Trust & Compliance / HIPAA
HIPAA compliance for PHI in email, files and data transfer.
The HIPAA Security Rule requires covered entities and business associates to protect the confidentiality, integrity and availability of electronic protected health information (ePHI). XQ encrypts PHI in email, files, forms and data transfer, controls who can open it and from where, and logs every access — inside and outside your organization.
Built for Healthcare providers and health systems · Health plans and business associates · Digital health and patient-app builders
At a glance
RuleHIPAA Security Rule, 45 CFR § 164.312
ProtectsPHI in email, chat, forms, files and transfers
Share withPatients, partners and other providers
EvidencePer-object access logs, SIEM integration
Works with Gmail · Outlook · iOS · Android · AWS · Azure · Google Cloud · Splunk
Share PHI without friction
Patients and partners open protected messages and files after authenticating, in the tools they already use.
Know who opened what
Every access to PHI is logged by person, time and place.
Revoke access instantly
Pull back PHI sent to the wrong person — even after delivery.
What the HIPAA Security Rule requires
The Security Rule (45 CFR Part 164, Subpart C) sets administrative, physical and technical safeguards for ePHI. The technical safeguards in § 164.312 are where most data-protection decisions land — and where PHI shared with patients, partners and other providers is hardest to control.
How XQ maps to the technical safeguards
| Technical safeguard | How XQ helps |
|---|---|
| Access control — § 164.312(a) | Each message, file and record is encrypted with its own key, released only to authorized users under policy; access can be revoked or expired at any time. |
| Audit controls — § 164.312(b) | Every access attempt is logged with who, when and where, and can be sent to your SIEM to speed threat remediation. |
| Integrity — § 164.312(c) | Protected objects carry a signed chain of custody, so you can show PHI was not altered or accessed outside policy. |
| Person or entity authentication — § 164.312(d) | Recipients authenticate before a key is released, including when PHI is shared with patients or outside organizations. |
| Transmission security — § 164.312(e) | PHI stays encrypted end to end in email, chat, forms and site-to-site or on-premises to cloud transfers. |
Need a HIPAA workflow review for email, forms or data transfer?
Where XQ protects PHI
- Send and receive HIPAA-compliant email and attachments from Gmail, Outlook and mobile devices.
- End-to-end encrypted chat with staff and directly with patients and clients.
- Secure web forms for intake of sensitive information on your website.
- Protected file exchange and collaboration with partners, without trusting their environment.
- Patient-management and custom applications, through SDKs.
- Data loss prevention rules from the edge to the cloud.
Related resources and articles
- AI Governance solutions for healthcare data
- Trust & Compliance overview
- Loss of Chain of Custody in Healthcare Imaging Data: Impacts and Solutions
- How Zero Trust Data Protects Patient & Sensitive Data in AI for Healthcare
- Healthcare CISOs’ Ransomware Extortion Crisis
- Effortless Compliance: Mastering Healthcare Data ‘Right to Be Forgotten’ in Cloud Backups
FAQ
HIPAA, answered directly.
Is email encrypted with XQ HIPAA compliant?
XQ provides the technical safeguards HIPAA calls for when email carries PHI — end-to-end encryption, access control, recipient authentication and an audit trail — from Gmail, Outlook and mobile devices. Compliance also depends on your policies and agreements.
Can we share PHI securely with patients?
Yes. Patients receive protected messages and files they can open after authenticating, and you can revoke or expire their access at any time.
Does XQ sign Business Associate Agreements?
Ask our team about a Business Associate Agreement (BAA) for your deployment.
How does XQ help after a suspected breach?
Because every access is logged per object, you can see exactly who opened which PHI and when, and revoke access to affected data immediately — even data that has already left your systems.
Can XQ protect PHI moving from on-premises systems to the cloud?
Yes. PHI is encrypted before it leaves your site and stays encrypted in transit and in cloud storage, with keys and policies that are not tied to the cloud environment and every access logged. That supports EMR backup and migration to clouds such as AWS.
Protect PHI everywhere it travels.
Talk to our team about HIPAA-compliant email, file sharing and data transfer in your current tools.