Paubox just launched an attachment preview for quarantined messages. The new feature allows customers to see the attachments for quarantined emails without actually downloading the message. Customers can now preview attachments in both inbound and outbound quarantine. However, there is a big difference between inbound and outbound quarantine.
Inbound email quarantine contains suspicious incoming mail directed toward the organization. Outbound email quarantine contains messages that were prevented from leaving the organization.
Typically, outbound mail is quarantined because it may violate a security policy or data loss prevention rule. Since inbound quarantine contains emails attempting to enter an organization, its purpose is to prevent external attacks against both employees and information systems. Outbound quarantine, on the other hand, prevents sensitive patient data from leaving the practice.
What is email quarantine?
Email quarantine refers to a controlled storage environment for email messages that meet specified security criteria. Rather than allowing automatic delivery, a HIPAA compliant email solution quarantines the message and allows it to be reviewed, deleted, or released.
Just because a message is quarantined doesn’t necessarily mean that it is malicious or violates HIPAA. Various rules can cause email quarantine and false positives are possible. Sometimes a valid email might trip a protective rule. Therefore, before responding to or deleting a quarantined message, covered entities should examine the email, the sender, the recipient, and the rationale for its quarantine.
While email quarantine isn’t an explicit patient data security requirement under HIPAA, it may be part of a technical safeguard strategy. According to the HHS summary of the HIPAA Security Rule, covered entities are required to implement “reasonable and appropriate administrative, technical, and physical safeguards to protect electronic protected health information created, received, used, or maintained by a covered entity against known threats and unauthorized uses and disclosures.” If email quarantine helps your organization achieve that goal, it may be right for an organization's risk analysis.
What is inbound email quarantine?
Inbound email quarantine isolates messages headed to individuals inside a healthcare organization. Malicious insiders aren’t typically targeted by inbound email quarantine features. Inside an inbox, emails can contain phishing links, malware, spam, suspicious attachments, impersonation attempts, and other risky content. They may even be legitimate emails sent by someone with an infected device.
In general, there are eight categories of inbound mail:
- legitimate mail
- spam mail
- gray mail
- phishing mail
- ExecProtect mail
- virus mail
- macro virus mail
- data loss prevention matches
Emails from the highest risk categories can be quarantined instead of heading straight to an employee inbox. Using inbound quarantine, healthcare entities can prevent suspicious emails from reaching employees. Then, authorized personnel can investigate the quarantined mail. It gives users more time to evaluate the message and lowers the likelihood that an employee will open a dangerous attachment or hand over their credentials.
To give a practical example of phishing email danger, researchers at six US healthcare organizations analyzed almost 3 million simulated phishing emails. Staff clicked on 14.2% of the emails, that’s nearly 1 in 7 simulated phishing emails. HIPAA compliant email that features inbound quarantine places a technical control point just before that click. However, it should be complemented by consistent workforce training.
In a Paubox report, 68% of surveyed healthcare leaders reported a phishing attack during the prior 12 months. Among the attacks that were known by IT, only 5% were reported by employees. Healthcare organizations shouldn’t expect their employees to catch every malicious email.
What is outbound email quarantine?
Outbound email quarantine holds messages sent from the healthcare organization before they reach an external recipient. It is commonly connected to data loss prevention (DLP) which uses rules to identify sensitive information and prevent it from leaving an organization improperly.
For example, an outbound message may be quarantined because it contains a patient identifier, is addressed to a restricted domain, includes an attachment matching a DLP rule, or is being sent to an unauthorized recipient. The exact result depends on how the organization configures its rules.
Paubox DLP can apply rules to inbound messages, outbound messages, or both. Administrators can configure those rules to inspect the sender, recipient, subject line, headers, body, and attachments. When an outbound email triggers a rule, it can be held for review before it leaves the organization.
Many email disclosures do not begin with an external attack. Paubox research found that 60% of surveyed healthcare organizations had experienced accidental PHI exposure through email. Common examples included messages sent to the wrong recipient or sent without appropriate encryption.
Moreover, a Perspectives in Health Information Management study of 1,485 healthcare breach events identified 382 incidents associated with carelessness or negligence. Of those incidents, 212 involved PHI being mailed or emailed to the wrong recipient. Outbound quarantine allows compliance teams to review a matched message before a similar mistake becomes an external disclosure.
How to review quarantined email in healthcare
Healthcare organizations can manage quarantine access based on role. Paubox’ quarantine guide recommends giving admins the ability to see quarantined email organization-wide and only limiting users to messages they’ve sent. Roles can be defined further by release authority and controls for adding sender addresses/domains to your allow/block lists.
Exercise caution before allowing a sender/domain. Remember that an allow rule will apply to future messages as well, so it should be decided upon using verified sender information and an understanding of why the message was quarantined. Malware, phishing, and impersonation filters should not be circumvented just because the content looks familiar.
Quarantined outbound mail should be handled with a clearly defined workflow as well. A compliance officer should verify that the recipient is allowed to receive the information, that the disclosure is allowed, that the minimum necessary applies, and whether the message should be corrected before disclosure. If protected health information (PHI) has been disclosed already, your incident response process should be leveraged, as the HHS Breach Notification Rule considers improper disclosure a breach unless a documented risk assessment proves a low probability of compromise.
Safer attachment review in inbound and outbound quarantine
The Paubox attachment preview update works for quarantine messages in both directions. Supported image files, PDFs, plain-text documents, Excel, and Word attachments can now be opened right in message view. Files are detected by their actual contents, instead of just filename. And the preview renders in your browser without uploading the file to a third-party viewer.
File previews will be disabled for any message containing attachments identified as viruses or macro malware. Those attachments will remain download-only. Messages can be reviewed safely and supported, lower-risk attachments can be previewed, preventing ‘just this once’ attitudes where a preview feature is treated as an opportunity to open clearly malicious attachments.
Inbound quarantine and outbound quarantine work hand-in-hand. Inbound catches threats before they reach your employees. Outbound catches sensitive info before it reaches the wrong person. Bidirectional email protection that’s HIPAA compliant can help minimize weak spots created by asking human beings to be perfect.
FAQs
Can outbound quarantine prevent every HIPAA violation?
Outbound quarantine can reduce certain disclosure risks, but healthcare organizations still need encryption, access controls, workforce training, risk analysis, and incident response procedures.
Does quarantine replace email encryption?
Quarantine decides whether a message should proceed, while encryption protects the message during transmission.
Is every outbound DLP alert a reportable breach?
No, a message stopped before disclosure may be a prevented policy event rather than a breach.
