Part two of a two-part series on HIPAA Compliant Email.
In a previous post, we reviewed some of the statements that the Office of Civil Rights (OCR), the HIPAA Privacy and Security Rule enforcers, include in their online FAQs relevant to HIPAA and email rules for covered entities. It is interesting that this guidance has hardly changed in the years that these FAQs were first issued or updated. In some respects, the widespread use of electronic health records with secure patient portals had actually increased the use of email for communications with patients – at least to get them to log into a portal where the security of the email communication is less of an issue because the patient data stays within the EHR application.
However, there are still regulated (covered) entities – physicians, hospitals, health plans and business associates – using email for patient communications. So it’s worthwhile to review the need for HIPAA compliant email. After all, knowing the rules is one thing … but putting them into practice and implementing HIPAA training for your employees is what’s going to keep your healthcare organizations out of trouble. So let’s explore some HIPAA regulations and best practices to stay HIPAA compliant with your email communications.
Table of contents
- 5 strategies for achieving HIPAA compliant email
- 1. Utilize technical expertise on the topic of HIPAA compliant email on behalf of your patients.
- 2. Document the patient’s consent to receive communication by email.
- 3. Use an EHR system with a patient portal function for patient access and communication.
- 4. Consider exploring options with HIPAA compliant email services.
- 5. Manually encrypt transmitted files to maintain HIPAA compliance.
- What to look for in a HIPAA Compliant Email Application
- SMS text messaging (regular texting) is not “secure messaging”.
- A HIPAA violation for email mishandling can be costly.
- Send HIPAA compliant email … sleep well at night.
5 strategies for achieving HIPAA compliant email
Like so many other things with HIPAA compliance, there’s not one, singular answer that addresses the question of what constitutes HIPAA compliant email. However, the options addressed below represent a collection of first-line strategies that we often recommend. They can go a long way toward ensuring you are protecting the privacy of patient protected health information and other sensitive data. And we’ll discuss some related non-email alternatives as well.
1. Utilize technical expertise on the topic of HIPAA compliant email on behalf of your patients.
This means making sure you have appropriate notices visible, both online and in the real world, warning patients about the potential security risks of transmitting protected health information (PHI) using email over the non-secure portion of the Internet. For instance, many practices include a page on a website for submitting questions to the office via email. Based on our experience, we recommend posting a statement that emphasizes security measures and security features such as:
2. Document the patient’s consent to receive communication by email.
Don’t assume that because your patient sent an email requesting PHI or sharing PHI, that he or she understands the risks of sending or receiving such emails. Consider using a form like this “Emergency Contact Sheet” to document the patient’s preferences in many areas. If you’re using an EHR system, do not enter a patient’s email address without making sure the patient knows they may get appointment reminders and other email notices with sensitive information. And make sure you have entered the correct email address! Many email accounts have similar addresses, so make sure you have transcribed the correct email address the first time it is entered! In our role as Privacy Officers for many clients, we have seen numerous situations where the email address entered was erroneous – but it was a valid address for someone else! And sending PHI to the wrong email address is potentially a reportable breach!
3. Use an EHR system with a patient portal function for patient access and communication.
If you’re using an EHR system with a patient portal function, encourage patients to use the portal’s capabilities for secure messages. Most portals utilize secure channels for the information available via the portal, but make sure the vendor certifies that to you – and then test it yourself prior to encouraging patients to use it.
What we like about an EHR system with this type of function is that it encrypts patient information so that it can only be accessed by authorized users. This connection is HIPAA compliant and allows the patient to access their medical records, and communicate with their care team. It also allows the healthcare provider to encrypt and send messages to the patient.
4. Consider exploring options with HIPAA compliant email services.
If you must use email to communicate with patients, a secure email service will protect your communications by using secure channels to send them. If you plan on using your existing email provider, make sure they are meeting the Security Rule standards for access control, integrity and transmission security. For example, they must have a way to encrypt emails so that only the intended recipient can read them. They must also have a way to verify that the email was not altered in transit, and they must provide a way for the sender to recall an email if it was sent to the wrong person.
Email encryption standards are also important. Many purveyors of HIPAA compliant email applications boast of using 256-bit encryption. It is not hard to find a HIPAA compliant email service provider, so you should be able to find one that meets your needs. If you do go this route, be sure to sign a business associate agreement (BAA) with the selected email service provider.
5. Manually encrypt transmitted files to maintain HIPAA compliance.
If you don’t have a patient portal and don’t want to use a secure, HIPAA compliant email provider, avoid including PHI in the text of the email, and use end to end encryption for any messages or files containing PHI that you are sending to patients.
