Sure, social media gets a lot of press these days. But email still remains one of the most popular and frequently used modes of communication. It’s convenient and efficient, but risky, too, according to a Proofpoint white paper about increasingly broad HIPAA and HITECH provisions.
Sending an unencrypted email over the Internet is about as secure as sending a postcard via snail mail. If it contains confidential information – like a Social Security number or health records – the privacy of that information is in jeopardy.
This is a big deal not only for those organizations Medicare considers “covered entities,” but also for any of their business partners – say, a Web hosting firm or an accountant – because the penalties for a security breach are steep (up to $1.5 million in a calendar year.)
With health care looking to be increasingly networked and electronic, a growing volume of information will be sent through email. Health care organizations and their business partners need to make sure emails containing protected health information, or PHI, is always secure and in compliance with the growing body of strict regulations.
A secure email solution, according to Proofpoint, should be:
- Automated and comprehensive. End users shouldn’t be counted on to distinguish sensitive data from insensitive data and take special steps to ensure that it is transmitted securely. It’s safer to build the automated detection of PHI into the email infrastructure itself.
- The solution should be able to detect and protect confidential information, whether it’s included in the body of an email message or in an attachment.
- Encryption, monitoring and logging should accommodate treatment and business processes, providing a helpful service that interferes as little as possible with existing operations.
For more detailed information about encrypting email, check out Proofpoint’s white paper, “HIPAA and Beyond: An Update on Healthcare Security Regulations for Email.”