OurHOA
Board & governance

Should HOA board members use personal email, and how should the board manage passwords?

By OurHOA · General information · Revised

How an HOA board should handle email, passwords, and shared accounts: association addresses, records requests, two-factor login, and handovers when directors change.

Part of the HOA board handbook: running the board.

The problem with personal email

Most small boards run on personal email. It is free and everyone already has it. It also causes three predictable problems. First, association business ends up scattered across a dozen private inboxes that nobody else can search. When a director leaves, their correspondence with vendors and owners leaves with them. Second, those emails may be association records. Florida Statutes section 720.303(4) lists the official records a Florida HOA must keep, and the list ends with all other written records of the association related to its operation. Other states define records differently, and whether a particular email must be produced depends on the statute and the content. In a lawsuit, relevant emails can be requested regardless. A director who used a personal account may end up searching it and handing over messages. Third, personal accounts are often poorly secured, and a compromised inbox can expose owner data or be used to send fake payment instructions.

Use association addresses tied to roles

The fix is to give the association its own domain or email account and create addresses by role rather than by person, such as president, treasurer, secretary, and board. When a new treasurer takes over, they get the treasurer mailbox and its history. Nothing needs to be forwarded. A shared board mailbox that several directors can read works well for owner questions, because anyone can see whether a message has been answered. Keep association business in these accounts and personal matters out of them. If directors insist on using personal email, at least ask them to copy or forward association correspondence to the association account so the record stays in one place.

Passwords and two-factor login

A small association can have more logins than it realizes. Bank accounts, the payment portal, email, the website, the domain registrar, the state corporate filing account, insurance portals, utility accounts, and any management software. Store all of them in a password manager with a shared vault that only current directors, and the manager if you have one, can open. Do not keep passwords in a spreadsheet, a group text, or the board email. Turn on two-factor authentication for every account that offers it, starting with banking and email. The federal Cybersecurity and Infrastructure Security Agency recommends multifactor authentication on all accounts that support it, because a stolen password alone is then not enough to get in. Where possible, give each director their own login with appropriate permissions instead of sharing one. Banks usually support this, and it creates a record of who did what.

Keep an account inventory

Make a single list of every account the association has. For each one, record the service, what it is used for, who has access, who the administrator is, how two-factor is set up, and the renewal date if it has one. Note which accounts are tied to a personal phone number or personal email for recovery, because those are the ones that get lost when a director leaves. The domain name deserves special attention. If the registrar account is in a former director's name, the association can lose its email and website when that person stops renewing it. Move ownership to the association and list at least two directors as contacts. Review the inventory each year and whenever the board changes. Keep the inventory itself in the password manager or another restricted location, not in the general board folder, because it is a map of everything worth attacking. Two other details are easy to miss. Payment portals and banks often send alerts to a single email address, so point those alerts to a role mailbox that more than one director reads. And if a former director's phone number is the recovery method for any account, one lost phone can lock the association out entirely. Fix that before you need it.

Handing accounts over when directors change

Plan the handover before the annual meeting, not after. Within a few days of a change on the board, remove the departing director's access to email, the password vault, bank accounts, and any other system. Change passwords on any shared credential they knew. Update recovery phone numbers and emails. Give the incoming director access to the role mailbox and the accounts they need. Update bank signature cards and online banking users through the bank's own process. Record the changes in the board's minutes or records so the next handover has a starting point. A separate guide covers handing off HOA records to a new board. Treat access changes as part of that same process. A former director with live bank access is a risk even if everyone parted on good terms.

Reply-all is not a meeting

Email is fine for sharing information and scheduling. It is a poor place to make decisions. Florida Statutes section 720.303(2)(a) says directors may use email to communicate but may not vote on association matters by email. California Civil Code section 4910 bars the board from acting outside a meeting and from holding a meeting through a series of electronic transmissions, with a narrow exception for emergencies when every director consents in writing. Other states differ, and a separate guide covers whether an HOA board can make decisions by email. The practical rule is to keep email threads to facts and logistics, and when a discussion turns into a debate about what to do, put it on the next meeting agenda.

Write your email practices down

A short email and account policy saves arguments later. It can say that association business goes through association accounts, that the password manager is the only place credentials are stored, that two-factor login is required on financial and email accounts, that access is removed within a set number of days after a director leaves, and that email is not used for board votes. Add how long the association keeps email and who can search it when a records request comes in. Adopt it by resolution at an open meeting and include it in new director orientation. Check your governing documents and state law, especially records inspection rules, before deciding what to keep and for how long.

Sources

These guides are general education for HOA boards and residents, not legal, tax, or financial advice. Rules vary by state and by your community's governing documents - check with a professional for your situation.

Leave the next board a clean record

Minutes, votes, documents and board decisions stay in one place when directors change. Free to start.