Linsey Knerl | August 7, 2026

How to Send Encrypted Email for Work and Compliance

How to Send Encrypted Email

If your team sends anything covered by HIPAA, financial regulations, or a client confidentiality agreement, encrypting that email in transit isn't optional in practice, even where the rule technically gives you flexibility. This guide covers how to roll out encryption for a business: setting up certificates in Outlook, enabling S/MIME for your whole organization in Google Workspace, and what to document to stay compliant.

(For personal, single-account setup, see our companion guide: How to Encrypt Email and Send Secure Messages.)

Why Business Email Encryption Matters for Compliance

Under the HIPAA Security Rule, encrypting protected health information in transit is technically an "addressable" specification, not a flatly required one. In practice, that distinction matters less than it sounds: organizations must either implement encryption or document a risk assessment showing why an equivalent safeguard provides the same protection. For most businesses handling sensitive data over email, encryption is the straightforward way to satisfy that requirement rather than build and defend an alternative. Regulations like GLBA for financial data and various state breach-notification laws carry similar expectations. If you work with a third-party encryption vendor and handle protected health information, you'll also need a signed Business Associate Agreement (BAA) with that vendor.

None of this requires a large IT budget. Most of what's below uses tools your organization likely already has.

Choosing the Right Setup for Your Organization

  • Already on Microsoft 365®? Microsoft 365 Message Encryption is the fastest path for licensed users and needs no per-user certificate exchange.
  • Already on Google Workspace™? Hosted S/MIME gives you the strongest encryption, but it requires an administrator to enable it and issue certificates.
  • Mixed environment, or need a signed BAA with your provider? A third-party encryption gateway (see below) can layer on top of either platform.
  • Need signed, verifiable messages, not just encrypted ones? S/MIME certificates in Outlook® give you both encryption and a digital signature.

Setting Up S/MIME in Outlook

For a small team or an individual who needs a digital certificate, here's the manual process:

Create a digital ID

  1. In Outlook, go to File > Options > Trust Center > Trust Center Settings.
  2. Select Email Security, then "Get a Digital ID."
  3. Choose a certification authority. Most are comparably rated for this purpose.
  4. You'll receive an email containing your digital certificate.
  5. Back in Outlook, go to Options > the Security tab, and enter a name in the Security Settings Name field.
  6. Confirm S/MIME is selected under Secure Message Format and that Default Security Settings is checked.
  7. Under Certificates and Algorithms, select Choose next to Signing Certificate.
  8. Check the box next to Secure Email Certificate and next to "Send These Certificates with Signed Messages."
  9. Select OK to save.

Encrypt outgoing messages by default

  1. Go to File > Options > Trust Center > Trust Center Settings.
  2. Under Email Security, select Encrypted email.
  3. Check "Encrypt contents and attachments for outgoing messages."

Recipients need your digital ID on file to decrypt what you send, so exchange a signed message with a contact before relying on encryption for that thread.

At scale: rather than walking every employee through this manually, IT can deploy certificates fleet-wide through your device management platform (Intune, Jamf, or similar), which is the more realistic path for anything beyond a handful of users.

Enabling Hosted S/MIME in Google Workspace (Admin Setup)

This is an admin-console task, done once for your whole organization rather than per user.

  1. In the Google Admin console, go to Apps > Google Workspace > Gmail > User settings.
  2. Toggle on S/MIME encryption for sending and receiving, and save. Changes can take up to 24 hours to apply.
  3. Add S/MIME certificates using either the Gmail S/MIME API (recommended for admins managing certificates centrally) or by letting individual users upload their own certificates under Gmail settings.
  4. Have users reload Gmail. A lock icon will appear next to the subject line; green means the message is protected by hosted S/MIME.

Using Microsoft 365 Message Encryption

For licensed Microsoft 365 users, this is the lower-effort option and doesn't require certificate exchange between sender and recipient. In an email, select Options, then Encrypt, and choose a restriction level such as Encrypt-Only or Do Not Forward.

When to Bring In a Third-Party Encryption Gateway

If your organization spans multiple email platforms, works with external partners on varying systems, or needs a signed BAA from a vendor, a dedicated encryption gateway can be simpler to manage than coordinating S/MIME certificates across every recipient. Look for a vendor that explicitly offers a BAA if you're handling protected health information, supports your existing platform (Microsoft 365 or Google Workspace), and gives you centralized policy controls rather than relying on each employee to remember to encrypt manually.

Building Encryption Into Your Compliance Program

Setting up the technology is only part of the requirement. To stand behind your approach if it's ever reviewed:

  • Document the risk assessment behind your encryption decision, including why you chose your specific method.
  • Keep signed BAAs on file with any vendor that transmits or stores regulated data on your behalf.
  • Train employees on when encryption is required and how to verify it's active before sending sensitive data.
  • Revisit your setup periodically. Addressable doesn't mean set-and-forget.

Next Steps

For platform-by-platform personal setup instructions, including Gmail and iOS, see How to Encrypt Email and Send Secure Messages. If you're outfitting your team with hardware built for regulated environments, browse HP business laptops with built-in security features.

About the Author

Linsey Knerl is a contributing writer for HP Tech Takes. Linsey is a Midwest-based author, public speaker, and member of the ASJA. She has a passion for helping consumers and small business owners do more with their resources via the latest tech solutions.

Disclosure: