Secure email uses encryption to protect data, while HIPAA compliant email goes further by incorporating strict regulations to safeguard protected health information (PHI).
Secure email is any email system that incorporates security measures, primarily encryption, to protect messages from unauthorized access. Many secure email services use transport layer security (TLS) to encrypt emails in transit, preventing interception by malicious actors.
Additional security features in a secure email system may include:
While these features make email more secure, they do not necessarily fulfill the strict requirements set by HIPAA.
The Health Insurance Portability and Accountability Act (HIPAA) sets specific standards for handling PHI to ensure privacy and security. HIPAA compliant email must meet all security and administrative requirements outlined in the HIPAA Security Rule, which includes:
According to Peter F. Edemekong, et al. in a study published by the National Library of Medicine, the “rise in ePHI exchange has necessitated robust security standards to safeguard sensitive health information while ensuring proper access for healthcare-related entities.” While all HIPAA compliant emails are secure, not all secure emails are HIPAA compliant. Therefore, healthcare organizations must diligently assess their email platforms to ensure they are both secure and fully HIPAA compliant, minimizing the risk of non-compliance and data breaches.
Without a signed BAA, your email provider is not legally responsible for protecting PHI under HIPAA regulations. This could lead to non-compliance penalties and potential data breaches.
HIPAA violations can result in fines ranging from $141 to $71,162 per violation, with an annual maximum of $2,067,813, depending on the severity and negligence of the breach.