Help Me With HIPAA

Episode 18: Email isn't secure, really, it isn't


Listen Later

Let's review email systems and how they can be secured for ePHI and other sensitive data.

Find Healthcare IT

HIPAA For MSPs

Kardon Compliance

Alston Article on Email Security

Notes

Leigh from Florida sent us an email asking for us to explain some more specifics about email. She had been listening to Episode 8: HIPAA Myths Part 2 which mentioned it but she had specific questions how can email be secured. This couldn't be covered in a quick 5 minute HIPAA answer episode so we are doing a whole episode.

  • How does email work - for "real people" to understand
    • Compare to the post office since that is the way it was originally modeled to match
  • Why that isn't secure at all, really
    • http://www.healthcareitnews.com/news/hipaa-breach-letters-go-out-after-email-hack (article on email hacked and it had patient info in it)
    • open transmissions and many different servers
  • Misconceptions
    • I use a password so it is secure
    • I use https so it is secure
    • I use TLS so it is secure
    • I use updated Outlook with Hosted Exchange so that should be secure
  • Secure email via
    • End to end encryption tools - each party knows the key
    • Messaging system - you get an email telling you to log in to get the secure email
    • Hosted services that allow for specific types of messaging
      • Hosted exchange
      • Plug-in apps
    • Secured internal only messaging systems
      • Very specific set up to secure the mail database on your internal server
      • Controls you have in place to prevent email to other domains outside the secure system (usually software required)
      • Some systems are automatic encryption / others require you to hit a button on the mail to send it secured.
  • Secure messaging systems for internal discussions that don't use email

    • whole new way of communications in forums / chats instead of email
  • Texting also matters but that is a different episode we can touch on it here

  • A word about spear phishing - excellent example this week from a client

...more
View all episodesView all episodes
Download on the App Store

Help Me With HIPAABy Donna Grindle and David Sims

  • 4.9
  • 4.9
  • 4.9
  • 4.9
  • 4.9

4.9

61 ratings


More shows like Help Me With HIPAA

View all
The Joe Rogan Experience by Joe Rogan

The Joe Rogan Experience

228,777 Listeners

The Ben Shapiro Show by The Daily Wire

The Ben Shapiro Show

153,461 Listeners

REAL AF with Andy Frisella by Andy Frisella

REAL AF with Andy Frisella

386 Listeners

The Sporkful by Dan Pashman

The Sporkful

3,945 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,020 Listeners

In The Dark by The New Yorker

In The Dark

28,355 Listeners

Pod Save America by Crooked Media

Pod Save America

87,160 Listeners

The Daily by The New York Times

The Daily

112,027 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,059 Listeners

This Podcast Will Kill You by Exactly Right and iHeartPodcasts

This Podcast Will Kill You

16,951 Listeners

Defense in Depth by David Spark, Steve Zalewski, Geoff Belknap

Defense in Depth

74 Listeners

All-In with Chamath, Jason, Sacks & Friedberg by All-In Podcast, LLC

All-In with Chamath, Jason, Sacks & Friedberg

9,946 Listeners

The MeidasTouch Podcast by MeidasTouch Network

The MeidasTouch Podcast

50,210 Listeners

SmartLess by Jason Bateman, Sean Hayes, Will Arnett

SmartLess

57,836 Listeners

The Tucker Carlson Show by Tucker Carlson Network

The Tucker Carlson Show

16,924 Listeners