The Compliance Divas Podcast
Our podcast covers current topics such as infection prevention and control, OSHA and HIPAA compliance for dentistry. We discuss the latest regulatory information, answer frequently asked questions and give suggestions for dental practices to make compliance easy and sustainable. The Compliance Divas are a trusted source for consistent, accurate information based upon current guidelines, standards, science, and recommendations.
The Compliance Divas Podcast
#205 Does HIPAA Require the Use of Encryption?
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Email encryption ensures that only authorized individuals have access to patient information and it's required under the HIPAA Security Rule. Having the right program makes it easier to be compliant and protect your patients' sensitive information. In this episode, the Divas provide tips for evaluating your current email encryption program.
- HIPAA Security Rule updates: https://www.hhs.gov/hipaa/for-professionals/security/hipaa-security-rule-nprm/factsheet/index.html
- Holland and Hart Law article: https://www.hollandhart.com/hipaa-emails-texts
Welcome. I'm Leslie Cannon. I'm Mary Gavoni.
SPEAKER_00I'm Linda Harvey. I'm Olivia Juan. And together we are the Compliance Divas.
SPEAKER_03Welcome to the Compliance Divas Podcast. This is Linda Harvey and I will be your moderator for this episode. As the Compliance Divas, we bring clarity and simplicity by navigating the regulatory world to keep you on course. We invite you to subscribe to our podcast through your favorite podcast channel or on our website, thecomplicedivas.com. As always, any resources that we mentioned can be found in the show notes today. And we invite you to submit questions to support at the compliancedevas.com. And don't forget to scroll down and leave us a review at the end of today's podcast. Well, today the Divas are talking about something very important related to your patients and patient care. And that is actually HIPAA and email encryption. It may not sound very exciting, but it certainly is very important for protecting the practice and patients and just overall good business. We know that the HIPAA laws set strict guidelines for covered entities to ensure that protected health information, known as PHI, remains private and secure, whether it's being transmitted or being stored. So we know it's not a new requirement, but it's important that we delve into just a little bit of this today to make sure that you have the basics covered. I'd like to call on our Olivia first and talk about maybe Olivia, what are some of the obligations that practices actually have? Let's before we talk about email encryption, let's talk about kind of like the framework around it. What do offices actually have to have in place, Olivia?
SPEAKER_00Well, very basically, Linda, the HIPAA rules require that we assure the confidentiality, the integrity, and the availability of the protected health information that the dental practice is creating or receiving, maintaining, and transmitting. So that's just a basic generic response of our obligations. And as it relates to email, there's obligations there too. And I want to differentiate, Linda, the security rule does not expressly prohibit the use of email for sending electronic protected health information. But they're supposed to be, as I mentioned, standards for access control, integrity, transmission security, and also having policies and procedures in place and assuring that there's no unauthorized access to the electronic protected health information. Now, what gets confusing, Linda, is through the standard as we knew it, encryption was listed as addressable. But now over the years since the rule was published, we've seen quite a bit of changes in technology and how easy it is to encrypt and also monitor. So we are looking at proposed rule changes where encryption would be made mandatory. So just to briefly summarize it, email encryption services can actually block a significant amount of potential attack from a cyber criminal and protect the information. Now, personally, I just got through working on a case for a dental office that that's how their data breach occurred. They were using uh standard email, which did not have the security level to protect the data. And so that's one of the ways that we protect the information on our network systems, is making sure that the email is protected so that it minimizes the risk of a phishing email attack. Because once the link is clicked on, it deploys the ransomware into the system, which uh has malware and could cause a significant attack on the data, resulting in uh breach notification and and all these other issues. So just to uh just briefly mention that you know it's not difficult to encrypt and it's uh one of the most important ways that we can protect our system.
