Arrow Up to go to top of page
Hero Image for Lob Deep Dives Blog PostWhy Lob is the best direct mail platform for healthcare complianceDirect Mail Q&A's
Direct Mail
August 7, 2026

Why Lob is the best direct mail platform for healthcare compliance

Share this post
Tags
No tags found.

Healthcare direct mail often contains sensitive patient information and supports important communications, from billing statements and explanation of benefits documents to appointment reminders and required notices.

That makes security and compliance part of the workflow from the beginning. Patient data must remain protected as it moves from internal systems through mail creation, printing, and delivery.

Lob helps healthcare teams automate direct mail while supporting HIPAA requirements, protecting sensitive data, and providing visibility into individual mailpieces.

What makes a direct mail platform HIPAA compliant?

A direct mail platform that creates, receives, maintains, or transmits protected health information on behalf of a healthcare organization may be considered a business associate under HIPAA.

Healthcare organizations should evaluate the complete mail workflow, not only the software used to upload a file.

Important requirements include:

  • Business Associate Agreement: A BAA defines how the vendor may use protected health information and the safeguards it must maintain.
  • Secure data transfer: Patient data should be protected while moving between healthcare systems, the mail platform, and production facilities.
  • Data protection: Sensitive information should remain protected while stored and processed.
  • Access controls: Only authorized users should be able to view patient data, manage templates, or approve mailings.
  • Audit records: Teams should be able to review relevant account activity, campaign records, and data-handling practices.
  • Subprocessor controls: Organizations should understand which production partners and subprocessors may handle protected information.
  • Appropriate mail formats: Sensitive information should be enclosed rather than exposed on an open mailpiece.

A secure platform connection does not protect patient data if the information is later transferred to an uncontrolled print workflow. Every organization involved in producing the mail must follow the appropriate safeguards.

A strong HIPAA-compliant direct mail workflow protects information throughout the entire process, not only when the data first enters the platform.

How Lob supports HIPAA and SOC 2 requirements

Lob undergoes annual third-party audits for SOC 2 Type 2 and HIPAA compliance. These assessments review the controls used to protect customer information and operate secure workflows over time.

HIPAA support for healthcare mail

Lob maintains dedicated processes and production facilities for customers that need to send HIPAA-compliant mail containing protected health information.

Healthcare teams should work with Lob to confirm that their account, selected mail format, production workflow, and intended use are configured appropriately before sending PHI.

SOC 2 Type 2 controls

SOC 2 Type 2 assesses how an organization’s controls operate over a defined period.

For healthcare teams, this provides additional information about how a platform manages areas such as security, availability, confidentiality, access, and operational controls.

Independent assessments should be considered alongside the healthcare organization’s own vendor review, risk analysis, and legal requirements.

How Lob handles Business Associate Agreements

A Business Associate Agreement establishes how a vendor may use and disclose PHI and what safeguards it must maintain.

Lob supports BAAs for healthcare customers whose workflows require one. The agreement should be completed before protected health information is submitted to the platform.

Healthcare teams should confirm:

  • Which Lob products and services are covered
  • Which mail formats support HIPAA-compliant workflows
  • How patient information will be transferred
  • Which subprocessors may handle PHI
  • How data is retained and deleted
  • How security incidents are reported
  • What responsibilities remain with the healthcare organization

A BAA does not make every campaign automatically compliant. The healthcare organization still needs to configure the workflow correctly, limit the information included, select an appropriate format, and manage user access.

The right healthcare direct mail platform should make security documentation and BAA information available during the vendor review process.

How Lob protects PHI through the mail workflow

Healthcare direct mail can create risk at several stages, including data transfer, template creation, printing, and storage.

Lob supports secure workflows that reduce unnecessary manual handling and help teams maintain greater control over patient information.

Secure data transfer

Lob protects data in transit and at rest.

Healthcare teams can use Lob’s API and other supported workflows instead of emailing spreadsheets or transferring patient lists through uncontrolled processes.

Reducing manual file handoffs limits the number of people and systems that interact with PHI.

Access controls

Access controls help healthcare organizations limit who can manage patient mail.

