Healthcare organizations regularly mail billing statements, explanations of benefits, appointment information, care-plan documents, and other communications containing protected health information.
HIPAA permits these mailings, but organizations must apply appropriate safeguards throughout the process. That includes controlling how patient data enters the workflow, who can access it, what appears on the mailpiece, where it is sent, and which records are retained.
Understand what HIPAA allows in direct mail
Protected health information, or PHI, is individually identifiable information related to a person’s health, care, or payment for healthcare. A name or postal address becomes PHI when it is connected to that information.
Healthcare organizations can send PHI through physical mail when the use or disclosure is permitted. Examples may include:
- Billing statements
- Explanations of benefits
- Appointment reminders
- Enrollment materials
- Policy and plan notices
- Lab or prescription information
- Care-management documents
- Breach notifications
The HIPAA Privacy Rule applies to PHI in any form, including paper. The Security Rule applies to electronic PHI while patient data is stored, transmitted, or processed electronically before printing.
A compliant workflow should prevent unnecessary PHI from appearing on the envelope or through its windows. Where the minimum necessary standard applies, the communication should include only the information reasonably needed for its purpose.
No platform or vendor is officially “HIPAA-certified.” Your organization must evaluate whether a provider’s controls, agreements, facilities, and services support its specific obligations.
Put a Business Associate Agreement in place
A direct mail provider that receives patient data, creates personalized documents, or prepares mail containing PHI will generally qualify as a business associate.
A signed Business Associate Agreement should be in place before the provider receives PHI. The BAA should define:
- Permitted uses and disclosures of PHI
- Required safeguards
- Breach-reporting responsibilities
- Subcontractor requirements
- Data-retention and deletion procedures
- Responsibilities when the agreement ends
USPS is generally treated as a conduit when it only transports sealed mail and has no more than incidental access to the contents. Covered entities typically do not need a BAA with USPS for that transportation service.
Your legal and compliance teams should evaluate every vendor involved in processing, storing, printing, or preparing PHI. Do not assume that the conduit exception applies to a provider simply because it participates in the mailing process.
Choose a mailing method based on risk
HIPAA does not universally require First-Class Mail or Certified Mail for communications containing PHI. The appropriate method depends on the communication, applicable requirements, and evidence your organization needs.
Consider:
- The sensitivity of the contents
- The mailing deadline
- Whether proof of mailing is required
- Whether stronger delivery evidence is needed
- How returned mail will be handled
- Which records must be retained
- Whether another law or contract specifies a mailing method
Certified or Registered Mail may be appropriate when stronger evidence is required. First-Class Mail may fit communications that need a narrower expected delivery window.
Standard postal tracking does not prove that the intended recipient personally received or opened a document. Your organization should select the service that matches the risk and documentation requirements of each communication.
Protect PHI throughout the production workflow
The electronic data used to create physical mail needs protection while it is transmitted, stored, processed, and prepared for printing.
Look for controls such as:
- Encryption in transit and at rest
- Role-based access
- Unique user credentials
- Multifactor authentication
- Access and activity logs
- Defined data-retention periods
- Restricted production-facility access
- Secure destruction procedures
- Regular vendor and facility reviews
Once the document is printed, encryption no longer protects the physical page. Envelope design, facility security, production controls, quality checks, and careful handling become the primary safeguards.
Healthcare teams should protect PHI throughout the mailing workflow, not only while transferring files to a vendor.
Automate sends without removing oversight
Manual spreadsheets, file transfers, printing, envelope stuffing, and mailing logs create more opportunities for the wrong data or document to enter production.
Healthcare organizations can trigger mail based on events such as:
- A member enrolling
- A claim being processed
- A statement becoming available
- An appointment being scheduled
- A care gap being identified
- A payment becoming overdue
- A policy or benefit changing
- A required notice reaching its send date
Automation should still include approved templates, access controls, data validation, duplicate prevention, testing, and exception handling.
VillageCareMAX previously spent more than 300 hours each month preparing and mailing care plans. After automating its healthcare direct mail with Lob, the organization reported saving more than 4,000 hours per year.
