Gmail confidential mode provides privacy features intended to provide users with control over the information sent by email. However, this feature is based on manual actions and requires additional steps when using clunky security features like SMS verification.
Gmail’s confidential mode is a feature designed to give users greater control over the sensitive information they send through email. Gmail specifies in their administrators’ guidance, “With Gmail confidential mode, your users can help protect sensitive information from unauthorized or accidental sharing. Confidential mode messages don't have options to forward, copy, print, or download messages or attachments.”
The feature ensures that emails sent cannot be forwarded, copied, printed, or have attachments downloaded by recipients. The sender can also send an expiration date for the email, revoke access after that time, and even manually revoke access before the expiration date. Additional security features include the option to require recipients to enter a verification code sent via SMS before opening the email.
While Gmail prevents recipients from forwarding, copying, downloading, or printing the email it does not block them from taking screenshots or using a phone camera to capture the content. Information is therefore not truly protected from distribution and can still be shared as photo attachments.
If the sender enables SMS verification, the recipient must receive and enter a code before accessing the email. The extra step is inconvenient when a recipient does not have access to their phone. It also poses an issue to elderly recipients who might not understand how to alternate between devices to access emails and could be prone to just ignoring the email.
Once the email reaches its expiration date, the recipient loses access to the email entirely. While this is meant to increase security it can frustrate recipients if they still need to reference the message attachments after it expires.
Human error can occur due to the manual steps required to set expiration dates, revoke access, or send passcodes through SMS for email security. Staff might forget to enable these features, use them inconsistently, or misunderstand how they work. Without additional training and regular monitoring, the feature loses its central purpose in the protection of sensitive information.
Gmail’s free account, including its features like confidential mode, is not fully HIPAA compliant on its own. Gmail does offer free accounts accessible to most users but requires those seeking compliance to use the paid version of Google Workspace to access a business associates agreement (BAA) with Google. Even once users ensure that accounts are HIPAA compliant there are still challenges associated with the use of its confidential mode.
As discussed in the limitations section of this article, Confidential Mode puts security in the hands of staff. When considering the multitude of factors influencing staff's ability to select the correct options when sending every email, the possibility of error grows exponentially. In a healthcare setting, where the room for error is narrow, there is a high possibility of an avoidable data breach occurring.
Paubox, on the other hand, is a HIPAA compliant email service that automatically encrypts every email sent by an organization without the need for additional steps or security settings. On their Email Suite product, Paubox states, “We'll encrypt every email you send so you don't have to worry about HIPAA compliance. Our patented solution ensures HIPAA compliant delivery even if your recipient's email has an outdated email platform.”
The simplified process eliminates the potential for user error present in Google Confidential Mode. The service also easily integrates with Google Workspace and Microsoft Outlook without requiring additional logins or services, meaning that organizations can use their existing familiar email accounts while being assured of the security of every email sent.
Related: Healthcare’s Ultimate Guide to Gmail: Is Gmail HIPAA compliant?
While Gmail Confidential Mode offers basic security features, it relies heavily on manual input which is not realistic in organizations sending a high volume of emails daily. When adding the fact that multiple staff members may access the accounts, the potential for human error makes it far too risky to apply in healthcare settings.
HIPAA is a US law that protects the privacy and security of individuals' medical information.
It is a contract between a healthcare organization and a third party that handles protected health information.
Any third party service that handles, transmits, or processes protected health information on behalf of a healthcare organization must sign a BAA.
Yes, HIPAA compliant email can be useful in any sector that requires secure communication.