Email Security Settings Worth Turning On This Week

Email remains the main way attackers reach healthcare organizations, whether through phishing, fake invoices or account takeovers. The good news is that several of the most effective protections are settings you can turn on in the platforms you already use, such as Microsoft 365 or Google Workspace. Here is a list worth reviewing with your IT provider this week.

1. Require multifactor authentication

A stolen email password is a gateway to resident information, password resets for other systems and convincing fraud against your staff and vendors. Require multifactor authentication for every mailbox, beginning with administrators and leadership. If you do only one thing from this list, make it this.

2. Block legacy sign-in methods

Older email protocols do not support multifactor authentication and are commonly abused in password attacks. Disable legacy authentication unless an application truly requires it, and if one does, plan to replace it.

3. Set up SPF, DKIM and DMARC

These three DNS-based records help prove that messages claiming to come from your domain really did, and help receiving servers reject forgeries.

SPF lists the servers allowed to send mail for your domain.

DKIM adds a digital signature to outgoing messages.

DMARC tells receivers what to do with messages that fail the checks and sends you reports.

Start DMARC in monitoring mode, review the reports to find legitimate senders you forgot, such as billing or marketing services, then move gradually to a stricter policy. A properly configured domain is harder to impersonate, which protects residents, families and vendors from scams that use your name.

4. Turn on advanced filtering

Most platforms include features that scan attachments and links for malicious content. Enable safe attachment and safe link protections where your license supports them. Quarantine messages that are likely phishing instead of delivering them with a warning.

5. Mark external email

Add a visible banner or subject tag to messages from outside your organization. A fake message from the administrator is more likely to be noticed if it carries a warning label, saying that it came from outside.

6. Restrict automatic forwarding

Attackers who take over a mailbox often create a hidden rule that forwards copies of messages to an outside address. Block automatic external forwarding by default, and review mailbox rules regularly. This also helps keep PHI from leaving your control through well-meaning forwarding to personal accounts.

7. Review sharing and external access

Check who can share files outside your organization and whether links can be opened by anyone. Limit anonymous sharing and set expiration dates where possible.

8. Protect shared and generic mailboxes

Shared mailboxes such as admissions or billing are often forgotten. Make sure they have restricted membership, no direct sign-in with shared passwords and logging enabled.

9. Enable logging and alerts

Turn on audit logging, and set alerts for suspicious activity such as sign-ins from unusual countries, impossible travel, mass deletion or new forwarding rules. Logs are only useful if someone reviews them, so decide who receives alerts.

10. Use encryption when sending PHI

HIPAA does not prohibit emailing PHI, but the Security Rule expects safeguards for transmission. Offer a secure way to send messages that contain resident information, such as policy-based encryption or a secure portal, and train staff on when to use it. Combine this with data loss prevention rules that warn when an email appears to contain sensitive identifiers.

11. Prepare for compromise

Even good defenses can fail. Document how to respond if an account is taken over: reset the password, revoke active sessions, remove suspicious rules, review recent activity and determine whether PHI was exposed. Assign a person to decide whether the incident is reportable under HIPAA.

A reasonable order of work

A small organization might spend a week on this list: multifactor authentication and legacy blocking on day one, filtering and external banners on day two, forwarding and sharing restrictions on day three, and DNS records and logging after that. Record each change and the date.

Getting help

UnityCare IT configures and monitors email security for healthcare organizations, including DMARC rollout and staff training. If you would like a review of your current settings, we can walk through them with you.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172