$1.25 million HIPAA fine issued to Arizona's largest employer
Banner Health, the largest employer in Arizona, announced today it's recently paid a $1.2 million HIPAA fine for a breach that was originally...
Email breaches were the second most common type of breach in 2024, impacting 109,663 individuals. Healthcare organizations must understand that the anatomy of a HIPAA compliant email is meticulously designed to protect against potential vulnerabilities.
A HIPAA compliant email uses a combination of multiple layers of security as dictated by the Privacy and Security Rules of HIPAA. Based on the Privacy Rule, for an email to be HIPAA compliant it must only be able to be accessed and disclosed by authorized people. This means that safety measures should be in place throughout the emailing process to ensure that no unauthorized access occurs.
“The HIPAA Security Rule specifies a series of administrative, technical, physical, and organizational security standards to ensure the confidentiality and security of electronic PHI. While the technical and physical safeguards address significant information security conditions, such as data integrity, user authentication systems, and transmission security, the administrative safeguards require significant organizational changes such as security awareness and training, security incident procedures, contingency planning, and business associate contracts.” As discussed in the ASA article, the Security Rule sets in place the specific measures that protect this email, from using encryption to implementing access controls.
The basic behind-the-scenes measures to make sure that emails remain HIPAA compliant include:
See also: Top 10 HIPAA compliant email services
Not all email providers are HIPAA compliant.
Not every email a healthcare provider sends needs to be HIPAA compliant, only those that contain or have the potential to expose PHI.
Banner Health, the largest employer in Arizona, announced today it's recently paid a $1.2 million HIPAA fine for a breach that was originally...
Appointment setters, whether they’re working in-house at a hospital or on behalf of a third-party service, often handle sensitive information like...
According to the study Human Factors in Electronic Health Records Cybersecurity Breach: An Exploratory Analysis, unintentional human errors, such as...
Every Friday we bring you the most important news from Paubox. Our aim is to make you smarter, faster.