Join us
@denyskontorskyy ・ Jan 30,2024 ・ 10 min read ・ 1k views
When it comes to the transition of the sensitive information, medical data should be treated especially seriously. In the U.S., this is a matter not only of ethics but also of legal responsibility. In this post, we will discuss HIPAA requirements. In particular, we will explain how to check if they apply to you and what you need to do to keep your emails secure if your response is positive.
The Health Insurance Portability and Accountability Act of 1996 was passed by the U.S Congress to handle the health insurance and protect patients’ personal data. Among other important regulations, HIPAA establishes security rules for the transmission of electronic information ( Electronic Protected Health Information, or ePHI). These rules apply to the online data that could expose patients’ personal information, healthcare services, medical history, and even related payment details.
How to check whether your activities (namely, emails you or your service sends) are subject to HIPAA? Answer the questions below:
If you answered “YES” to any of these four questions, then you should be considered an HIPAA compliant entity, and all data related to patients’ names, addresses, diagnoses, prescriptions, payments, or refunds must be properly protected. It means that you can’t send an invoice or results of medical tests, or prescriptions details via your regular email client or messenger without additional precautions. This applies to the personal information of the employees of the listed organizations as well. In this way, sensitive information can be accessed by a third-party as a result of the mailing attack, laptop loss, or a simple human mistake. This will be treated as a HIPAA violation and will lead to a penalty.
Also, note that there is a criminal penalty for intentionally committed offenses.
Does it sound serious enough? It does, but before we move forward, let’s check what is not subject to HIPAA:
As a rule of thumb, it is better to protect the information that is not HIPAA compliant information than to miss something and send HIPAA covered data in an insecure way.
The most complicated thing about HIPAA compliance is that the requirements are broad but still vague. Another difficulty encompasses the unavailability of the official compliance certification.
After all, as a HIPAA covered entity, you have to follow technical, physical, and administrative safeguards to ensure proper ePHI protection.
Technical safeguards relate to technology methods to protect ePHI and data access.
Their only provision is that all confidential information transferred outside the internal firewalled servers must be encrypted according to the standards approved by the U.S. National Institute of Standards and Technology (NIST). We will discuss the email encryption in a separate section of this article.
In the rest, you have to ensure the following, in any appropriate method:
Physical safeguards concern the data storage and include physical access to data on servers (both local and cloud) and devices.
Administrative safeguards focus on the implementation of technical and physical protection.
For more details, we recommend following the HIPAA Journal and the U.S. Department of Health & Human Services website.
We have already mentioned that according to the HIPAA requirements, emails must be encrypted to NIST standards. It means that messages need to be both encrypted and decrypted to ensure security while sending, transferring, receiving, and storing information.
AES encryption is one of the recommended algorithms. It is implemented in TLS as well, but note that simple TLS encryption is not enough: mostly, email services use opportunistic TLS. This is enough for sending encrypted information but if the recipients’ server doesn’t support TLS, the message arrives without encryption.
So, how can you implement the required encryption for your email messages?
This method fits large corporate organizations that have resources for setup and maintenance of their own secure hosting and email infrastructure. This is a complicated and highly tech savvy task. If you are not absolutely sure that you are able to ensure the required level of security, it is better to use a third-party service.
It sounds weird but in fact, you can keep all the ePHI on the dedicated patient portal, which is HIPAA compliant, and send a link to the appropriate notification via email. You should consider this option if you already use (or plan to use) a patient portal software. Such platforms offer all-in-one service for scheduling, payments, messaging, and more. Some of the popular systems are Athenahealth, Epic, Cerner, NextGen Office, etc.
This is the most popular option and you have a broad selection of HIPAA compliant email sending providers. Some of them offer standalone services and other – plugins for your preferred email clients. We will do a brief overview of the most popular options in a separate section.
Patient safety and confidentiality are top priorities for services provided by the server. As a healthcare provider, a HIPAA compliance security checklist is a must. If you have a medical website built with WordPress, you are probably wondering if it should (and can) be compatible with HIPAA.