Verify addresses before production
An address can be properly formatted and still belong to a former residence or the wrong person. Address verification should therefore be part of a broader patient-data process.
Lob’s Address Verification can standardize and evaluate postal addresses before production. It can identify many formatting, completeness, and deliverability problems, but it cannot confirm that a particular patient currently lives at the address.
Healthcare organizations should also:
- Give patients clear ways to update their addresses
- Sync approved changes across source systems
- Review returned mail before sending again
- Define when staff must confirm an address
- Prevent unverified data from overwriting trusted records
A misdirected mailpiece may require an incident assessment. The organization should evaluate the PHI involved, who received it, whether it was viewed, and whether the risk was mitigated.
Maintain records that support audits
Healthcare teams should be able to retrieve the records connected to a specific mailing without searching across email threads and spreadsheets.
Depending on the workflow, retain:
- The approved document version
- The recipient and address used
- Approval history
- Order-submission time
- Production milestones
- Proof of mailing when available
- Postal tracking events
- Returned-mail information
- Correction or reissue records
Lob Enterprise customers can access a per-letter proof-of-mailing event showing the confirmed date and time of USPS handoff. This record may support an audit trail, but it is not proof that the intended recipient personally received the mail.
Legal, privacy, compliance, and records-management teams should define which records must be retained and for how long.
Prepare for returned and misdirected mail
A HIPAA-compliant workflow also needs a documented exception process.
For returned or misdirected mail, record:
- The affected mailpiece
- The address used
- The return or exception reason
- When the issue was identified
- Whether PHI may have been exposed
- Which team reviewed the event
- How the address was corrected
- Whether the communication was reissued
- The final resolution
If PHI reaches the wrong recipient, follow your organization’s incident-response and breach-assessment process. Not every impermissible disclosure is treated identically, so trained privacy and legal personnel should evaluate the circumstances.
Choose a provider that supports HIPAA workflows
A direct mail provider should be able to explain exactly how it handles PHI. Broad compliance claims are not enough.
When evaluating a secure direct mail provider, look for:
- A BAA for qualifying healthcare workflows
- Encryption for electronic PHI in transit and at rest
- Documented access controls and logs
- Defined data-retention and deletion practices
- Vetted production facilities
- Secure physical production processes
- Address verification
- Individual mailpiece records
- Incident-response procedures
- Current security and compliance assessments
Lob’s security and compliance program includes Business Associate Agreements, HIPAA/HITECH privacy audits, encryption, data-retention controls, and regular reviews of its printer network.
These capabilities can support your compliance program. They do not make every template, data transfer, mailing decision, or customer workflow automatically compliant.
Automate HIPAA-compliant mail with Lob
HIPAA-compliant mail requires secure data handling, controlled production, accurate recipient information, documented workflows, and a clear response when something goes wrong.
Lob helps healthcare organizations automate physical mail while supporting BAAs, secure data handling, address processing, production controls, and mailpiece-level records.
Book a demo to discuss your healthcare direct mail requirements.
Frequently asked questions about HIPAA-compliant mail
FAQs
Is physical mail allowed under HIPAA?
Yes. Covered entities and business associates can send PHI through physical mail when the use or disclosure is permitted and appropriate safeguards are applied.
Does HIPAA require First-Class or Certified Mail?
No. HIPAA does not universally require a particular USPS mail class or service. Organizations should select a method based on risk, evidence requirements, and any other applicable laws or contracts.
Can PHI be included in a mailed document?
Yes. PHI can be mailed when its use or disclosure is permitted. Organizations should limit the information where required and prevent unnecessary PHI from appearing on the exterior.
Does a direct mail provider need a BAA?
A provider that handles PHI on behalf of a covered entity will generally qualify as a business associate and should sign a BAA before receiving the information.
Does USPS need a BAA?
Generally, no. USPS typically falls under HIPAA’s conduit exception when it only transports sealed mail and has no more than incidental access to PHI.
Does address verification guarantee delivery to the correct patient?
No. Address verification can identify postal-data problems, but it cannot confirm who currently lives at an address or who opens the mail.







