Poor Email Practices are a Leading Cause of HIPAA Violations

Poor email practices and bad email compliance are common causes of HIPAA violations and often lead to major data breaches. The most recent report to Congress from the HHS’ Office for Civil Rights for calendar year 2022 shows there were 626 reports of large breaches of protected health information (PHI), 22% of which were email-related. Across those incidents, the PHI of 2,337,032 individuals was exposed or stolen.

Less obvious are the smaller breaches and HIPAA violations, as these incidents, while reportable, are not publicly disclosed on OCR’s breach portal. These breaches and HIPAA violations are far more numerous and are most commonly due to employee errors, including sending emails to the wrong individuals and attaching incorrect files to emails. In 2022, OCR received 63,966 reports of breaches of fewer than 500 records which included more than 3,731 incidents involving email. Email-related breaches accounted for 20% of breached records (50,935 individuals).  This is despite secure and HIPAA-compliant email solutions like Paubox are readily available to mitigate the risks of HIPAA violations. Top vendors like Paubox have solutions that are suitable for any size of HIPAA-covered entity so there is very little excuse for not using HIPAA-compliant email.

Email Security

There are several ways that email accounts are compromised, and while it is not possible to prevent all email-related breaches, risk can be reduced to a low level through HIPAA Security Rule compliance.  The standards of the HIPAA Security Rule are concerned with reducing risks and vulnerabilities to the confidentiality, integrity, and availability of electronic PHI (ePHI), which involves implementing safeguards to protect against the most common initial access vectors used by cybercriminals and reducing the risk from malicious and negligent insiders.

The most common causes of hacking-related email data breaches are phishing, credential stuffing, and other brute-force attacks on email accounts. Many hacking incidents involving malware and ransomware have their roots in poor email security practices and a lack of technical safeguards.

Security Solutions for Email Compliance

The HIPAA Security Rule is deliberately light on detail when it comes to specific security solutions that need to be implemented, to avoid frequent legislative updates when new technologies are developed, and threats evolve. It is the responsibility of HIPAA-regulated entities to stay up-to-date on the latest technologies and evolving attack methods and implement technical safeguards to reduce all reasonably anticipated threats.

The most common email security threats are phishing and malware. Phishing often involves impersonation and uses social engineering techniques to trick users into disclosing sensitive information, most commonly login credentials, opening malicious attachments, and downloading malware. Less common, but more damaging financially, are business email compromise (BEC) attacks, which often start with a phishing attempt. Having the right email security solutions in place will ensure that the majority of these email attacks are blocked and do not reach end users.

HIPAA
Compliance
Checklist

Simple Guidelines
Immediate PDF Download

Immediate Access

Privacy Policy

Download Free Checklist

Secure email gateways/spam filters

A secure email gateway or spam filter is used to identify and block malicious and unwanted emails before they reach your email system. Email service providers often incorporate their own spam filters to reduce the volume of unwanted emails. Google and Microsoft 365, for example, filter out many unwanted messages; however, more robust protection is required for blocking malicious emails and more sophisticated attacks.

Antivirus protection

Traditionally, antivirus solutions have been signature-based. The digital signature of a malware variant is identified and added to a definition list. When that signature is detected in the future, the malicious file will be deleted or quarantined. The volume of malware now being released and the obfuscation methods used by malware developers have reduced the effectiveness of signature-based detection. Behavioral detection, such as sandboxing, can identify and block novel malware threats based on the actions of files when they are analyzed in an isolated environment.

Anti-phishing protection

Spam filters will block many phishing attempts, but phishing emails can be difficult to detect. The spoofed web pages that phishing emails link to often involve multiple redirects and the web pages may pass reputation checks. Anti-phishing solutions that involve AI and machine learning algorithms provide an additional layer of protection against phishing threats and can identify novel phishing attempts from how they deviate from standard emails that are typically received.

Security Practices

Safeguards must also be implemented to block direct attacks on the email system. To ensure HIPAA compliance for email, robust access controls are required to block unauthorized attempts to access email accounts.

Password Security

Access to email accounts must be controlled, which for many decades has involved unique usernames and passwords for all employees. Logs must be created to record system activity, which can be linked to each user via their login details. The problem with passwords is they are far from secure as they can be guessed or hacked.

Cybercriminals use powerful computers to automate attacks on accounts using brute force tactics to guess the correct password. These attacks succeed due to the use of weak passwords and the reuse of passwords. Tests involving computers with the latest GPUs have shown that a password consisting of any combination of 6 upper- and lower-case letters and numbers can be guessed in less than 6 hours, with commonly used passwords guessed almost instantly. Credential stuffing attacks use passwords obtained in a breach on one platform to try to gain access to an account on another and succeed due to password reuse.

To improve password security, employees must be told how to create secure passwords, and password policies must be implemented and enforced to prevent users from setting weak passwords. A password manager can help users generate complex unique passwords, store them securely, and auto-fill them when they are needed. Password policies should be guided by the latest guidance from the National Institute of Standards and Technology (NIST).

