Shared mailboxes may already sound familiar to you; they look like referrals@clinic.com, billing@hospital.org, or appointments@practice.com.

Clinics and hospitals can deploy shared mailboxes to manage patient care coordination responses and ensure messages don’t get stuck in a single staff member’s inbox. But these mailboxes can also house protected health information (PHI) like full names, medical records, appointment requests, billing questions, and treatment inquiries.

Because of this, shared mailboxes need to have cybersecurity measures in place. Tools like HIPAA compliant email can help in this regard by encrypting messages, restricting who can view them, and logging all activity in the inbox.

 

HIPAA compliance starts with cybersecurity

Why should healthcare organizations implement cybersecurity solutions if they have HIPAA security solutions? For starters, according to the HHS, the HIPAA Security Rule requires that covered entities and business associates go about “implementing the most …appropriate administrative, physical, and technical safeguards to protect the confidentiality, integrity, and availability of e-PHI.”

Put simply, that means:

  • Confidentiality so that information isn’t made inaccessible to the wrong people
  • Integrity ensuring information can’t be inappropriately altered or deleted
  • Availability, allowing authorized users to access the information they need

Referral inboxes need to be available to the healthcare professionals that are tasked with coordinating care. However, the organization also needs to ensure that other employees and external attackers can’t read those messages.

Tools like HIPAA compliant email allow organizations to place access controls, encryption, authentication, and monitoring on that workflow. The result is fewer opportunities for data breaches and unauthorized access events while maintaining the ability for staff to collaborate.

 

A shared inbox shouldn’t mean a shared password

Email service providers can allow employees to have delegated access to one mailbox from their individual user accounts. Doing so means multiple people can work together to manage the same messages without sharing the same username, password, or multifactor authentication process.

The difference should be considered, as the HIPAA Security Rule calls for a unique user identification standard. The HIPAA Security Rule’s HHS technical safeguards require covered entities to assign a unique name and number for identifying and tracking user identity.

When employees have their own accounts, an organization can track which individual opened, forwarded, deleted, or replied to a message, as long as the email platform tracks those details. If each employee uses the same username and password, the organization could lose that level of individual accountability.

 

Access should be tied to employee roles

Besides encryption, another core tenant of the HIPAA Security Rule is access control. As per the HHS’s Security Rule Summary covered entities must permit access to ePHI only to those persons or software programs that have been granted access rights.

The principle can be applied to healthcare organization’s email use by restricting shared inbox access to the smallest group of employees that require the data. For instance, not every scheduler may need access to clinical attachments that get routed to a referral team inbox. Access to appointment information may be sufficient for scheduling team members.

A peer-reviewed paper on healthcare access management explains that “privacy considerations call for restricting access to electronic medical records (EMRs) to only the parties needing them.” Although the paper discusses medical records rather than email, the same least-privilege principle supports limiting shared inbox access according to each employee’s responsibilities.

If one shared inbox presents more information than a group of users needs, consider creating separate email addresses, queues, or permission groups to segregate by function. Another best practice is to review user access when employees switch positions within your organization or leave the company.

 

Multifactor authentication adds another layer of security

Multifactor authentication (MFA) requires two or more factors when a user signs in to an account. For example, an employee may enter a password and then approve a login request on a separate application or security key.

HHS 405(d) Health Industry Cybersecurity Practices advises organizations to deploy MFA before granting access to an email account. If hackers steal a legitimate password, multifactor authentication could prevent them from accessing the inbox right away.

Every employee who accesses the inbox should have MFA applied to their account. Allowing numerous employees to sign in with one username and password could make authentication more difficult to manage. It could also weaken individual accountability for those logins.

 

Encryption protects the information while it travels

Inbox security should also protect messages as they travel between users. The HIPAA guidance on email acknowledges that healthcare organizations can send ePHI through email. They must restrict who can view messages, protect the integrity of that information, and mitigate the risk of unauthorized users accessing data in transit.

Encryption can protect PHI as it travels across electronic networks when employees use a HIPAA compliant email service. It makes it more difficult for hackers to read information that was not intended for them.

Of course, encryption is just one part of security. Encryption will not limit who can access an inbox. It will not reveal suspicious logins. It will not stop a legitimate user from emailing information to the wrong person. Encryption is one piece of a larger security plan that should include access controls, multifactor authentication, monitoring, policies, and workforce training.

 

The email vendor might need to sign a BAA

A business associate agreement (BAA) is a contract that defines what a vendor can do with PHI and how it must protect that information. Per HHS cloud computing guidelines, if a cloud service provider creates, receives, maintains, or transmits electronic PHI on behalf of a covered entity, the cloud service provider is likely a business associate. It also clarifies that this includes email vendors that store email messages containing ePHI, even if those files are encrypted and the vendor does not have the key to decrypt them.

In Paubox's Breach Report from 2026, breaches caused by vendor and business associate email exposure made up 28% of all incidents we analyzed, representing the largest breach category featured in the report.

Because of that reality, covered entities should ensure their email provider is willing to sign a BAA for the specific services associated with your shared inbox solution. You should also verify if the agreement extends to integrated apps, archived mail, backups, and any applicable subcontractors. While a signed BAA provides contractual security, covered entities should also evaluate the vendor’s access controls, encryption standards, monitoring practices, and incident-response plan.

 

FAQs

Should everyone at the front desk have access to every shared inbox?

Access should reflect each employee’s responsibilities. A scheduler may need appointment information without needing access to clinical attachments, billing records, or referral documents.

 

How often should shared-inbox access be reviewed?

HIPAA does not establish one fixed review schedule. Organizations should review access periodically and whenever an employee changes roles, transfers departments, or leaves the organization.

 

What should administrators look for in shared-inbox audit logs?

Administrators can look for unusual sign-ins, unexpected downloads, deleted messages, permission changes, and newly created forwarding rules.