Under HIPAA, encrypted email converts message content into a coded format, ensuring electronic protected health information (PHI) remains confidential and secure from unauthorized access during transmission and storage. Unencrypted email, however, leaves electronic PHI vulnerable to interception and unauthorized access, posing a high risk of data breaches and making it challenging to meet HIPAA compliance requirements due to the lack of safeguards.
According to the HHS, "The Security Rule requires covered entities to maintain reasonable and appropriate administrative, technical, and physical safeguards for protecting e-PHI.".
While encryption isn't explicitly mandated, it is highly recommended to secure PHI during transmission. The goal is to ensure that patient information remains confidential and is not accessed by unauthorized individuals.
Unencrypted email refers to messages sent without encryption, leaving them vulnerable to interception. These emails can be easily read by unauthorized parties if intercepted during transmission, creating a high risk for a data breach.
While HIPAA does not outright prohibit unencrypted email, it presents significant compliance challenges. Demonstrating that reasonable safeguards are in place to protect PHI is difficult when using unencrypted email, making it harder to meet HIPAA requirements. Patients must be informed of the risks and should consent in writing if unencrypted email is to be used.
Related: What happens if an email is not encrypted?
Encrypted email, on the other hand, converts the content of the message into a coded format that can only be deciphered by the intended recipient with the appropriate decryption key, significantly enhancing security by protecting PHI from unauthorized access during transmission and storage.
Encryption offers several benefits in the context of HIPAA:
Related: The consequences of not having a BAA with an email service provider
Healthcare organizations can conduct regular security assessments and audits to verify the effectiveness of their email encryption and ensure ongoing compliance with HIPAA regulations.
If an unencrypted email containing PHI is accidentally sent, the provider should immediately report the incident, assess the potential breach, notify affected patients, and take steps to prevent future occurrences.