Getting your letter without undoing the safeguards
Everything protecting your record inside the service can be undone in one step at the end: sending the document to the wrong inbox. Delivery is where clinical privacy most often fails in practice, and it is the stage you control most completely.
Channel by channel
Ranked by how much can go wrong
The document never leaves a protected environment. Access requires your credentials, and the download is logged.
A short-lived link rather than an attachment. If the mailbox is later compromised, an expired link discloses nothing.
Convenient and widely used. The document then lives in your mailbox indefinitely, which is a risk you are accepting rather than one we control.
Text is not encrypted end to end across the carrier network and frequently appears on lock screens. Fine for “your letter is ready”; wrong for the letter itself.
Employer-administered email can be read by administrators lawfully and without notice. A shared household address is worse still.
You can consent to a less secure channel
HIPAA does not forbid ordinary email. A patient may request delivery by unencrypted email after being made aware of the risk, and a provider may honour that request — convenience is a legitimate thing for you to weigh.
What matters is that the choice is yours and informed, rather than a default imposed on you. If you would prefer a portal download or a secure link, ask; it costs nothing and removes the document from your mailbox entirely.
Before you nominate an address
Is it an address only you can read?
Is it administered by your employer?
Does anyone else know the password?
Is it linked to a shared family device?
Would a lock-screen preview reveal it?
Sending it on to a landlord
Send to a named person
A specific leasing manager rather than a general inbox that several staff can open.
Attach, do not paste
Pasting the text into an email body makes it trivially forwardable and strips the letterhead that establishes authenticity.
Say what it is for
One line framing it as a reasonable accommodation request creates the written record you may later need.
Keep your sent copy
The date you sent it is frequently the fact in dispute later.
Frequently asked
Is it safe to receive an ESA letter by email?
It is widely used and permitted where you have chosen it. The trade-off is that the document then lives in your mailbox indefinitely, so the security of that account becomes the security of the letter.
Can I ask for a more secure delivery method?
Yes. A portal download or a short-lived secure link keeps the document out of your mailbox entirely, and asking for it costs nothing.
Is text message delivery secure?
Not particularly. SMS is not encrypted end to end across the carrier network and commonly appears in lock-screen previews. It is suitable for notifications, not for the document itself.
Can my employer read a letter sent to my work email?
Potentially, and lawfully. Employer-administered mail systems can generally be accessed by administrators, and your employer is not bound by HIPAA. Use a personal address.
Should I paste the letter text into an email to my landlord?
No. Send it as an attachment. Pasted text loses the letterhead and signature that establish authenticity and is easier to alter or forward.
Does HIPAA require encrypted email?
It requires that the risk be assessed and addressed, not that a specific technology be used. A patient may request ordinary email having been made aware of the risk.
Your privacy is not an afterthought here
Start a free evaluation and see exactly what your landlord will — and will not — receive.
Start free evaluation All privacy topics