Looking for HIPAA compliant email hosting service

Reaction score
13
Location
Richmond Va
Hey nibblers, I have a client (doctor's office) that is looking to move their email to a hosted solution that is HIPAA compliant. They are looking at Hushmail now. I personally would like to move to hosted exchange via Microsoft's office 365, but I don't know if they are considered HIPAA compliant.

Anyone with any suggestions?
 
Hosted email services are not considered HIPPA compliant. They will need to host their email server in house and use email encryption between all users, and even then someone will get stupid and send an email with PHI to someone they shouldn't, and then here comes HHS to bust you. :mad:

Essentially, your physicians / staff will send email with PHI outside their firewall, to land on a server outside their direct control, and then re routed to the recipient, who more likely than not won't have any serious security to protect the contents of that email.

We secure fax imaging reports to physicians (or directly to their EMR via HL-7 interface), if they want to see the study they have to logon via SSL client to PACS. Any EMR / HIS / RIS / PACS worth the trouble to have will have the ability for users to logon off site (home, other office, etc), so that physicians can collaborate on particular case studies.

Essentially, you have to account for every place the PHI is accessed from, where it went, where it's stored, who had access to it, blah, blah, blah... In the event of a complaint, HHS will demand an audit of the PHI in question, and if they find out it was just emailed out to anyone without encryption, here come the fines.

For an in house LAN messenger I use Softros LAN messenger, that way staff (all behind the firewall) can message each other with all the PHI they want, it's behind the firewall. Softros Messenger also works via WAN as well.

So to make a long winded explanation short, don't send email with PHI via hosted services, ever. If they just gotta, then host the email server in house with full encryption between ALL senders / recipients, even then it probably won't save you during a HHS inspection / audit. :rolleyes:
 
I haven't had to deal with HIPAA myself, but I do know that any typical hosted email solution isn't going to work - you need something like Reflexion. I've heard it's one of the easiest solutions to use & implement and that it's used by a very large percentage of the industry.. I'd start there.

I also believe that HIPAA mandates like an 8 or 10-year retention of all email as well - don't forget to look into archiving too...

-Randy
 
The bank I worked at has a service that all they have to do is put the word encrypt in the subject line it encrypts it and stores it on a server. The recipient gets an email directing them to a URL where they setup an account to view the message.

I don't know the name of the service but you might be interested in looking into that.
 
Just wondering, any update on this? Anyone care to add a successful migration to HIPPA email solution.
 
My healthcare client that needed this service signed up with hushmail.com. I don't work with them on that side of their business too much, but they seem to be happy.

I'd like to know more if anyone else has experience with this.
 
Could you use an email client such as outlook or windows live mail and use the encryption feature...a bit of a pain to install the security certificates at all endpoints.
 
Back
Top