Email remains the main way attackers reach healthcare organizations, whether through phishing, fake invoices or account takeovers. The good news is that several of the most effective protections are settings you can turn on in the platforms you already use, such as Microsoft 365 or Google Workspace. Here is a list worth reviewing with your IT provider this week.
A stolen email password is a gateway to resident information, password resets for other systems and convincing fraud against your staff and vendors. Require multifactor authentication for every mailbox, beginning with administrators and leadership. If you do only one thing from this list, make it this.
Older email protocols do not support multifactor authentication and are commonly abused in password attacks. Disable legacy authentication unless an application truly requires it, and if one does, plan to replace it.
These three DNS-based records help prove that messages claiming to come from your domain really did, and help receiving servers reject forgeries.
SPF lists the servers allowed to send mail for your domain.
DKIM adds a digital signature to outgoing messages.
DMARC tells receivers what to do with messages that fail the checks and sends you reports.
Start DMARC in monitoring mode, review the reports to find legitimate senders you forgot, such as billing or marketing services, then move gradually to a stricter policy. A properly configured domain is harder to impersonate, which protects residents, families and vendors from scams that use your name.
Most platforms include features that scan attachments and links for malicious content. Enable safe attachment and safe link protections where your license supports them. Quarantine messages that are likely phishing instead of delivering them with a warning.
Add a visible banner or subject tag to messages from outside your organization. A fake message from the administrator is more likely to be noticed if it carries a warning label, saying that it came from outside.
Attackers who take over a mailbox often create a hidden rule that forwards copies of messages to an outside address. Block automatic external forwarding by default, and review mailbox rules regularly. This also helps keep PHI from leaving your control through well-meaning forwarding to personal accounts.
Check who can share files outside your organization and whether links can be opened by anyone. Limit anonymous sharing and set expiration dates where possible.
Shared mailboxes such as admissions or billing are often forgotten. Make sure they have restricted membership, no direct sign-in with shared passwords and logging enabled.
Turn on audit logging, and set alerts for suspicious activity such as sign-ins from unusual countries, impossible travel, mass deletion or new forwarding rules. Logs are only useful if someone reviews them, so decide who receives alerts.
HIPAA does not prohibit emailing PHI, but the Security Rule expects safeguards for transmission. Offer a secure way to send messages that contain resident information, such as policy-based encryption or a secure portal, and train staff on when to use it. Combine this with data loss prevention rules that warn when an email appears to contain sensitive identifiers.
Even good defenses can fail. Document how to respond if an account is taken over: reset the password, revoke active sessions, remove suspicious rules, review recent activity and determine whether PHI was exposed. Assign a person to decide whether the incident is reportable under HIPAA.
A small organization might spend a week on this list: multifactor authentication and legacy blocking on day one, filtering and external banners on day two, forwarding and sharing restrictions on day three, and DNS records and logging after that. Record each change and the date.
UnityCare IT configures and monitors email security for healthcare organizations, including DMARC rollout and staff training. If you would like a review of your current settings, we can walk through them with you.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172