An end-to-end encryption system ensures that only the intended email recipients can read your encrypted emails and their attachments. This prevents unauthorized access to sensitive patient information, and helps ensure communications between healthcare providers remain private as well! In addition, end to end encryption can help to prevent email spoofing, phishing attacks, and other online threats. So the usefulness of email encryption extends beyond HIPAA compliance.
What to look for in a HIPAA Compliant Email Application
If you have decided to use a stand-alone application for secure communication involving PHI, there are several important issues to explore. In our experience, these factors will help you to compare how well each application meets HIPAA requirements.
- What level of encryption does the application utilize? While AES 128-bit encryption is required by the Security Rule as part of the Technical Safeguards, many HIPAA compliant email providers offer an AES 256-bit email encryption tool.
- Does the vendor offer a business associate agreement? Since you are relying on your email service provider to maintain the privacy of your patient’s PHI, you want them to understand their obligations to investigate potential data breaches of their system, and to mitigate the effects of any breach.
- Is there seamless integration into your existing electronic health record system or into other existing office automation or web portal? Is it easy to start an email in your EHR? Is there automatic encryption of PHI detected in the text of the email? Is the application limited to only working with other applications such as Google Workspace or Microsoft Outlook?
- How complicated is email delivery? Is the application easy to use on the receiving end? If users are directed to a website to retrieve an email message, does the website maintain a log of the messages for future reference? Are there set expiration dates when messages are no longer available? Are mobile apps user-friendly? Does the application include web forms and signature capture? Does it include secure large file sharing or offer two factor authentication? Are there detailed logs and/or an audit trail accessible?
- Is there an easy-to-use process for archiving selected messages into an EHR system? Not all email communications may be worthy of including in a patient medical record, but some certainly are. What is the email archiving capability of the application.
These are just a few of the issues that we recommend you consider when looking at HIPAA compliant email providers. The complexity of the application, reputation of the vendor and its time in business are also important. And of course there is the price you will pay, typically a subscription with a monthly payment. Fees may sometimes be based on the number of users, e.g., up to five users.
SMS text messaging (regular texting) is not “secure messaging”.
While not technically “email” security, the context is the same when it comes to text messaging. Specifically, covered entities sending PHI via texting when using an unsecured electronic format was deemed unlawful in 2013 when the U.S. government updated HIPAA laws and enacted specific safeguards into the Security Rule. Those safeguards include …
- Controlling how people access PHI.
- Managing how people utilize PHI.
- Ensuring that people sending and receiving the text messages are who they say they are.
- For PHI being transmitted outside of the organization via text messaging, or any other form of transmission, the data must be encrypted.
A HIPAA violation for email mishandling can be costly.
It is not far-fetched to think that one of these days, the OCR, while investigating a complaint from a patient about a privacy violation, determines that a provider was disclosing PHI when communicating via email with a patient. And that every such email constituted an unauthorized disclosure – a HIPAA breach. And that every such email to any patient was a breach. It might not take long to get to a breach involving more than 500 patients, with all the attendant notices to the media and reports to the Secretary of HHS that would entail. Not to mention financial penalties ranging from $141 to $71,162 per Tier 1 violation. And that’s for situations where the covered entity was unaware of the violation, and with reasonable due diligence would not have known of the violation! Penalties for Tier 2, Lack of Oversight, start at $1,424 per violation. These figures are adjusted annually to take inflation into account. Of course, what cannot be accurately valued it the damage to your reputation when the breach is publicized.
And the OCR is not the only regulatory that you may have to report a breach to. Many states also require notification to state Attorneys General – based on the state in which a patient resides. We can certify from experience that the cost of these notifications starts to go up exponentially when large numbers of existing email clients in multiple states are involved.
Send HIPAA compliant email … sleep well at night.
Don’t be the practice or other healthcare provider that finds itself in the unenviable position described above, simply because you didn’t pay enough attention to establishing a HIPAA compliant email strategy with your patients!
Email will be around for a while, in the healthcare industry and so many other areas of our lives. It’s a great tool, but like any tool, it must be respected for its power – both for communications we want and for the potential to disclose sensitive information we need to keep private.
Using email in healthcare requires more effort and safeguards than in other areas, but it certainly is possible to mix the two. By following the HIPAA email rules we’ve outlined, you can minimize your risk of violating HIPAA law and protect the privacy and security of your patients’ protected health information. Remember, these are just guidelines – if you have any questions or need help implementing them to ensure your practices are HIPAA compliant, please reach out to The Fox Group for assistance.
For a comprehensive look at implementing HIPAA requirements in a physician setting, check out our recent post on Medical Office HIPAA Compliance. If you still feel overwhelmed, give us a call!