Whichever method you choose, keep in mind the following rules:
The most popular solution is to entrust the transmission of sensitive data to a HIPAA compliant email service provider. In this section, we will answer the frequent questions like which email providers can be considered HIPAA compliant and whether it is possible to keep sending emails via your preferred service.
The main idea of using the proper email service is to ensure that only the authorized sender and recipient are able to access the content of the message.
The HIPAA Journal lists 10+ compliant email providers. Let’s review several services and methods they use to ensure the security of your communications.
Hushmail provides you with an email account, which is available as a web service or an iPhone app. If your recipients don’t use Hushmail, they will get emails protected with a password or a security question.
Hushmail’s interface is similar to most popular email clients. You need to tick an encryption checkbox manually when sending a message to a non-Hushmail account, which entails a risk of sending unsecured emails.
For developers, they provide access to their API so that the service can be customized and used for sending automated email notifications.
Pricing starts at $9.99 per month per user. Also, there is a special price for non-profit organizations.
NeoCertified is another service that offers a secure web portal. In addition, they provide seamless integration with Gmail and Outlook by adding a button, as well as iPhone and Android apps.
NeoCertified bills you annually, starting at $99 per user, with a special price for non-profits as well.
You can also integrate NeoCertified API with your own software with its SDK.
Paubox is a comprehensive system for sending HIPAA compliant emails. They offer seamless integration with commercial platforms like Office 365, G Suite, Salesforce, etc. It doesn’t require the installation of an extra application, either for the sender or the recipient.
You can integrate Paubox with your own application with API or using its SMTP relay. Email Data Loss Prevention (DLP) and Email Archiving are offered as additional solutions.
The cost of the minimum subscription is $30 per month for three users. The price of using API and SMTP relay depends on the number of messages you send monthly and starts at $100 for 10,000 emails.
Virtru provides data encryption tools for enterprise applications. Sending HIPAA compliant emails is one of them. It can be integrated with Gmail, Google Drive, and Microsoft Outlook. Email protection can be switched on and off manually.
To decrypt your message sent with Virtru, your recipients will need to verify themselves with a password or an email confirmation.
For bigger needs, SDK is available as well. Virtru pricing is custom.
LuxSci is also a platform and a set of tools for secure email, high volume sending, email archival, and smart hosting. You can send messages via an SMTP TLS. In this case, recipients don’t need to authenticate to read your message. However, such an email will be encrypted during transmission only. Another option is a secure portal, which can be accessed via a free account or answering a security question.
Starting monthly price is $50 at $1-10 per user, as users come in multiples of five.
Mostly, HIPAA compliant email sending is offered as a part of the secure portal, in some cases – SMTP relay. The services may be quite expensive. But any HIPAA compliant email sending provider you choose, they will sign a business associate agreement (BAA) with you, which is an obligatory requirement. And what about our usual email clients like Gmail, Outlook, Mailchimp? Some of the above listed tools add plugins for popular services, does it mean that they are not HIPAA compliant?
Gmail and Outlook can’t be HIPAA compliant. They are free and not designed for business use. It means that you can’t sign a BAA with any of them. However, their paid versions – G Suite and Office 365 – can be used for sending ePHI securely. Check their policies, sign BAA, and set up the right configuration, before you can move forward.
GoDaddy is not HIPAA compliant on its own, but provides email encryption and archiving for GoDaddy Office 365 customers.
Most email marketing platforms can’t ensure HIPAA compliance. For example, Mailchimp states in its Terms of Use that this is customer’s responsibility to determine if their service can be used for proper transmission of the confidential information. In addition, Mailchimp won’t be able to sign a BAA with you.
Amazon AWS is one of the less advertised options for medical needs. Still, you can use it for hosting your application and sending email communications via Amazon SES, since they are both HIPAA compliant.
All confidential information in healthcare (and other industries as well) must be properly protected and accessed by the addressed parties only. You need to be very cautious when choosing methods and services for transferring ePHI. Follow these simple rules:
Delighted you found value in Diana Lepilkina's article on mailtrap.io! For a deeper dive into related information, simply click here!
Join other developers and claim your FAUN account now!
Technical Content Writer
@denyskontorskyyInfluence
Total Hits
Posts
Only registered users can post comments. Please, login or signup.