SPEAKER_03Thank you, Olivia. You mentioned quite a few important details, and I'd like to summarize one or two because I just think they are so important for our listeners. Yes, these rules are not new. The security rule became effective in 2005. And now we are waiting for uh the passage of the revised security rule. So in anticipation of that, it's best to be sure you have the basics from the original security rule in place and that you haven't gotten slack because otherwise that happens exactly what happens to the client you worked with, Olivia. You end up in just a lot of hot water with some kind of a data breach, and now it's reportable, a lot of expense, your reputation is at risk, and a lot of different issues that come up with that. So it's important to realize that we have to maintain the confidentiality and the integrity, meaning meaning that nothing has happened to the data. It hasn't been, I'll use the word spoiled, even though that's not the right technical word, but spoiled or it's corrupt so you can't use it. You know, we've all had files that have been bad and we couldn't open them. And the availability means it has to be available when the team needs it to be available. So I couldn't agree with you more about the fact that we need policies and procedures. So I would encourage our listeners to look back through their HIPAA binder and be sure they have an email, pardon me, be sure they have a policy and procedure on email and the use of email. And then you while you can rely on your IT or maybe another software company to provide the encryption for you through a program, it's uh ultimately the doctor's responsibility and the practice to be sure they are compliant and everybody is using the encrypted email when sending PHI. So thanks again, Olivia. Leslie Oh, Olivia, yes.
SPEAKER_00I just wanted to add another point there, Linda, that you know, when we're creating policy, we probably have language in the policy not to use free consumer emails, email accounts, and to make sure emails encrypted if it contains EPHI. But it all boils down to what are we actually doing? What is the actual performance? Because if we're just creating policy without performance, it means nothing to the Office of Civil Rights. So we want to prevent something bad happening before we have to address it.
SPEAKER_03That is was beautifully stated, Olivia. Yes, it's not just about having some nice policy either on your computer or on a portal or in a binder. It's about living those policies. And that's so very important. Because otherwise, if you're not, you have no defense with the Office of Civil Rights as you just mentioned. So kind of turning around just a little bit, I'd like to call on our diva Leslie. Leslie, can you share with us some issues that occur when encryption is not used?
SPEAKER_01Well, Linda, you know, the encryption actually helps to guard against the cyber threats as Olivia was mentioning, and uh it also helps to mitigate those risks of hacking, phishing, or data interception, making it harder for cyber criminals to exploit our communication than the vulnerabilities that we have. And did you know, Linda, that uh in two in 2024, over 75% of the targeted cyber attacks actually started with an email uh that made phishing a primary vector for cyber criminals to be able to get into our systems and to cause all this havoc. And this is sourced from Norton Antivirus. And something else that is kind of interesting is that uh we don't actually know when somebody is attacked or when our systems are attacked. It can be as many as 118 days prior to our recognition that something's not right. So it's uh been sourced through uh another as a company called Thought Lab that it does take the average time to detect a data breach is 118 days. That's kind of scary because the how much information has been pulled from our system and and uh transmitted in a way that is not uh acceptable.
SPEAKER_03Leslie, I think that's a point that should really let resonate with our listeners that it's a hundred could be as much as 118 days and maybe even longer before the ransomware is deployed, but it's in the system calling information and learning about software, well, pardon me, learning about your passwords and knowing where they're going to cut off, where's the backup, and they're looking for all kinds of things in your system, they're gathering all kinds of data. So, and that's an important piece to know whether or not something is reportable to the Office of Civil Rights when a forensics is performed on that computer system. So it's very important to understand what's happening and how there could be such a lag time because you can come back after a three-day weekend or a vacation and all of a sudden you're locked down, you think, well, what happened while we were gone? Well, it didn't necessarily start then, right? Let's say it started way long before then. So good points. Thank you so much. We talked about the obligations of a covered entity, which all is all dental practices, and the things that can happen when they don't follow these obligations. Can you share with us some items that our listeners can look out for when they're evaluating an encrypted email system to make sure that theirs is truly as sufficient and protecting the data as it should?