Teams should assign permissions based on each person’s responsibilities. A user who reviews campaign reporting may not need the same access as someone who manages templates or integrations.

Internal controls should also determine who can:

  • Upload or transmit patient data
  • Edit templates
  • Approve healthcare mail
  • Launch sends
  • View campaign records
  • Access tracking information

Secure print production

Lob uses dedicated HIPAA-compliant processes and facilities for qualifying healthcare mail.

Healthcare teams should confirm that the selected product and format are supported before launching the workflow. Protected health information should not be exposed on postcards, self-mailers, or other open formats.

Lob recommends sealed letters for mail that contains PHI.

Data retention

Healthcare organizations should understand how long patient information remains available and whether retention settings align with their own privacy and recordkeeping policies.

Keeping only the information needed for the appropriate period can reduce unnecessary exposure while preserving required documentation.

How Lob tracks healthcare mailpieces

Healthcare teams need more visibility than a single confirmation that a batch was transferred to a printer.

Lob provides piece-level production and postal tracking events that help teams follow individual mailpieces through the workflow.

Depending on the mail format and available postal data, events may indicate when a piece:

  • Is created
  • Enters production
  • Completes production
  • Enters the postal network
  • Moves through postal processing
  • Reaches its expected delivery stage
  • Is rerouted or returned

This information can appear in Lob and flow into connected systems through APIs or webhooks.

Postal events are valuable operational signals, but they should not automatically be treated as legal proof that a specific person received or opened a mailpiece. Healthcare organizations should determine what documentation is required for each communication.

How Lob supports healthcare direct mail

FeatureLobPostGridStannpLegacy Mail Houses
Individual piece trackingYesLimitedYesRarely
BAA includedYesYesYesVaries
API-first automationYesYesLimitedNo
SOC 2 Type IIYesCheckCheckRarely
CRM/EHR integrationsNativeLimitedLimitedManual

‍

Healthcare teams should evaluate a platform based on its complete workflow rather than relying on a general claim of HIPAA compliance.

Important capabilities include:

  • Support for Business Associate Agreements
  • Third-party security assessments
  • Dedicated healthcare mail workflows
  • Secure data transfer
  • Controlled print production
  • Appropriate mail-format restrictions
  • Piece-level tracking events
  • APIs and automated workflows
  • Access controls
  • Data-retention controls
  • Address verification
  • Production redundancy

Lob brings these capabilities into one platform, helping healthcare teams manage mail creation, production, delivery visibility, and automation without relying on fragmented manual processes.

How Lob connects with healthcare systems

Healthcare organizations often manage patient information across several internal systems.

Lob’s API, webhooks, and supported integrations allow teams to connect direct mail to the systems they already use without manually exporting a new patient list for every send.

Healthcare teams can trigger mail based on events such as:

  • A patient schedules an appointment
  • A claim or statement becomes available
  • A member completes enrollment
  • A payment becomes overdue
  • A renewal period begins
  • A patient misses an appointment
  • An account status changes
  • A required notice becomes due

The connected system sends the required information to Lob, which creates and sends the mailpiece based on the approved template and workflow.

An automated healthcare direct mail program can reduce manual handling while giving teams more consistent records for each send.

How to personalize healthcare mail without exposing PHI

Healthcare mail can be personalized, but teams must consider what information is visible on the outside of the mailpiece.

Sensitive patient information should be placed inside a sealed envelope. Lob does not support HIPAA-compliant mailing for postcards, self-mailers, or letter-affixed cards containing PHI.

Use sealed letters for sensitive information

Sealed letters are appropriate for communications that contain protected or account-specific information, such as:

  • Explanation of benefits documents
  • Billing statements
  • Test or treatment information
  • Insurance information
  • Account notices
  • Patient-specific instructions

Use postcards only for general communication

Postcards may be appropriate when the visible content does not disclose protected information.

For example, a general reminder asking the recipient to contact an office may be appropriate, while a postcard that identifies a diagnosis, procedure, medication, or treatment would expose sensitive information.

Healthcare organizations should have their privacy and legal teams approve postcard content and use cases.

Limit the data included

Include only the information needed to accomplish the communication’s purpose.

