HIPAA-compliant file sharing

Make HIPAA-compliant file sharing easier.

SendThisFile Business helps medical offices share patient files with patients, providers, and partners while maintaining HIPAA-compliant file-sharing practices. Protect files during transfer and temporary storage, verify recipients, limit how long files remain available, check download activity, and request our standard Business Associate Agreement.

File-sharing controls

How SendThisFile helps protect patient file sharing

Files in transit

Files are encrypted while they travel between the user's browser and SendThisFile, and while temporarily stored awaiting download.

Recipient access

Business can require recipient verification and a separate download password.

Availability

Business applies a 30-day availability window, and the sender can end access sooner in Activity.

Visible outcome

Activity shows the transfer, whether the recipient downloaded it, and when access is scheduled to end.

A simple SendThisFile workflow

Send, protect, and check the outcome.

Terms your office may use

HIPAA file-sharing terms, in plain language

HIPAA
The U.S. health privacy and security law framework.
ePHI
Patient information kept or sent electronically.
BAA
A Business Associate Agreement is a written agreement that may be required when another company handles ePHI for a covered organization.

Your office's process

Use SendThisFile within your office's HIPAA process.

Your office decides who may send and receive patient files, which protections are required, and what to do if something goes wrong. Use the Business account, BAA, settings, and work process your office has established for ePHI.

Before your office sends patient files

  1. Use the SendThisFile Business account your office has set up for ePHI.

  2. Confirm that your office has the BAA it requires.

  3. Review the recipient's address before adding files.

  4. Add only the patient files your office intends to share.

  5. Turn on the recipient protections required for the transfer.

  6. Know when access is scheduled to end and end it sooner when needed.

  7. After sending, check Activity for the transfer and download outcome.

For the approver

What your privacy or IT approver can review

SendThisFile encrypts files while they travel between the user's browser and SendThisFile, and while they are temporarily stored awaiting download.

  • Recipient verification and download-password availability.
  • Business availability and earlier access expiration.
  • Transfer, download, and scheduled-access status in Activity.
  • Organization activity export for Business administrators with appropriate access.
  • Business eligibility and the monitored manual BAA process.

Common questions

Questions for staff and approvers

How does SendThisFile help with HIPAA-compliant file sharing?

SendThisFile Business combines encrypted transfer and temporary storage, recipient protections, scheduled availability, Activity, and access to our standard BAA. These controls help medical offices maintain HIPAA-compliant file-sharing practices.

Which SendThisFile plan should we use for ePHI?

Use Business with the BAA and settings required by your office. Free and Standard are not approved by SendThisFile for sending ePHI. Fullstack supports a separate tailored agreement path.

How do we request a Business BAA?

Email legal@sendthisfile.com. Our legal team confirms that you have, or are purchasing, Business and sends the current standard agreement for review and signature. SendThisFile countersigns it and returns a copy. Requested changes are handled manually.

Which recipient protections are available?

Business can require recipient verification and a separate download password. Your office decides which protections its workflow requires.

How long do Business files remain available?

Business applies a 30-day availability window. You can end access sooner in Activity.

What can I check after I send?

After sending, Activity shows the transfer, whether the recipient downloaded it, and when access is scheduled to end. Business administrators with the appropriate access can export organization activity.

What is our office responsible for?

Your office decides who may send and receive patient files, which account and protections to use, and how to respond to mistakes. SendThisFile helps with the file-sharing part of that process.

What should I do if I sent a file to the wrong recipient?

End access sooner in Activity and follow your office's incident process. Ending access does not reverse a download or access that already happened.

Ready for the Business path

Make patient file sharing easier for your office.

Use SendThisFile Business with the agreement, settings, and protections your office requires. For a tailored environment or agreement, discuss Fullstack with SendThisFile.