Email is the most heavily used tool in most clinics and the least examined. Appointment confirmations, referral letters, lab results, insurance queries, images sent by patients from their phones: an enormous amount of protected health information moves through inboxes that were never set up with that responsibility in mind. Practices invest carefully in clinical systems and then run their correspondence on whatever was convenient when the practice opened.
Where Patient Information Actually Leaks
The failures are rarely dramatic. They are routine, and they repeat.
- Forwarding to personal accounts. A clinician forwards a case to a personal address to review at home. The information now sits in a consumer mailbox the practice does not control, cannot audit and cannot wipe.
- Misdirected messages. Address autocomplete picks the wrong contact with a similar name, and a full patient record leaves the building. This is one of the most common causes of reported healthcare data incidents, and it takes one distracted click.
- Shared inbox logins. A single reception password shared among six people means no record of who read or sent what, and no way to remove one person’s access without disrupting everyone.
- Departures that never get closed. A locum or a former receptionist retains mailbox access for months because offboarding was a conversation rather than a checklist.
What The Rules Actually Require
Practices often assume compliance means buying a specific certified product. It does not. The HIPAA Security Rule requires appropriate administrative, physical and technical safeguards for electronic protected health information, together with a documented risk analysis. It is deliberately written around outcomes rather than named vendors, which means the obligation sits with the practice to show that its choices are reasonable and that it can evidence them.
That framing has a practical consequence. A tool is not compliant on its own. It either supports the controls you need, such as encryption, access management, audit trails and a business associate agreement, or it leaves you unable to demonstrate them. The public breach reporting portal maintained by the HHS Office for Civil Rights is a sobering read on how often email sits at the centre of reported incidents.
Why Free Consumer Email Is The Wrong Tool
Consumer mail is built for individuals, and the gaps show quickly in a clinical setting. There is typically no business associate agreement available, so the arrangement cannot be documented properly in the first place. There is no administrative console, so nobody can see which accounts exist or what permissions they hold. Offboarding depends on the departing person cooperating. Retention and deletion cannot be enforced centrally. Audit logging, if it exists at all, is not designed for anyone to review.
None of that makes consumer email badly built. It makes it built for a different purpose, in the same way a domestic fridge is not a vaccine fridge.
What To Look For Instead
When assessing business email for a practice, the questions worth asking are narrow and answerable:
- Is a business associate agreement offered as standard, and will the provider actually sign it?
- Is message content encrypted both in transit and at rest, and who holds the keys?
- Can an administrator see every account, assign roles and revoke access in one action when someone leaves?
- Can shared functions such as reception or referrals run as aliases and delegated access rather than shared passwords?
- Are there audit logs a practice manager can genuinely read during a review?
- Where is the data stored, and under which jurisdiction?
Five Things Worth Doing This Month
- None of the following requires a systems project.
- Inventory every account and alias attached to the practice domain, including ones nobody has logged into for a year.
- Disable forwarding to personal addresses, then give clinicians a legitimate way to work remotely so the workaround is unnecessary.
- Replace every shared password with named accounts plus delegated access to shared aliases.
- Write an offboarding checklist with mailbox access on it, and use it the same day someone leaves.
- Brief the team on misdirected email specifically, including a habit of typing recipient addresses last, after the message is written.
The Quiet Risk
Ransomware and intrusions attract attention, and the annual Verizon Data Breach Investigations Report consistently finds that human error and misuse of legitimate access account for a substantial share of incidents across sectors. In a small practice, the most likely exposure is not an attacker at all. It is a tired member of staff attaching the wrong file at the end of a long clinic list.
That is genuinely reassuring, because process problems respond to process fixes. Named accounts, enforced encryption, a real offboarding routine and a team that knows where the traps are will prevent more harm in a small practice than any single piece of software. The inbox deserves the same seriousness as the clinical record, because increasingly it holds the same information.
Disclaimer: This article is provided for general informational purposes only and does not constitute legal, regulatory, cybersecurity, or HIPAA compliance advice. Email security requirements may vary based on a medical practice’s location, size, systems, contracts, and handling of protected health information. Practices should conduct a documented risk assessment and consult a qualified healthcare compliance, legal, or information security professional before changing email systems, privacy policies, or access controls.