A mailpiece should not contain extra patient details simply because those fields are available in the source system.

Use dynamic templates carefully

Dynamic fields can personalize names, appointment information, provider details, account references, and calls to action.

Teams should test each field and conditional rule to confirm that sensitive information cannot appear in an exposed location or populate the wrong recipient’s mailpiece.

Common healthcare compliance failures

Uncontrolled file transfers

Emailing spreadsheets or transferring patient lists through unapproved systems can expose PHI and make the workflow difficult to audit.

APIs and controlled integrations reduce unnecessary manual handling.

Missing Business Associate Agreements

A BAA should be completed before a business associate creates, receives, maintains, or transmits PHI on behalf of the healthcare organization.

Healthcare teams should also understand how the vendor manages subprocessors that may access protected information.

Using the wrong mail format

A technically secure workflow can still expose PHI if sensitive content is printed on a postcard or another visible format.

Match the format to the sensitivity of the communication.

Excessive access

Giving every team member broad access to patient data increases risk.

Permissions should reflect each user’s role and be reviewed regularly.

Including unnecessary PHI

Templates should include only the patient information necessary for the communication.

This reduces exposure and makes the workflow easier to review.

Weak template testing

Incorrect merge fields, conditional logic, or address mapping can send information to the wrong recipient.

Test templates with multiple data scenarios before launching a healthcare mail program.

Unclear data-retention practices

Healthcare teams should understand how long data and campaign records remain stored and configure retention according to organizational requirements.

Treating postal scans as guaranteed receipt

Postal events can indicate movement through the mailstream and expected delivery, but they do not necessarily prove that the intended recipient personally received or opened the piece.

Use tracking information according to the documentation requirements of the specific communication.

Build compliant healthcare direct mail workflows with Lob

Healthcare direct mail requires more than secure software. Teams need controls that extend from the original patient data through template creation, print production, delivery tracking, and retention.

Lob helps healthcare organizations bring these stages together through secure data handling, qualifying HIPAA-compliant mail workflows, BAAs, automated integrations, controlled production, and piece-level tracking.

Book a demo to discuss your healthcare direct mail requirements and confirm the appropriate Lob configuration for your use case.

Frequently asked questions about HIPAA compliant direct mail with Lob

FAQs

Is Lob HIPAA compliant?

Lob maintains dedicated HIPAA-compliant processes and facilities and undergoes annual third-party HIPAA compliance audits.

Healthcare customers should work with Lob to confirm that their account, mail format, and workflow are configured for HIPAA-compliant mailing.

Does Lob sign Business Associate Agreements?

Lob supports Business Associate Agreements for healthcare customers whose workflows require one.

The agreement should be completed before the customer submits protected health information to Lob.

Can healthcare organizations send PHI on postcards?

Lob does not support HIPAA-compliant mailing for postcards, self-mailers, or letter-affixed cards containing PHI.

Sensitive information should be placed inside an appropriately configured sealed letter.

Can healthcare direct mail be personalized?

Yes. Healthcare mail can use dynamic fields and variable data, provided the personalization follows the organization’s privacy requirements and does not expose PHI.

Teams should limit data to what is necessary and test every template before launch.

How does Lob track healthcare mail?

Lob provides mailpiece-level production and postal events through its platform, API, and webhooks.

Available events depend on the mail format and postal data. They can help teams monitor workflows and investigate delayed or returned mail.

Does postal tracking prove that a patient received a letter?

Not necessarily. Postal events can indicate movement and expected delivery, but they do not always prove that the intended person received or opened the mailpiece.

Healthcare organizations should determine what evidence is required for each type of communication.

What should healthcare teams review before choosing a direct mail platform?

Teams should review the platform’s BAA support, third-party assessments, encryption, access controls, production facilities, mail-format restrictions, subprocessors, tracking capabilities, data retention, and integration options.

Does using Lob automatically make healthcare mail HIPAA compliant?

No. Lob provides infrastructure and qualifying workflows that support HIPAA compliance, but the healthcare organization remains responsible for its data, content, permissions, configuration, and legal obligations.

‍

Answered by:

Continue Reading