Multifactor Authentication

Even with complex password requirements, email accounts are not sufficiently secured. Employees may ignore their training and set passwords that meet complexity requirements but are easy to guess, and passwords may be obtained through phishing, keylogging malware, or other means. Multi-factor authentication (MFA) adds an additional layer of protection and requires a second authentication factor in addition to a password before account access is granted. That second factor may be a one-time code sent to a registered device or email account, an answer to a secret question, or a hardware token. Phishing kits are being used in attacks that can defeat some forms of MFA, so phishing-resistant multifactor should be used if possible.

Email encryption

While encryption is not a required HIPAA Security Rule standard for internal emails, it is essential for protecting emails containing ePHI that are sent externally. With email encryption, emails are rendered indecipherable in transit, so if the email is intercepted in transit, the content cannot be read. With end-to-end encryption, emails are encrypted by the sender and can only be read by the intended recipient.

Security Awareness Training

Phishing, BEC, and email-related malware incidents target employees and exploit human weaknesses. Technical security measures will reduce the number of threats that arrive in employee inboxes; however, even with the most advanced, AI-powered email security solutions, many malicious emails will evade those defenses and land in inboxes. Cybercriminals use social engineering techniques to trick employees into opening attachments containing malicious scripts, following links to websites where credentials are harvested, or trick them into emailing sensitive information. Employees are the last line of defense, and that defensive line needs to be strengthened.

Security awareness training is a requirement for HIPAA Security Rule compliance. The aim of security awareness training is to educate the workforce on security best practices to eliminate risky behaviors, raise awareness of common threats that they are likely to encounter and teach them the skills they need to identify and avoid those threats.

Cybercriminals are constantly evolving their tactics and devising new phishing lures and social engineering techniques to trick employees, and these new tactics need to be covered in training as and when they are identified. That means training needs to be provided continuously throughout the year, rather than requiring employees to complete an annual training session. Regular security awareness training reinforces the training and helps to develop a security culture, where employees are constantly alert and stop and think before taking any action suggested in an email. Consider also conducting phishing simulations to reinforce training, identify knowledge gaps, and provide targeted training in response to any failure to identify or report simulated phishing emails.

Email Policies, Procedures, and Practices

You can make your email HIPAA compliant with the HIPAA Security Rule by implementing technical safeguards; however, you also need to develop and implement policies and procedures – and provide staff training on those policies and procedures – to ensure that email is used correctly, and employees are aware of their responsibilities under the HIPAA Privacy Rule. Most of the smaller privacy violations reported to OCR are due to employee mistakes and a lack of understanding of the HIPAA Rules. HIPAA Privacy training can help to reduce these risks.

Email Policies and Staff Training

Organizations should implement rules on how email can be used, what information can be sent via email, and by whom, and should have policies and procedures for obtaining consent from patients to communicate via email. If the decision is taken to allow patient data to be sent via email, then patients need to be informed of the risks and must agree to receive their data via email.

If emails are sent externally, there is a chance of interception. Many email encryption solutions allow the sender to decide whether to encrypt an email and while there are advantages to having that option, the risk is that employees will make mistakes and may accidentally fail to encrypt an email. A better option to reduce risk is to configure email to encrypt all emails that are sent externally.

Staff must receive training and be informed about email security risks and the importance of carefully checking email addresses before they are sent. Many of the privacy violations in the 63,966 reports of small breaches in 2022 were due to miscommunications, including emails sent to incorrect recipients.

Email Retention Policies

Many of the email-related breaches reported to the HHS’ Office for Civil Rights have involved hundreds of thousands of exposed records. Storing a large volume of sensitive data in email accounts is a recipe for disaster. If an email account is compromised, access can be gained to massive amounts of ePHI. Further, the reviews of email accounts after such a breach will be incredibly time-consuming, resource-intensive, and costly.

It is important to have an email retention policy for email to ensure that your organization meets its regulatory obligations for data retention under federal and state laws, and the easiest way to achieve this is by using an email archive, setting strict data retention rules, and automating data deletion when the retention period is reached.

Business Associate Agreements with Email Vendors

If protected health information is sent via email, then the email vendor meets the definition of a business associate under HIPAA, which means they must sign a business associate agreement. The business associate agreement outlines the vendor’s responsibilities under HIPAA, including the requirement to implement policies, procedures, and safeguards to comply with all appropriate provisions of the HIPAA Rules.

There are many email service providers that do not charge for their services, for instance, Hotmail and the free version of Gmail. These services cannot be used, as the email service providers do not enter into business associate agreements for their free accounts. For added peace of mind, when searching for a HIPAA-compliant email vendor, look for a vendor with HITRUST CSF Certified status as this demonstrates that they are committed to security and have implemented safeguards to manage risk.

About Liam Johnson

Liam Johnson has produced articles about HIPAA for several years. He has extensive experience in healthcare privacy and security. With a deep understanding of the complex legal and regulatory landscape surrounding patient data protection, Liam has dedicated his career to helping organizations navigate the intricacies of HIPAA compliance. Liam focusses on the challenges faced by healthcare providers, insurance companies, and business associates in complying with HIPAA regulations. Liam has been published in leading healthcare publications, including The HIPAA Journal. Liam was appointed Editor-in-Chief of The HIPAA Guide in 2023. Contact Liam via LinkedIn: https://www.linkedin.com/in/liamhipaa/