May I send medical/patient data by email?

Why this question is tricky
Medical data says something about someone's health, and that's exactly the kind of information you'd never want to leak. The GDPR therefore counts health data among the special-category personal data, with extra protection. An ordinary email travelling unsecured across the internet doesn't provide that extra protection by itself.
That doesn't mean email is forbidden. It means you have to take measures that match the sensitivity of the information. So the question isn't so much "is it allowed?" but "how do I do it responsibly?".
Important to know: a mistake is quickly made. A wrongly entered address, an attachment that ends up with the wrong person or an unsecured connection can already amount to a data breach. That's exactly why it pays to set up a few fixed habits and the right technical foundation in advance, so you don't have to reconsider each time whether it's all in order.
What the GDPR and professional rules require
The main rule: take appropriate technical and organisational measures, matched to the risk. For health data that bar is high. In practice it usually comes down to these points.
- Send securely. Make sure the message is protected in transit with encrypted connections, and consider extra security for the most sensitive content. Read how that works in forced TLS and encrypted connections.
- The right recipient. Check the email address carefully. A typo that delivers data to the wrong person is a data breach.
- Basis or consent. Make sure you have a valid reason to share the data, and inform the patient where appropriate.
- As little as possible. Only send what's really necessary, no more.
How exactly these rules are applied differs by profession. In Belgium you look to the code of conduct of your professional order and to the Belgian Data Protection Authority (GBA). The direction is the same for everyone, the details are not.
This article is informative and not legal advice. If you're unsure about a specific situation, consult a specialist or your professional organisation. For the broader question outside healthcare, read may I send personal data by email under the GDPR?.
How do you send medical data responsibly by email?
In practical terms, this step-by-step approach helps keep the risk small:
- Limit the content. Put no more in the message or attachment than is strictly necessary for the recipient.
- Check the recipient. Review the address and, if in doubt, confirm via another channel, especially with new contacts.
- Use a secure connection. Make sure you send and receive mail over encrypted connections (TLS).
- Secure access. Turn on two-factor authentication for your mailbox, so a stolen password isn't enough to get in.
- Follow your profession's channels. For actually exchanging records, specific, prescribed systems often apply. Use those where they're mandatory.
What this means for your email choice
The GDPR doesn't require a specific brand, but it does require a reliable, well-secured foundation. Concretely, you want email hosted in Europe and GDPR-compliant, with encrypted connections, strong access security and filtering that stops fake messages.
Mailflux delivers exactly such a foundation: professional mailboxes on your own domain, hosted in Europe and GDPR-compliant. Connections run encrypted over TLS, you optionally turn on 2FA per mailbox, and every plan includes antivirus, anti-spam, anti-malware and automatic backups. The ML-driven filtering helps against phishing that poses as a known sender, precisely the kind of mail that leads to a wrong click and a data breach.
To be honest: Mailflux is not a separately certified system for medical messaging, and it doesn't offer end-to-end encryption. It's EU-hosted, GDPR-compliant professional email that forms a strong, secure foundation. For exchanging medical records, also follow the channels your professional organisation prescribes. You'll read more about the sector context in email for healthcare, and which professions this further concerns in who Mailflux is for.
In short
Sending medical data by email is allowed, provided you do it securely, check the right recipient and have a valid basis. Unsecured email falls short for that; an EU-hosted, GDPR-compliant mailbox with encrypted connections and 2FA is a sensible foundation. For the precise rules in your situation: consult your professional organisation or a specialist.
Want to get that foundation right straight away? Request your mailbox with no obligation. We're happy to help you on your way.