In 2024, Paubox covered the cyberattack on Ascension that started with an employee unknowingly downloading a malicious file disguised as a legitimate one. The attack impacted electronic health records (EHRs), phones, medication ordering, and more throughout their health system.
It brought to the forefront the need for healthcare organizations to have a secure way to safely inspect suspicious files. On July 31, 2026, Paubox announced attachment previews for quarantined messages. Customers can now opt to preview supported attachments inside the message view instead of downloading the original file.
Email quarantine creates a holding area for emails. Administrators or authorized users can review quarantined emails manually before releasing, blocking, or deleting them. Attachment previews can also streamline the review process while minimizing unnecessary file interactions.
What attachment previews change
A study on cyber risks in healthcare explains, “Upon clicking on a phishing e-mail link or opening the attachment, the user loads the malware.” The danger is especially prevalent when the file appears as a benign invoice, referral, lab result, or patient file.
Clinicians and healthcare staff sometimes need to assess whether a quarantined message is legitimate before proceeding with a clinical or administrative process. To do that, they’ve previously needed to download a file to view it more closely, creating another copy of the file on a workstation.
Attachment previews offer a safer alternative. With Paubox, supported attachments appear above the fold in a quarantined message and are represented by file-type icons or image thumbnails. Reviewers can preview the following file types within their web browser:
- Images
- PDF documents
- Plain text files
- CSV files
- Microsoft Excel spreadsheets
- Microsoft Word documents
Why fewer downloads can make reviews safer
A hospital phishing study found that “customization of phishing emails makes them much more likely to be acted on.” Attackers can make messages resemble familiar clinical, billing, human resources, or vendor communications. Healthcare employees are often under time pressure. For example, if reviewing a message requires several distinct actions, an employee may inadvertently release it without previewing the attachment. Alternatively, they may download the file to a convenient but unmanaged location.
Inline previews keep the message review process within the quarantine workflow. According to Paubox, attachments render in the user’s browser without going to a third-party service. For attachments that might contain PHI, this feature also prevents unnecessary exposure to another vendor.
That said, the ability to preview an attachment does not guarantee that the file is secure to open. If a message is classified as Virus or Macros, Paubox automatically disables previews. Those attachments remain download-only based on the upstream scan results. Employees should never interpret “download-only” as safe to open. Attachment previews are one safety feature among many. They do not replace malware filters, endpoint security, access controls, or employee training.
How previews fit into HIPAA compliant email
To defend against these attacks, an article on attacks against healthcare systems notes, “hospitals must employ multiple layers of filtering, detection, encryption, and monitoring.”
Attachment previews help form one of those layers by allowing people to safely interact with isolated messages after automated controls have already scanned them.
HIPAA requires covered entities to implement electronic safeguards that protect the confidentiality, integrity, and availability of electronic protected health information and guard against reasonably anticipated threats or hazards to the security or integrity of such information.
The security standard does not specifically address attachment previews. However, covered entities can still use the feature as part of their reasonable and appropriate technical safeguards. Administrators can combine the feature with restricted quarantine access, malware scanning, audit logging, workforce training, and formal release documentation.
Best practices for reviewing quarantined attachments
Researchers studying simulated phishing attacks at six US healthcare organizations found that “almost 1 in 7 simulated emails sent were clicked on by employees.” Another key finding is that repeated attacks lowered employees’ odds of clicking on malicious links. Mitigation efforts include:
- Restricting who has access to your quarantine portal.
- Previewing attachments before taking any other action.
- Examining the sender, reply-to address, message contents, and listed reason for quarantine.
- Contacting the sender through a known phone number or alternate channel to verify anything out of the ordinary.
- Avoiding virus and macro detections on standard workstations.
- Whitelisting whole senders or domains. Verify any suspicious messages independently before releasing them.
- Logging and investigating repeated false positives, malicious messages, and suspicious outbound attachments.
- Training employees to quickly report suspicious messages and accidental downloads.
FAQs
What is the difference between attachment previewing and sandboxing?
Previewing lets a reviewer examine supported content without downloading the original email. Sandboxing runs a suspicious file in an isolated environment to observe whether it performs harmful actions.
What is a zero-day attachment attack?
A zero-day attack exploits a software vulnerability that the vendor or security tools may not yet recognize. Because a protective update may not exist, filtering, isolation, restricted permissions, and rapid patching are important.
Why are password-protected attachments difficult to scan?
Encryption can prevent email security tools from examining the file’s contents. Unexpected password-protected files should remain quarantined until the sender and business purpose are verified.
Why are macro-enabled documents considered higher risk?
Macros are small programs that automate tasks inside documents or spreadsheets. Attackers can misuse them to download malware, steal information, or make unauthorized system changes.
