Skip to the main content.
Talk to sales Start for free
Talk to sales Start for free
REPORT

How Microsoft and Google put PHI at risk

We tested their encryption claims. What we found shows just how often patient data is left unprotected.

REPORT

2025 healthcare email security report

Key insights from 180 email-related healthcare breaches and actionable steps to protect your organization.

 

Download the report

Cybersecurity graphic
REPORT

2025 healthcare email security report

Key insights from 180 email-related healthcare breaches and actionable steps to protect your organization.


Download the report

2025-03-07_REPORT_StateofSecurity-1

Top takeaways

Think your email is secure? This report reveals a hidden encryption flaw in Microsoft 365 and Google Workspace putting PHI at risk.
Email Being sent icon-2-2

Google Workspace allows delivery over obsolete and unsafe TLS versions

PHI Breach-1

Microsoft 365 can sometimes send protected information in cleartext

Breaking Guidelines-1

Google and Microsoft may not be following NSA recommendations for email encryption

Not protected icon-1

"Using obsolete encryption provides a false sense of security because it seems as though sensitive data is protected, even though it really is not."

Email vs patient portals-1
Email vs patient portals (2)
Low risk email security infographic
HIPAA fines infographic

Key resources

1

2025 Report: How Microsoft and Google put PHI at risk

Explore the real-world testing results, security missteps, and compliance risks every IT leader should know.

2
How Microsoft and Google put PHI at risk executive summary

A high-level overview with the essential findings and implications—designed for quick internal sharing.

3
How Microsoft and Google put PHI at risk infographic

Get a visual breakdown of the key data points and what’s at stake when email encryption fails.

4
Report excerpt: The experiment

Microsoft and Google silently failed encryption tests under real-world conditions.

5
Report excerpt: Why the NSA deprecated TLS 1.0 and 1.1

Outdated TLS is unsafe by design, yet still allowed by platforms.

6
Report excerpt: The myth of "force TLS"

Force TLS gives a false sense of security—and fails silently.