Virtual Mailbox
May 31, 2023

Is Earth Class Mail HIPAA Compliant?

Thatch is a HIPAA compliant virtual mailbox service with locations in CA, TX, IL and PA. We have looked through the landscape of other virtual mailbox providers to see if any other companies can also provide these services.

Earth Class Mail is one of the first and largest virtual mailbox companies, so we decided to look into their HIPAA program to see if it works for all healthcare companies.

As healthcare is split between outdated laws and regulations and technology adoption interest in HIPAA compliance is becoming more and more important.

There are a lot of considerations when selecting partners for HIPAA compliance and we hope to break down a compliance overview of Earth Class Mail

What is Earth Class Mail?

Earth Class Mail manages postal mail online.

It was founded in 2004 and have worked with thousands of companies like Zapier, Reddit, and Lyft. They are helping companies go paperless and bring efficiencies to their operations.

What is a Business Associate?

A Business Associate is a person or company that performs certain functions or activities that involve the use or disclosure of protected health information (PHI) for a Covered Entity. A business associate is any person or entity that works with Covered Entities to help them in the course of business but not a direct employee to the Covered Entity.

Business Associate Agreement

If a Business Associate provides services to a Covered Entity, then a Business Associate Agreement (BAA) must be in place to ensure that PHI is protected properly. A BAA is a written contract between a Covered Entity and a Business Associate and is required by law for HIPAA compliance.

Earth Class Mail and the Business Associate Agreement

We checked the Earth Class Mail site for mention of their ability to sign a Business Associate Agreement (BAA). We found the following information on their terms of services page.

On that page, we can see that Earth Class Mail does not currently sign a BAA with its customers without prior consent.

Notify us of HIPAA coverage. If you are a covered entity or business associate under the Health Insurance Portability and Accountability Act, (“HIPAA”), you may not use our Services to receive or process mail that includes “protected health information” (PHI) as defined in HIPAA unless you have notified ECM in advance and ECM consents to process PHI on your behalf.

In further research Earth Class Mail has 80 processing facilities which are not owned by the company. They are PO Boxes and Retail mail centers that are unable to comply with all HIPAA requirements.

Is Earth Class Mail HIPAA compliant?

The BAA is a key component of HIPAA compliance between a covered entity and a business associate. In conversations with Earth Class Mail they currently won't sign a BAA. When using Earth Class Mail in a healthcare context, you can use it to receive mail, but opening and scanning would be prohibited without a BAA.

Ultimately, Earth Class Mail may not be HIPAA compliant, and it's important to be careful about using them if you'll be storing or transmitting PHI.

Conclusion: Earth Class Mail may not be HIPAA compliant.

Start For Free. Begin Your Next Business Chapter

Free 30 day trial  •  No set-up costs  •  Cancel anytime

Continue reading