Email quarantine is designed to keep suspicious messages away from a user’s inbox, but the quarantine itself can also become an important source of evidence. For healthcare organizations, the next step is determining whether a held message is routine spam or whether it could help explain a potential security incident.
If an email may help reconstruct what happened, identify which accounts or patient information were at risk, or document the organization’s response, preserve a copy before the message and related log data expire. The goal is not to keep every quarantined email indefinitely. It is to recognize when a message has moved from being a security alert to becoming potentially useful incident evidence.
A quarantine flag starts a review
Paubox’s 2026 healthcare email security report explains, “The 2025 breach data shows that risk exists in both directions.” When an email is placed in quarantine, it indicates that there is something that should be looked into further. Spam may only require staff to follow the procedures outlined for documentation and can then be left alone. However, if organizations believe someone has compromised a set of credentials or there are several instances of spoofing, a more extensive procedure might be required.
The HIPAA Security Rule states that an attempted or successful unauthorized act could qualify as a security incident. It goes on to tell organizations what to document about an incident but leaves the incident response relevant to the situation. Keeping an email in quarantine does not mean PHI was disclosed.
Preserve inbound mail when it could explain account access
The Paubox research brief Phishing-driven mailbox takeover was 2025’s most damaging email attack reports, “Phishing-driven mailbox takeovers exposed more than 630,000 individuals in 2025.” It discusses email attacks that occurred at healthcare organizations. If an employee interacted with a suspected phishing message, preserve the message whether they clicked a link, opened an attachment, or entered credentials. Whether they clicked on the link or attachment or provided a password. A series of similar quarantined messages can also reveal a broader phishing or impersonation campaign targeting multiple employees.
The IT or security team can preserve the message and its metadata, then review authentication logs, endpoint alerts, mailbox activity, and other relevant security records. The message can help investigators understand the attacker’s apparent objective, while authentication, mailbox, endpoint, and other logs can help determine whether access occurred. Corresponding logs can help determine whether the attempt resulted in unauthorized access. If an employee’s account may have been compromised, the organization should contact that employee through a verified method. It will allow the team to quickly identify any additional mailboxes compromised and provide safe instructions to employees.
Preserve outbound mail when patient information may be at risk
The study Evaluation of Causes of Protected Health Information Breaches found, “Overall, 603 PHI breaches (53.0%) were internal, attributable to the health care entities’ own mistakes or neglect.” They looked at 1138 breaches that included 500 individuals or more between 2009 and 2017. Applying this statistic to every email that arrives would be an oversimplification. Still, it is a good idea to keep this in mind when examining an email that mistakenly left the organization's network.
When an outbound security rule flags an email containing sensitive information, consider preserving the original message along with any relevant documentation and logs. The privacy and security teams may need evidence showing whether the message was delivered, who received it, whether the information was accessed, and what mitigation steps were taken.
If a copy of that email was delivered. Or the improper access to the information. During the assessment, employees should avoid sending additional versions of the same information unless directed to do so by the response team.
Keep the original message and the surrounding record
The journal article Prevention and mitigation measures against phishing emails: a sequential schema model explains, “By checking for discrepancies between the “from” and “reply to” addresses, system administrators can detect phishing emails.” A screenshot or forwarded copy may omit header and metadata information investigators need.
Where the email security platform supports it, an authorized administrator should export the original message in a format that preserves the available headers, body, attachments, links, and metadata. Make sure to preserve the full email, covering the headers, the main message, attachments, and links. Note the quarantine reason and ID. Include recipient information, dates/times, and any applicable logs. Retain the original as evidence and export a second copy for review purposes. In the course of the investigation, organizations should encourage users to avoid clicking on any links or opening any suspicious-looking attachments.
Protect the evidence while keeping colleagues informed
The review The Chain of Custody in the Era of Modern Forensics states, “The chain of custody demonstrates the integrity of an item of evidence.” For investigations requiring stronger evidentiary controls, the security team may generate cryptographic hashes for exported files and document how the evidence was collected, stored, and handled. Ensure your evidence is stored securely and communicate notifications using a HIPAA compliant email service.
For example, an internal notification might say, “The security team is investigating a suspicious email sent to the scheduling team. If you received the message, do not forward it, open its attachments, or interact with its links. We will provide further instructions after the investigation.”
Document the decision and apply the right retention rule
The healthcare incident response review EARS to cyber incidents in health care advises, “Every step of this process should be documented, and all evidence should be secured during this stage.” Preserved email evidence may later become relevant to a law enforcement request, regulatory review, litigation, insurance claim, or internal investigation. Organizations may need legal counsel when preservation obligations, litigation holds, law enforcement requests, or regulatory reporting requirements apply.
NIST guidance encourages organizations to establish defined procedures for collecting, preserving, retaining, and handling digital evidence during investigations. Those procedures help organizations preserve evidence consistently and document how it was handled. HIPAA requires documentation required by the Security Rule to be retained for six years from the date it was created or the date it was last in effect, whichever is later. There may not be a time frame for every email that is held, but documenting and keeping the email will help guide decisions.
FAQs
What if the apparent sender says the quarantined email is urgent and legitimate?
Verify the request using a trusted phone number or contact method already on file, then let an authorized reviewer decide whether the message should be released.
What if an employee clicked a link before a similar message was quarantined?
Ask the employee to report when they clicked the link and what they entered or opened, then have the security team review the delivered message and account activity.
Should a patient be sent the suspicious message to explain an incident?
Give the patient a clear explanation through an approved secure channel, leaving out active links and attachments.
What if an evidence copy includes unrelated patient information?
Limit access to the original and ask the privacy team whether a working copy can be redacted for wider review.
