Skip to contentSkip to navigationSkip to topbar

Is SendGrid HIPAA Compliant?


No, we are not.

SendGrid does not natively support HIPAA compliant data transmission and is not a HIPAA Eligible Service(link takes you to an external page). We do not offer any encryption or security measures surrounding message transmission beyond those included in the SMTP RFC, which was not designed with HIPAA compliance in mind.

If you are concerned about sensitive personal data, you can consider encrypting the message body of your emails on your end, or offer a secure download link for secure documents rather than transmitting them directly via email. However, implementation of the above security mitigation tools does not make SendGrid a HIPAA Eligible Service.

SendGrid does not intend uses of the Service to create obligations under The Health Insurance Portability and Accountability Act of 1996 ("HIPAA") or similar laws and makes no representations that the Service satisfies the requirements of such laws. Twilio is not able to sign Business Associate Agreements for SendGrid, therefore, customers should not use SendGrid for any purpose or in any manner involving Protected Health Information (as defined in HIPAA).