Is Virtru's email recall feature worth it?
Virtru's email recall feature allows users to withdraw access to previously sent encrypted emails when sent to the wrong person in an attempt to...
3 min read
Kirsten Peremore
February 16, 2024
Virtru’s email recall feature revokes access when an email is sent to the wrong recipient. After weighing the feature's pros and cons in the article, Is Virtru's email recall feature worth it?, we determined that it might not be worth it for organizations looking to promote HIPAA compliance.
The Virtru email recall feature works by first having a user send an encrypted email through Virtru. Should the sender need to retract the email, they navigate to their sent items, select the option to revoke access, and confirm this action. If the recipient tries to access the email after revocation, they're notified that access to the content has been removed, effectively preventing them from viewing the sensitive information.
Virtru has an extensive installation and activation process, requiring multiple steps and leading to confusion and inconvenience. This is followed by the need to manually activate encryption for each email, which disrupts the natural flow of composing emails. User complaints include:
These issue contribute to gaps in HIPAA compliance (and the potential of a violation) customers experinece despite the use of the email recall feature. The primary examples of potential breaches that can still occur while using the Virtru email recall feature include:
With the number of email users reaching 4.37 billion by the end of 2023, it offers the ability to reach more patients in a easily accessible way. Virtru however adds additional steps to this process:
The result of this longer and more difficult process has far reaching results for the healthcare organizations using Virtru.
See also: Do patients read healthcare emails?
See also: HIPAA Compliant Email: The Definitive Guide
Is timing important for increasing email engagement in healthcare?
Send emails at times when patients are more likely to read them, such as weekday mornings. Avoid weekends or holidays when possible. Consider patient demographics and their likely schedules when planning your email campaigns.
Is it possible to prevent sending emails to unintended recipients?
Yes it is. Always double-check the recipient's email address before sending, use email software with features like delayed sending or confirmation prompts, and implement an email approval process for particularly sensitive communications.
What is an incident response plan?
An incident response plan is a predefined set of guidelines and procedures designed to identify, respond to, and recover from cybersecurity incidents or data breaches effectively.
Virtru's email recall feature allows users to withdraw access to previously sent encrypted emails when sent to the wrong person in an attempt to...
Last week we received an email with the following Subject line: question about migrating from Virtru to Paubox
The Iowa Capital Dispatch reports that the Iowa Department of Human Services (DHS) is unable to decrypt approximately 432,000 emails encrypted by...
Every Friday we bring you the most important news from Paubox. Our aim is to make you smarter, faster.