Email is one of the most important communication tools in public health. Public health organizations use email to coordinate disease surveillance, communicate with healthcare providers, distribute laboratory results, manage vaccination campaigns, notify stakeholders of emerging health threats, and collaborate during emergencies. Beyond supporting communication between healthcare professionals, email also plays an important role in public engagement and education. As the authors of Email for the provision of information on disease prevention and health promotion note, “Email can be used as a one-way, healthcare professional-to-patient method of providing information on disease prevention and health promotion.”
What is email used for in a public health setting?
According to Email for the provision of information on disease prevention and health promotion, email is primarily used to deliver “advice or recommendations intended to help recipients improve health, avoid ill health, or maintain good health.” This allows healthcare professionals and public health organizations to provide evidence-based information directly to patients and caregivers in a timely and accessible manner.
In public health, email can support a wide range of health promotion and disease prevention activities, including:
- Health education: Sending educational materials on healthy eating, physical activity, smoking cessation, mental well-being, and other lifestyle behaviors that reduce the risk of disease.
- Disease prevention: Providing information on vaccination, infection prevention, chronic disease risk factors, cancer screening, and other preventive health measures that help individuals make informed healthcare decisions.
- Preventive care reminders: Encouraging participation in routine healthcare by reminding patients about immunizations, health screenings, annual check-ups, and follow-up appointments.
- Public health campaigns: Distributing evidence-based information during awareness campaigns to promote healthier behaviors and improve health literacy across communities.
The review also points to the advantages of email as a communication tool. It notes that email “has the potential to be low cost and instantaneous,” making it an efficient way to distribute health information to large numbers of people. Unlike printed materials, email can also include links to trusted resources, allowing recipients to access more detailed guidance whenever needed.
However, the authors conclude that there is currently “insufficient evidence to determine whether email can improve health behaviours or other outcomes compared with no intervention or alternative interventions.” While email is an effective channel for disseminating public health information, it is most effective when used alongside other communication methods, such as text messaging, websites, social media, and community outreach initiatives.
The widespread use of email also creates new security challenges, thus, public health organizations must protect sensitive information from unauthorized access while ensuring critical communications remain available.
Why secure email matters in public health
Public health organizations operate at the intersection of healthcare, government, and community services. Their work depends on the timely exchange of information with a diverse network of partners, including:
- Hospitals and health systems
- Clinical laboratories
- Primary care providers
- Pharmacies
- Emergency medical services
- Government agencies
- Community health organizations
- Schools and universities
- Long-term care facilities
- Health insurers
Many of these communications involve sensitive information, such as:
- Patient referrals
- Laboratory test results
- Disease investigation reports
- Vaccination records
- Contact tracing information
- Health surveillance data
- Employee health information
- Administrative records
Much of this data qualifies as protected health information (PHI) under the Health Insurance Portability and Accountability Act (HIPAA). If unauthorized individuals gain access to these communications, the consequences can be significant, including identity theft, regulatory penalties, operational disruptions, and loss of public confidence.
Unlike many private organizations, public health agencies also play a critical role during disease outbreaks and public emergencies. Any disruption to email communications can delay investigations, hinder coordination among agencies, and negatively impact patient care and public safety.
HIPAA requirements for secure email
Public health organizations that qualify as covered entities or business associates must comply with the HIPAA Security Rule when transmitting electronic PHI (ePHI). This rule “sets forth the administrative, physical, and technical safeguards that covered entities and business associates (collectively, “regulated entities”) must put in place to secure individuals’ electronic protected health information.”
Key safeguards include:
- Encrypting ePHI whenever appropriate
- Implementing access controls
- Using unique user IDs
- Maintaining audit logs
- Performing regular risk analyses
- Training workforce members on security best practices
- Having procedures to respond to security incidents
HIPAA does not explicitly require every email to be encrypted, but organizations must assess risks and implement reasonable and appropriate safeguards to protect ePHI.
