, satisfy standard-of-practice expectations, and support HIPAA's minimum-necessary and administrative-safeguards requirements. For actual PHI in an email, encryption is non-negotiable — the disclaimer sits alongside encryption, not instead of it.
  5. 5

    Deploy across every mailbox — three options

    Exchange transport rule: free, catches every send including mobile, appends at the bottom of the reply chain. Right for the disclaimer specifically. Google Workspace 'Append footer': same, native to Google Workspace. Signature manager (Exclaimer, CodeTwo, Wren): disclaimer sits inside the branded signature, correctly positioned under the sender's message. Best for readability; the two native options above are best for absolute enforcement.

Common questions

Does a HIPAA disclaimer make an email secure?
No. A disclaimer is a notice, not encryption. Sending actual PHI over unencrypted email is a HIPAA violation regardless of what the disclaimer says. Use a HIPAA-compliant email service (Paubox, Virtru, or the encryption features in Microsoft 365 / Google Workspace) for messages that contain PHI.
Is a HIPAA disclaimer legally required?
HIPAA itself does not mandate a specific disclaimer, but requires 'reasonable safeguards' against improper disclosure. Every compliance officer and healthcare attorney recommends a disclaimer as part of those safeguards. It's not optional in practice.
Where should the HIPAA disclaimer appear — under the signature or below the reply chain?
For pure compliance, below the reply chain (appended via a transport rule) is standard — it guarantees the disclaimer is on every send including mobile. For readability, inside the signature works too. Some organisations do both.
Can I use a shorter HIPAA disclaimer?
Yes — Template 2 above is roughly one-fifth the length and legally adequate. The longer version is more comprehensive; the shorter version is more likely to actually get read. Match to your organisation's risk tolerance.
How does a business associate's disclaimer differ from a covered entity's?
It names the sender as a business associate rather than a covered entity, which clarifies the legal basis for the recipient's handling obligations. If you're a BA (billing service, IT vendor, medical transcription), use Template 3.
Also useful