Email is how a great deal of healthcare business gets done, from coordinating with a pharmacy to answering a family member's question. It is also one of the easiest ways to expose protected health information by accident. A message sent to the wrong person, a forwarded thread with details nobody noticed or an unencrypted attachment can all become reportable incidents.
HIPAA does not forbid email. It requires reasonable safeguards. Here is how to build practical rules your staff can actually follow.
The Security Rule requires protections for electronic protected health information in transmission, including technical measures guarding against unauthorized access. Encryption is an addressable specification, meaning an organization must implement it or document an equivalent alternative and the reasoning. In practice, for anything leaving your organization over the open internet, encryption is the expected approach.
The Privacy Rule also recognizes that individuals may ask to receive information by unencrypted email, after being warned of the risk. That choice belongs to the individual, and it should be documented.
Keep the rule simple. A workable standard is: if a message or attachment contains protected health information and leaves your organization, it must be encrypted.
Examples to share with staff:
A resident's name with diagnosis, medications or lab results
Scanned face sheets, care plans or insurance cards
Billing statements showing the resident's name and service details
Photos of wounds or any images that identify a resident
If encryption takes six steps, staff will skip it. Look for solutions that encrypt automatically, for example by detecting keywords or by letting staff add a word like secure in the subject line to trigger it. Test the process from the recipient's side too, since a confusing portal results in people asking you to send it the easy way.
Many email breaches are mistakes, not attacks. Reduce them with habits and settings.
Turn off or review autocomplete suggestions, which often pick the wrong person with a similar name
Pause before replying all
Verify external recipients before sending, particularly when addresses are new
Enable warnings when sending to outside addresses
Use a short delay on outgoing messages so mistakes can be recalled
When possible, send less. Use initials or a resident identifier instead of a full name, and keep clinical details out of the subject line, which is often not encrypted even when the body is. If a conversation can be handled by phone, a secure portal or your EHR's messaging feature, use those.
Confirm the file is the right one before attaching it
Remove hidden information, such as extra tabs in spreadsheets
Use encrypted portals for large files rather than consumer file-sharing services
Never send protected information to personal email accounts, even to yourself
Automatic forwarding of work mail to personal accounts should be disabled. Restrict access to shared mailboxes to the people who need them. Make sure departing employees lose access immediately.
Encryption does not help if a criminal signs in as your staff member. Require multi-factor authentication on email, use filtering to block phishing and teach staff to report suspicious messages.
One page is enough. Cover:
What counts as protected health information in email
When encryption is mandatory and how to apply it
What not to put in subject lines
How to verify recipients
What to do if a message goes to the wrong person, including reporting to the privacy officer immediately
Rules for texting and messaging apps
Plan for them. Tell staff that quick reporting is expected and appreciated. The privacy officer can then assess the incident and decide whether notification is needed.
UnityCare IT can configure email encryption, filtering and warnings for your organization and help draft a policy that fits how your teams communicate.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034