Common email security threats in public health
Public health organizations are attractive targets for cybercriminals because they handle large volumes of sensitive health information and often communicate with multiple external partners. A compromised email account can expose PHI, disrupt public health operations, and delay the delivery of essential services.
Some of the most common email security threats include:
Phishing
Phishing attacks use fraudulent emails to trick recipients into revealing login credentials, downloading malware, or sharing sensitive information. Attackers often impersonate trusted organizations, healthcare providers, laboratories, or government agencies, making these messages difficult to distinguish from legitimate communications. According to a Paubox report, What small healthcare practices get wrong about HIPAA and email security, “As of 2024, over 70% of healthcare data breaches originated from phishing attacks.” Equipping employees with the skills to identify suspicious emails and implementing technical safeguards can prevent phishing messages from reaching users' inboxes.
Business email compromise
Business email compromise (BEC) occurs when attackers gain access to or impersonate a legitimate email account to deceive employees into transferring funds or disclosing confidential information. In public health settings, these attacks may target payroll departments, procurement teams, or staff responsible for handling patient or laboratory data.
Although the U.S. Department of Health and Human Services (HHS) breach data does not classify impersonation attacks as a standalone category, Paubox notes that business email compromise appears repeatedly in many of the most damaging healthcare email breaches reported in 2025. These incidents are typically recorded under broader categories such as “Hacking/IT Incident” or “Unauthorized Access/Disclosure,” highlighting the significant role that email impersonation continues to play in healthcare cyberattacks.
Ransomware
According to a Paubox report, “Attackers distribute malicious software through email attachments or links,encrypting files and demanding ransom for decryption keys.” Once opened, malware can spread across an organization's network, encrypt critical systems, and disrupt access to laboratory data, surveillance systems, and other essential public health services.
Email spoofing
Email spoofing involves forging the sender's address so that a message appears to come from a trusted individual or organization. Cybercriminals use spoofed emails to distribute malware, steal credentials, or convince recipients to disclose sensitive information. “Criminals count on being able to manipulate you into believing that these spoofed communications are real, which can lead you to download malicious software, send money, or disclose personal, financial, or other sensitive information,” says the FBI.
Human error
Not every email security incident is the result of a sophisticated cyberattack. Employees may accidentally send PHI to the wrong recipient, click on phishing links, reuse compromised passwords, or misconfigure email settings, increasing the risk of unauthorized access and data breaches.
Human error continues to be one of the leading causes of healthcare breaches. According to Verizon's 2024 Data Breach Investigations Report, the human element was involved in the majority of healthcare data breaches, including phishing, the misuse of stolen credentials, and errors such as misconfiguration. The report also notes that healthcare remains a high-risk sector because of its reliance on email, time-sensitive workflows, and the large number of employees who require access to sensitive clinical and administrative information.
Best practices for secure email in public health organizations
Protecting sensitive health information requires a combination of technical safeguards, organizational policies, and employee awareness. The following best practices can help public health organizations strengthen email security and support HIPAA compliance.
Encrypt sensitive emails
Encryption helps protect the confidentiality of ePHI by preventing unauthorized parties from reading intercepted messages. Organizations should implement encryption whenever emails contain sensitive patient or public health information.
Read more: What happens to your data when it is encrypted?
Enable multifactor authentication
Multifactor authentication (MFA) provides an additional layer of security by requiring users to verify their identity using more than a password. Even if an attacker obtains a user's credentials through phishing, MFA can help prevent unauthorized access to email accounts.
Train employees regularly
Employees are often the first line of defense against email-based attacks. Regular cybersecurity awareness training can help staff recognize phishing emails, verify unexpected requests, report suspicious messages, and handle sensitive information appropriately.
