Email is how healthcare organizations coordinate with pharmacies, physicians, families, payers and vendors. It is also the most common way attackers try to reach your staff. A basic spam filter helps, but it is no longer enough. Modern phishing messages are well written, often come from compromised legitimate accounts and may contain no obvious malware at all.
Here are the layers that make a meaningful difference, explained for administrators who will be asking IT what is in place.
A modern email security service examines messages before they reach inboxes. Look for these capabilities:
Anti-spam and anti-malware scanning as a baseline
Attachment sandboxing, which opens suspicious files in a safe environment to see what they do
Link scanning at time of click, because attackers sometimes activate a malicious page after delivery
Impersonation protection, which flags messages that appear to come from your administrator, director of nursing or a known vendor
Detection of unusual sender behavior, such as a vendor suddenly requesting a bank account change
External sender warnings, a banner that tells staff a message came from outside the organization
Three DNS records help receiving servers decide whether a message that claims to be from your domain really is.
SPF lists which servers may send mail for your domain
DKIM adds a cryptographic signature to outgoing messages
DMARC tells receivers what to do when SPF and DKIM checks fail, and sends you reports
Many organizations publish SPF and DKIM but leave DMARC at a monitoring-only setting forever. Moving to an enforcement policy, carefully and after reviewing reports, makes it much harder for criminals to send convincing fake messages that appear to come from your domain. Your IT team should review reports first so legitimate senders, such as your newsletter or billing system, are not blocked.
Even the best filter will miss something. Make sure that when someone is fooled, the damage is limited.
Require multi-factor authentication on every mailbox
Block legacy protocols that do not support modern authentication
Alert on suspicious sign-ins, such as logins from unusual countries or impossible travel
Alert on new inbox forwarding rules, which attackers use to quietly monitor mail
Limit who can create or modify mail flow rules
HIPAA does not prohibit emailing PHI, but the Security Rule requires you to consider transmission security, and many organizations choose to encrypt. Options include:
Automatic encryption triggered by keywords or patterns, such as medical record numbers
A user-initiated encrypt button or subject-line tag
A secure portal for sending files to families and outside providers
Data loss prevention rules that warn or block when sensitive data is about to leave
Train staff on when to use these tools, and provide a simple method for recipients to open encrypted messages.
Provide a one-click report button so staff can flag suspicious messages
Establish call-back verification for any request to change payment details or send sensitive records
Define who can approve unusual requests, so a message claiming to be from the administrator cannot bypass the process
Share examples of real attempts that reached your organization
Only the main office mailboxes are protected while shared mailboxes are overlooked
Staff forward work email to personal accounts for convenience
DMARC set to monitoring only, with no one reading reports
Former employee mailboxes remain active
No archiving or retention policy, so old messages with PHI accumulate
Ask your IT provider for answers to five questions:
What email filtering do we use, and does it include link and attachment scanning?
Are SPF, DKIM and DMARC configured, and what is our DMARC policy?
Is MFA enforced on every mailbox?
Do we alert on forwarding rules and unusual sign-ins?
How do staff send PHI securely, and have they been trained on it?
UnityCare IT manages email security for healthcare organizations, including filtering, authentication records and mailbox monitoring. If you would like a quick review of your email protections, reach out and we will walk through it with you.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172