SPEAKER_02Absolutely, Linda. The first criteria is that it's not a free mail application, that a consumer free email application is not appropriate to be used for transmitting protected health information. But I tell my clients, don't even use it for any kind of a communication in your dental office because, as Leslie and Olivia just said, it if you use an encrypted email that is a secure email, it's helping to filter out um phishing attempts and spam email. And it's also making sure that you're following best practices. Um that and that's going to be a big change when this new rule, as Olivia said, when this new rule gets implemented, that there were a lot of things that were addressable before, meaning sort of scalable for a smaller business, a smaller dental practice, but now will become required. But the big question I would always have is if it was addressable and you weren't doing it and you knew there was a better way, then why didn't you do it? Um, and that probably wouldn't sit well with the Office for Civil Rights. So there's things we need to look at. My suggestion that I make to my practices I work with is talk to the company or the folks that host your website because most of those companies have secure email that you can use for non-PHI. And then they may have a higher level of encryption, um, or you may have to use a subscription service for encryption when the emails have PHI. So if you're using an email address that is based on your URL for your website, that is a good marketing thing because it's identifying who you are, and it has a higher level of security. So then there are really five things you need to look for, and this is where the um the tech support people and your website hosts and so forth can come into play and help you. Number one, you have to have transmission security, a certain level of encryption higher than what may be done for non-PHI. Then you have to have authentication. There has to be a direct way to authenticate you as a user of that email that you have to have a password. And in some cases, there's now two-factor authentication to be able to use that. Access control. So once you are finished transmitting, it automatically logs you out. So that connection doesn't stay active. That could be hacked. And then audit control. I would guess that most practices don't even look at the audit controls for their email for get a report of phishing attempts and spam um attempts, somebody trying to spoof your email address and masquerade as you or your practice, those types of things. The same as many people don't look at the audit trail in their practice management software to see what's going on. And then the final thing is one of the things that Olivia mentioned before is integrity, making sure that that information is always available and that comes through a secure backup. You are required to keep copies of those emails that have been sent, and they have to be stored in a secure backup that can't be hacked, but that can be accessed.
SPEAKER_03Thanks for that great information, Mary. That's also very helpful to understand what are some of the components that our listeners should be looking for when evaluating their own system. And as you mentioned, free consumer emails just don't work. They're fine for maybe a business email. You want to have lunch with a colleague or something, but really it's just best to rely on the encrypted email services. Because I'll never forget when I was attending, and I know many of the divas did as well, the Office of Civil Rights Security Conference last fall. One of the speakers mentioned that artificial intelligence is supercharging ransomware. So it's getting harder and harder to keep our data secure. So it's important that we follow the regulations and best practices. I'd also like to mention when you're thinking about the types of email encrypted services to determine what kind of data you're sending. So when you need to share large data files, images such as CT scans, then is your email provider able to send a file at large, or can you zip it or condense it so that it can be mailed through your traditional encrypted email program you're using? Otherwise, you may need to have an encrypted portal for your practice, another paid subscription service that you know is HIPAA compliant, that you would have a business associate agreement in place, and that they are too uh as well HIPAA compliant. An encrypted portal is much preferred as some of the free services in them. I'm just going to mention a several like Google Drive or Dropbox, which you can have paid subscriptions on those, obviously, and different levels of security. And you may or may not be able to get them to complete a business associate agreement. So it's best to conduct practice in your business with HIPAA compliant programs that are meant to be used in healthcare versus generic programs, because those programs don't make an office compliant. You make the you make yourself compliant with the policies, procedures, and practices that you put into place and follow. So be very careful with some of these non-healthcare parties when you're sharing data, whether it's with a referring office, a specialist, or even your lab, make sure you're using HIPAA compliant portals if you need something for large files and images. Divas, you've provided some great tips today. Any other thoughts or ideas that you'd like to share? Mary?
SPEAKER_02Yes, I think that it's really important for our listeners to understand really the purpose of encryption. So if I'm just using a Gmail address and I'm going to send an X-ray to another practice, it's not so much the sensitivity of that x-ray. People say, well, no, there's no name on it, nobody can identify who it is. It's really about opening up your server or your portal to hackers. So when you encrypt something, what the encryption platform does is copies whatever that image or document is, stores it securely in a password-protected portal, and it stays there until the recipient gets the message that you know, Mary sent you an encrypted message, click this link, and then they have to have a password and a login, maybe even two-factor authentication, to access that image. So now there's no electronic pathway back to your server or to the recipient's server. I call it the electronic trail of breadcrumbs. And so nobody can intercept that. So that's really the purpose of it is to prevent those electronic trails out there from being accessed and followed back to the servers.
