The short answer to that user's question is no, at least not in a way that meets HIPAA's requirements. And if you work in healthcare, that's not a detail you can afford to fudge.
The question itself is telling. Someone is sitting at a desk with a list of patient email addresses, a Word document, and a deadline. They know the rules about protected health information. What they do not have is a clear, compliant path from their spreadsheet to their outbox. The classic mail merge between Excel and Outlook sends emails through a local client, which means those messages travel without encryption, without an audit trail, and without the access controls that HIPAA demands. One misdirected BCC field, one cached address in autocomplete, and you have a breach.
This is not about the user being careless. It is about the tools they are using. Excel and Word were built for a world where data lived on a local drive and email was a simple text delivery. That world is gone. Healthcare workflows now require that every transmission of patient data be logged, encrypted, and restricted to authorized recipients. A mail merge from a desktop client does not provide any of that. The user is asking the wrong question, not because they are uninformed, but because the legacy tooling has trained them to think inside its limits.
What this means in practice is that healthcare professionals need a different approach. Instead of asking whether Excel and Word *can* do a mail merge, the better question is what system can send those emails while keeping the data protected. Several secure email platforms offer bulk-send features with HIPAA-compliant encryption, recipient verification, and delivery logs. Some integrate directly with spreadsheet data, allowing you to import your list, flag entries marked "No entries," and send only to the approved recipients. The workflow is similar, but the compliance layer is built in from the start.
The user's underlying need is straightforward: send the right messages to the right patients without exposing their information. That is a solvable problem. But solving it requires stepping away from the desktop merge and toward a platform that treats security as a feature, not an afterthought. For anyone in healthcare, the path forward is not a better mail merge. It is a better system.