Skip to main content
HIPAA compliance on Z360 is shared. Z360 protects patient information inside covered services. Your practice controls what information goes where, who can see it, and everything outside the covered services.

Email

Email isn’t covered by your BAA with Z360. Your mailbox, email provider, and everything sent or received by email are your practice’s responsibility. You can request a Gmail or Outlook connection only in writing from the BAA signer at your practice. Email remains outside Z360’s BAA. Your practice is responsible for the mailbox, the email provider’s BAA and safeguards, and the destination’s risk. You can ask Z360 to turn the connection off. Free personal email accounts are not offered a BAA by their providers. For health-related communication, point patients to covered channels such as calls and texts.

A quick checklist for your practice

  • Keep patient information in covered services only.
  • Treat email as outside your BAA with Z360.
  • Turn on two-factor authentication for everyone on your team.
  • Review team access regularly and remove it when someone leaves.
  • Get patient consent to record calls where your state requires it.
  • Approve the recording disclosure used before covered calls are recorded.
  • Make written requests through the BAA signer for any practice-owned mailbox, EHR, CRM, or custom connection.
  • Tell us right away if you think patient information went somewhere it shouldn’t.