Email Security Settings Every Facility Should Check Today

Email remains the front door for most cyber incidents in healthcare. Phishing messages arrive there, invoice fraud happens there, and a compromised mailbox often contains years of resident information, financial details and contacts. The good news is that a handful of settings, most of them free with your existing email platform, make a meaningful difference.

Here is a checklist you can review with your IT provider this week.

Protect Sign-In

Require multifactor authentication for every mailbox

Not just administrators. A stolen password should not be enough to read email.

Disable legacy authentication

Older protocols, such as basic authentication for POP, IMAP or SMTP, cannot use MFA and are often targeted. Block them unless a specific, documented need exists.

Review who has administrator rights

Keep the number of global administrators small, use separate admin accounts and review them regularly.

Use conditional access

If your platform supports it, restrict sign-ins from unexpected countries, flag impossible travel and require compliant devices for sensitive access.

Authenticate Your Domain

Three DNS records help prevent others from impersonating your domain and help receiving servers trust your messages.

SPF lists which servers may send email for your domain.

DKIM adds a digital signature to outgoing messages.

DMARC tells receivers what to do when messages fail checks, and sends you reports.

Start DMARC in monitoring mode, review reports to ensure all legitimate senders, such as your newsletter service and billing system, are included, then move gradually toward enforcement. A misconfigured DMARC policy can block legitimate mail, so make changes carefully.

Filter Incoming Mail

Enable anti-phishing and anti-malware protection, with attachment scanning

Turn on link protection that checks URLs when clicked

Add a visible banner to messages that come from outside the organization

Block risky file types, such as executables and certain macro-enabled documents, where practical

Add warnings or quarantine for look-alike domains and display-name impersonation of executives

Watch for Mailbox Abuse

Attackers who gain access often create hidden rules that forward email externally or delete security alerts.

Disable automatic external forwarding, or require approval

Alert administrators when new forwarding rules are created

Periodically review mailbox rules for key staff such as finance and administrators

Review sign-in logs for unusual activity

Protect Sensitive Content

Email is not automatically secure for PHI. Consider:

Encryption for messages containing PHI, using a tool that is easy for recipients

Policies for what may be sent by email and what must use a secure portal

Data loss prevention rules that detect patterns such as Social Security numbers

Retention settings that align with legal requirements and your records policy

HIPAA does not forbid email with PHI, but the Security Rule expects you to assess risks and apply appropriate safeguards, and individuals can request unencrypted email after being warned of risks.

Defend Against Invoice and Wire Fraud

Business email compromise targets finance staff by impersonating vendors or executives. Require a phone call to a known number before changing payment details, require dual approval for large payments, and teach staff to be wary of urgent requests.

Help Staff Report

Install a report-phishing button if your platform offers one, and tell staff what happens next. Quick feedback encourages continued reporting.

Back Up Mailboxes

Cloud email providers protect their service, but typically do not guarantee recovery of messages deleted by users or attackers beyond retention periods. A third-party backup may be worthwhile for key mailboxes.

Quick Checklist

MFA on all accounts

Legacy authentication disabled

SPF, DKIM and DMARC configured

External forwarding restricted

Anti-phishing policies enabled

External sender banner in place

Admin accounts reviewed

Staff know how to report

Get a Review

UnityCare IT can review your email configuration, identify gaps and implement fixes with minimal disruption. If you are not sure whether your domain has DMARC or whether staff can forward mail to personal accounts, we can check in a short conversation.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172