Email remains the front door for most cyber incidents in healthcare. Phishing messages arrive there, invoice fraud happens there, and a compromised mailbox often contains years of resident information, financial details and contacts. The good news is that a handful of settings, most of them free with your existing email platform, make a meaningful difference.
Here is a checklist you can review with your IT provider this week.
Not just administrators. A stolen password should not be enough to read email.
Older protocols, such as basic authentication for POP, IMAP or SMTP, cannot use MFA and are often targeted. Block them unless a specific, documented need exists.
Keep the number of global administrators small, use separate admin accounts and review them regularly.
If your platform supports it, restrict sign-ins from unexpected countries, flag impossible travel and require compliant devices for sensitive access.
Three DNS records help prevent others from impersonating your domain and help receiving servers trust your messages.
SPF lists which servers may send email for your domain.
DKIM adds a digital signature to outgoing messages.
DMARC tells receivers what to do when messages fail checks, and sends you reports.
Start DMARC in monitoring mode, review reports to ensure all legitimate senders, such as your newsletter service and billing system, are included, then move gradually toward enforcement. A misconfigured DMARC policy can block legitimate mail, so make changes carefully.
Enable anti-phishing and anti-malware protection, with attachment scanning
Turn on link protection that checks URLs when clicked
Add a visible banner to messages that come from outside the organization
Block risky file types, such as executables and certain macro-enabled documents, where practical
Add warnings or quarantine for look-alike domains and display-name impersonation of executives
Attackers who gain access often create hidden rules that forward email externally or delete security alerts.
Disable automatic external forwarding, or require approval
Alert administrators when new forwarding rules are created
Periodically review mailbox rules for key staff such as finance and administrators
Review sign-in logs for unusual activity
Email is not automatically secure for PHI. Consider:
Encryption for messages containing PHI, using a tool that is easy for recipients
Policies for what may be sent by email and what must use a secure portal
Data loss prevention rules that detect patterns such as Social Security numbers
Retention settings that align with legal requirements and your records policy
HIPAA does not forbid email with PHI, but the Security Rule expects you to assess risks and apply appropriate safeguards, and individuals can request unencrypted email after being warned of risks.
Business email compromise targets finance staff by impersonating vendors or executives. Require a phone call to a known number before changing payment details, require dual approval for large payments, and teach staff to be wary of urgent requests.
Install a report-phishing button if your platform offers one, and tell staff what happens next. Quick feedback encourages continued reporting.
Cloud email providers protect their service, but typically do not guarantee recovery of messages deleted by users or attackers beyond retention periods. A third-party backup may be worthwhile for key mailboxes.
MFA on all accounts
Legacy authentication disabled
SPF, DKIM and DMARC configured
External forwarding restricted
Anti-phishing policies enabled
External sender banner in place
Admin accounts reviewed
Staff know how to report
UnityCare IT can review your email configuration, identify gaps and implement fixes with minimal disruption. If you are not sure whether your domain has DMARC or whether staff can forward mail to personal accounts, we can check in a short conversation.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172