2 min read

Email DLP (data loss prevention) for HIPAA compliance

Blue keyboard key labeled 'Data loss' with lock icon

Email DLP (Data Loss Prevention) is a strategy for making sure that end users do not send sensitive or critical information outside of a corporate network. The term can also used to describe software that helps IT professionals control what data end users can transfer.  It is included in Paubox Suite Premium. For healthcare organizations and partners, DLP can be great security solution for email security and data security to mitigate risks of violating HIPAA regulations and maintaining HIPAA compliance. Having the additional technical safeguard of a DLP solution can go hand-in-hand with administrative processes to ensure data protection from accidental or malicious release of protected health information (PHI).

 

Types of Data Loss Prevention software

Sometimes referred to as Data Leak Prevention, DLP products all work from the same core principal - using established business rules to identify and protect sensitive information from being shared without authorization. How DLP software products achieve this is different and can be separated into areas based on if data is:
  • In-use: Actions at the endpoints
  • In-motion: Moving over the network
  • At-rest: When stored on a server (like cloud services) or drive

 

Of all the ways data can be accessed and transferred without authorization, email messages is by far one of the biggest risks. This is especially true for healthcare with the push towards electronic health records (EHR) and interoperability. Many healthcare organizations and third-party administrators (TPA) are sending hundreds of emails a day with sensitive content (such as personally identifiable information or financial information) as they collaborate to deliver health services. While some email senders may use HIPAA compliant email encryption for data protection, there is still the risk that some information that should not be shared can be accidentally or maliciously sent. Having a good email DLP solution in place can help mitigate that risk and prevent data breaches.

 

Data Loss Prevention for Email

With a good email DLP solution possessing strong DLP features, business rules are created to classify and protect confidential and critical information. This prevents unauthorized end users from accidentally or maliciously emailing data whose disclosure could put the organization at risk. For example, if a social security number (SSN) is not required to disclose to a third-party vendor who is billing the health plan, then a business rule could be created to identify a SSN in the body of the outgoing email and attachments. If an employee then includes a SSN in the email, when it is sent the email DLP software will identify the SSN, stop the confidential information from being sent, and quarantine the email to be reviewed by an administrator. This type of encryption solution is one your standard Gmail email address doesn't offer.

 

Data Loss Prevention for HIPAA Compliance

DLP is not required for HIPAA compliance, but it can help prevent breaches and email data loss while being a core part of any compliance plan. To maintain HIPAA compliance, organizations need to be sure they have the proper safeguards (Technical, Physical, Administrative) in place so PHI is secure and protected. That means only authorized parties have access to patient data to carry out health care related services, from patient care and standard forms to collecting payments. This includes policies that define what is appropriate to share and who has authorization to share PHI. DLP can help enforce those policies to limit accidental breaches where an employee sends something they weren't supposed to. While not necessarily a must-have, DLP is definitely worth considering for any organization that deals with PHI and other sensitive data on a regular basis.

 

Learn how Paubox Suite Premium can give you complete email security and peace of mind. No pressure consultation and free 14-day trial.

 

Try Paubox for FREE and make your email HIPAA compliant today.
Try Paubox Email Suite Premium for FREE today.
Hand touching a red padlock surrounded by blue locked icons

Email DLP can monitor PHI being sent to personal accounts

In January of 2016, officials at Village of Oak Park discovered an employee had emailed spreadsheets containing the protected health information...

Read More
UofL Health storefront signage

UofL Health sends PHI to wrong email address: 42,000 patients affected

UofL Health in Louisville, Kentucky is the latest healthcare provider to have breached HIPAA by sending protected health information (PHI) to the...

Read More
Padlock with @ symbol representing email security

4000 patient records in New York breached due to nonexistent email DLP

In June 2015, Metropolitan Hospital Center in New York submitted a HIPAA breach notice to the Department of Health and Human Services’ Office for...

Read More

Subscribe to Paubox Weekly

Every Friday we bring you the most important news from Paubox. Our aim is to make you smarter, faster.