According to The 2026 Healthcare Email Security Report by Paubox, 170 email-related breaches were reported to the HHS Office for Civil Rights in 2025. Furthermore, 41% of those breached organizations fell into a high-risk category based on their email configuration, up from 31% the year prior. Three quarters lacked effective DMARC enforcement (a policy that tells email providers what to do with messages that fail authentication checks, like rejecting or quarantining them), over half had permissive or missing SPF records (a list of servers allowed to send email on a domain's behalf), and none of the breached organization enforced MTA-STS (a protocol that requires email to travel over an encrypted connection rather than being sent in plain text).

Paubox is built specifically to meet HIPAA's rules and close exactly these kinds of gaps. Here are six of its features that directly address what HIPAA requires and the regulations that enforce them.

 

1. Automatic email encryption

HIPAA's Security Rule at 45 CFR § 164.312(e)(2)(ii) requires that covered entities "implement a mechanism to encrypt and decrypt electronic protected health information" when transmitted electronically.

Paubox encrypts every outbound email automatically, without requiring the sender to take any extra steps or set any settings. Messages are delivered securely using Transport Layer Security (TLS) 1.2 or higher, keeping PHI protected as it travels to the recipient's inbox. Unlike systems that require patients to log into a separate portal, Paubox delivers encrypted emails directly to the recipient's regular inbox.

The report notes that none of the breached organizations analyzed enforced MTA-STS, meaning every one of them "relied on opportunistic TLS, a setting that attempts encryption when the receiving server supports it but falls back to sending messages unencrypted when it cannot." Automatic encryption removes that risk by making secure delivery the default.

Read also: User guide: Paubox email encryption

 

2. Inbound threat protection (Anti-phishing and anti-spoofing)

45 CFR § 164.306(a)(2) requires that organizations "protect against any reasonably anticipated threats or hazards to the security or integrity" of electronic PHI.

Paubox's ExecProtect feature is designed to identify display name spoofing, which is a tactic used in phishing attacks that mimics the names of employees or departments to deceive recipients into opening fraudulent emails. ExecProtect quarantines these emails before they reach the inbox. Additionally, Paubox uses DomainAge to automatically quarantine emails from newly registered domains, which are a known indicator of potential phishing or spam attacks.

The report identifies the specific conditions that make these attacks successful, which are, "missing or unenforced DMARC, permissive sender validation, and unsecured transport" these configurations "allow phishing emails to land, spoofed messages to appear legitimate, and credential harvesting campaigns to succeed." Blocking these messages before they reach the inbox is an effective way to reduce that exposure.

Read also: Inbound email security: Overview

 

3. Data loss prevention (DLP)

45 CFR § 164.312(a)(1) requires "technical policies and procedures for electronic information systems that maintain electronic protected health information to allow access only to those persons or software programs that have been granted access rights."

Paubox's Data Loss Prevention tool scans outgoing email to prevent sensitive data from leaking externally. Admins can customize scanning criteria to look for sensitive keywords in inbound or outbound messages, and any emails that include sensitive information are placed into quarantine to be released or blocked by the administrator. DLP can be used to identify which PHI can be released or blocked by creating rules related to patient names, medical record numbers, or Social Security numbers.

Read also: DLP (Data Loss Prevention): Overview

 

4. Email archiving

45 CFR § 164.312(c)(1) requires covered entities to "implement policies and procedures to protect electronic protected health information from improper alteration or destruction," and the Privacy Rule requires retaining documentation for six years.

Email archiving supports disaster recovery and HIPAA compliance. With Paubox, organizations can automatically archive all messages sent or received. Compliance officers can also access analytics and email reports which can be used for audit preparations.

Read also: Export emails in bulk from the mail archive

 

5. Business associate agreement (BAA)

HIPAA's Privacy Rule at 45 CFR § 164.308(b)(1) requires that covered entities enter into a business associate agreement with any vendor that may have access to PHI. Without a signed BAA, using a third-party email service with patient data is a violation of HIPAA.

A business associate agreement documents that both organizations are held accountable to HIPAA regulation. Paubox provides a BAA with all accounts and is certified as a third party for HIPAA compliance and security.

Related: Provisions of a business associate agreement

 

6. Secure forms

45 CFR § 164.530(c) requires that covered entities have safeguards in place to protect the privacy of PHI, including information collected from patients.

Paubox Email Suite offers a secure contact form that can be integrated into a healthcare provider's website. Patients can fill in their name, email address, phone number, and a message, and can also upload up to 50 megabytes of attachments. Patients access the encrypted contact form through a secure, custom URL. This means intake forms, appointment requests, and patient messages are collected securely without using standard web forms that transmit data in plain text.

The Email Security Report notes that, "patients must be able to trust that sensitive health information in their files is protected to preserve their trust in the patient-doctor relationship and ensure they get the care they need." This means securing every point at which patients share information, including website forms, is necessary to maintaining trust.

Read also: Secure Contact Form

 

FAQs

Does HIPAA apply to all healthcare providers, or only large organizations?

HIPAA applies to any covered entity that handles PHI, including individual practitioners, small clinics, and large hospital systems.

 

Can employees be held personally liable for a HIPAA violation?

Yes, individuals can face personal criminal liability for knowingly obtaining or disclosing PHI without authorisation, with penalties ranging from fines to imprisonment.

 

Does HIPAA cover verbal communication, or only digital records?

HIPAA covers all forms of PHI, including spoken, written, and electronic, meaning conversations about patients in public spaces can also constitute a violation.

 

Are business associates like billing companies and IT vendors required to comply with HIPAA?

Yes, any third-party vendor that handles PHI on behalf of a covered entity is legally required to comply with HIPAA through a signed business associate agreement.