Read also: How staff training ensures HIPAA compliant email
Implement email authentication protocols
Protocols such as Sender Policy Framework (SPF), DomainKeys Identified Mail (DKIM), and Domain-based Message Authentication, Reporting and Conformance (DMARC) help verify that incoming emails originate from legitimate senders. Together, these technologies reduce the risk of domain spoofing and phishing attacks.
Learn more: What is email authentication?
Apply the minimum necessary standard
When communicating by email, organizations should only include the information needed to achieve the intended purpose. Limiting the amount of protected health information shared reduces the impact of accidental disclosures or unauthorized access.
Read also: How to determine the minimum necessary information
Monitor email activity
Monitoring login attempts, unusual account activity, and email forwarding rules can help organizations identify compromised accounts before significant damage occurs. Maintaining audit logs also supports incident investigations and demonstrates compliance with the HIPAA Security Rule.
Develop an incident response plan
Even with strong security controls, email security incidents can still occur. Public health organizations should establish procedures for reporting suspicious emails, containing compromised accounts, investigating potential breaches, and restoring normal operations. A well-defined incident response plan enables organizations to respond quickly while minimizing disruptions to public health services.
Read more: HIPAA compliant email best practices
Secure vs. HIPAA compliant email
Although the terms secure email and HIPAA compliant email are often used interchangeably, they are not the same.
Secure email refers to email systems and practices that protect messages from unauthorized access. Depending on the provider and the organization's needs, this may include encryption, MFA, spam and phishing protection, access controls, and audit logging. These security measures help protect the confidentiality, integrity, and availability of email communications.
HIPAA compliant email goes a step further. It refers to the use of email in a manner that complies with the HIPAA Privacy Rule, Security Rule, and, where applicable, the Breach Notification Rule. Compliance requires organizations to implement administrative, physical, and technical safeguards to protect ePHI. Email security is one component of this broader compliance framework.
For example, an organization may use an encrypted email service, but if it does not perform risk analyses, train its workforce, manage user access, or have procedures for responding to security incidents, it may still fail to meet HIPAA requirements. Similarly, using a secure email platform does not automatically make an organization HIPAA compliant.
To support HIPAA compliance, public health organizations should look for email providers that offer features such as encryption, access controls, audit logs, and multifactor authentication. If the provider creates, receives, maintains, or transmits protected health information on behalf of a covered entity, it should also be willing to sign a business associate agreement (BAA).
Go deeper: The difference between secure and HIPAA compliant email
Secure public health communications with Paubox
Choosing an email solution that prioritizes both security and ease of use is essential for public health organizations. Whether communicating with healthcare providers, laboratories, partner organizations, or patients, organizations need a solution that protects sensitive information without creating barriers to communication.
Paubox helps healthcare organizations send HIPAA compliant email without requiring recipients to log into a portal or create an account. Messages are delivered directly to recipients' inboxes whenever possible using encrypted transport, making secure communication seamless for both staff and patients.
In addition to secure email delivery, Paubox offers inbound email security that helps protect organizations from phishing, malware, ransomware, BEC, and other email-based threats. Features such as spam filtering, malicious link protection, attachment scanning, and spoofing detection help reduce the risk of compromised accounts and data breaches while supporting everyday healthcare communications.
FAQS
Is regular email secure enough for healthcare communications?
Standard email is not inherently secure. Without appropriate safeguards, messages may be vulnerable to unauthorized access, phishing attacks, or interception during transmission. Public health organizations should use email solutions that include security features such as encryption, access controls, and threat protection when communicating sensitive information.
What should employees do if they receive a suspicious email?
Employees should avoid clicking links or downloading attachments from suspicious emails. Instead, they should report the message to their organization's IT or cybersecurity team, verify unexpected requests through a separate communication channel, and follow their organization's incident reporting procedures.
Can secure email improve public trust?
Yes. Protecting sensitive health information demonstrates an organization's commitment to patient privacy and data security. Secure email practices help reduce the risk of breaches, support regulatory compliance, and foster trust among patients, healthcare providers, and community partners.
