How to mitigate the risk of shared email inboxes
Shared email inboxes lack individualized access controls. With multiple staff members sharing a single account, it can be nearly impossible to...
3 min read
Kirsten Peremore
September 18, 2023
Healthcare providers should be aware of the risks associated with shared email accounts because they handle sensitive patient information subject to strict privacy regulations like HIPAA. Shared email accounts can compromise data security, violate regulatory requirements, and expose patient information to unauthorized access or breaches.
A shared email account or inbox that multiple users or team members have access to, allows them to send, receive, and manage emails collectively. While it can be convenient for teams to collaborate and handle incoming messages, shared emails can pose security and privacy risks, particularly when handling sensitive information, as they often lack individualized access controls and encryption measures, potentially exposing data to unauthorized access or breaches.
The key issue revolves around employees sharing login information for a shared account, which is not allowed according to the HIPAA Security Rule. Under this rule, regardless of their size, covered entities are mandated to allocate a unique name or number to each individual or entity with authorized access (defined as a "user" in § 164.304).
This unique identifier is necessary for tracking and identifying user activity within systems containing electronic protected health information (ePHI), ensuring that system access and actions can be traced back to specific users. This requirement applies to all workforce members within healthcare provider offices, health plans, group health plans, and healthcare clearinghouses.
See also: Shared email accounts and HIPAA compliance
To send HIPAA compliant emails and ensure patients' health information is secure and protected during communication.
See also: What are HIPAA's email archiving and retention requirements
Shared email inboxes lack individualized access controls. With multiple staff members sharing a single account, it can be nearly impossible to...
Data encryption scrambles information into an unreadable format, requiring a decryption key for access. In HIPAA compliant email and PHI security,...
Data breaches can have significant impacts on email communication within healthcare organizations. A data breach often leads to sensitive patient...
Every Friday we bring you the most important news from Paubox. Our aim is to make you smarter, faster.