SPEAKER_03Great analogy, Mary. I think we can all identify with the breadcrumbs. That's perfect. Leslie, what are your thoughts?
SPEAKER_01Well, I always want to remind our listeners as well to be especially vigilant when you think that you're clicking on something that's from a reliable, trusted source. It may not be because the cyber criminals are very sophisticated and they can do some research uh on your neighborhood and see who your specialists are. And it'd be very easy to change the uh email address from uh drjones at uh drjones.com to drjones at drjones.net. And you are thinking you are seeing the uh the usual referring back and forth uh emails and x-rays and communication. So to be especially vigilant when you're clicking on something, make sure that you look carefully at the sender's email address. And then something else that uh that this all bubbles up to me is you know, just on emails in general, uh, outside of the world of encryption, I've been getting lots and lots of emails from various different service providers. Uh, for example, uh, Miriam and I were talking earlier about our toll. We have a I have a fast pass in California, and I keep getting text messages that I'm delinquent on paying my toll fees, and I know I'm not, but as I look closely at them and as I hover over the sender's email address, I can see that they're fishing. They're trying to get me to click on something. They're giving me something that's a sense of urgency that I have to take care of. And I think, you know, when we work in a dental office, we're absolutely focused on our patients and patient care and the phones ringing and who's in front of us at the desk and the task at hand. And sometimes we may be just a little bit off as far as focusing fully on what we're doing when we're responding to emails or when we're sending emails. So it's important to be aware, have that antenna up at all times. And uh uh just that other tip is watch out for these attacks that may be coming in uh through emails to you that look like they require you to take action and take it immediately. And there's just one other thing I wanted to mention that is something that came up last year for uh actually FBI had uh noticed American Dental Association, there was some cyber activity attacking the Oral Surgery Association, where there was people who were uh cyber criminals posing as patients, and they were trying to send in a new patient form or claim they couldn't do it through the oral surgeons' platform, the whatever their system they were using. So they asked if they could just simply send it by email, their new patient forms, as an attachment. And as uh, you know, it would seem like a legitimate request, right? You don't want to uh insult a new patient of not being able to use your portal and you want them to be able to send their information in. Well, they were cyber criminals opposing as new patients, and as soon as the offices clicked on these links, that was the the end of the story, as you know. They they were subject to the ransomware and the malware, et cetera. So vigilance is so important, and encryption is uh, those are the guardrails for us when we're sending emails. And and uh it I know that sometimes people think it's just difficult to send that referring doctor uh a password and explain to them how to use encryption, but it's really simple. It's simple for people on the other end to receive an encrypted email, and uh it's uh just the effort that we all need to be focused on. I get asked the question about whether email is required over and over and over again when I speak or when I consult, and it is just best practices.
SPEAKER_03Oh, thank you for summarizing that so nicely, Leslie. That was beautiful. It is best practices, and it's it's and I liken it to patient safety as well, because when data is exfiltrated, when it's stolen, when it's resold on the dark web, you never know how that's going to impact their patients personally and professionally. So it's very important that we um protect all of our information. This is a very content-rich podcast on email and encryption and following the HIPAA laws that are in place and staying tuned for some of the updates that we expect to be coming in months. So, as a quick wrap-up, let's talk about the fact that we saw we mentioned not using free email systems, making sure the email system you have is HIPAA compliant using some of the tips that Mary shared, and making sure that you are following your policies and your practice and best practices and not just have policies and procedures written that you aren't living out and taking them to heart. And then lastly, one thing we did not mention was removing access to your email systems and any part of your data, any of your uh software programs when someone leaves the practice. So we hope that you have some great tips you can take back and share with your office and to be sure you're protecting your patient data as fully as you're required to. Thank you for joining us as the Compliance Divas. We bring clarity and simplicity to compliance by navigating the regulatory world to keep you on course. We invite you to subscribe to our podcast through your favorite podcast channel or on our website, thecompliancedevas.com. The resources that we mentioned today can be found on our podcast show notes. And we always invite you to submit questions to support at thecompliancedeevas.com. And we would love to hear from you. So scroll down the bottom and leave us a comment or a like. And we will see you the next episode.