{"id":1532,"date":"2021-01-24T01:16:21","date_gmt":"2021-01-24T09:16:21","guid":{"rendered":"http:\/\/blog.stevenreidbordmd.com\/?p=1532"},"modified":"2021-04-16T01:12:42","modified_gmt":"2021-04-16T08:12:42","slug":"hipaa-compliant-email-a-review","status":"publish","type":"post","link":"http:\/\/blog.stevenreidbordmd.com\/?p=1532","title":{"rendered":"HIPAA-compliant email: a review"},"content":{"rendered":"\n<div class=\"wp-block-image\"><figure class=\"alignleft\"><img loading=\"lazy\" decoding=\"async\" width=\"225\" height=\"275\" src=\"http:\/\/blog.stevenreidbordmd.com\/wp-content\/uploads\/2021\/01\/secure_email.jpg\" alt=\"\" class=\"wp-image-1535\" srcset=\"http:\/\/blog.stevenreidbordmd.com\/wp-content\/uploads\/2021\/01\/secure_email.jpg 225w, http:\/\/blog.stevenreidbordmd.com\/wp-content\/uploads\/2021\/01\/secure_email-123x150.jpg 123w\" sizes=\"auto, (max-width: 225px) 100vw, 225px\" \/><\/figure><\/div>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>The problem<\/strong><\/h4>\n\n\n\n<p>In the months since the COVID-19 pandemic <a rel=\"noreferrer noopener\" aria-label=\"forced (opens in a new tab)\" href=\"http:\/\/blog.stevenreidbordmd.com\/?p=1480\" target=\"_blank\">forced<\/a> me to practice by video and phone, I&#8217;ve exchanged much more email with patients than I did before.  Previously, I discouraged email from patients.  For one thing, I knew it was an insecure channel, not &#8220;HIPAA-compliant.&#8221;  It&#8217;s also somewhat less personal than a phone call.  But starting last March I gave patients my work email, which they needed in order to connect to my video link (usually <a rel=\"noreferrer noopener\" aria-label=\"Doxy.me (opens in a new tab)\" href=\"https:\/\/doxy.me\" target=\"_blank\">Doxy.me<\/a>) for sessions.  Most also use it to <a rel=\"noreferrer noopener\" aria-label=\"pay (opens in a new tab)\" href=\"https:\/\/www.zellepay.com\" target=\"_blank\">pay<\/a> me online.  Perhaps inevitably, email has become the most convenient way to send short messages back and forth, mostly medication refill requests and appointment confirmations or changes.<\/p>\n\n\n\n<p>Due to the pandemic, I also linked an online version of my intake form to the front page of my <a rel=\"noreferrer noopener\" aria-label=\"website (opens in a new tab)\" href=\"https:\/\/www.stevenreidbordmd.com\" target=\"_blank\">website<\/a>, so new patients could complete it remotely.  The completed form was transmitted to me by non-secure email as well.<\/p>\n\n\n\n<p>As the months dragged on, I realized I needed to treat all this electronic communication more carefully.  I started researching secure email designed for medical practices.  Below I&#8217;ll tell you what I found.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>What is HIPAA-compliant email?<\/strong><\/h4>\n\n\n\n<p>But first, a brief dive into terminology.  HIPAA, short for the Health Insurance Portability and Accountability Act of 1996, is a federal statute that, among other things, regulates the secure sharing of medical information, especially electronically.  Those of us who traffic in &#8220;protected health information&#8221;&nbsp;(PHI) \u2014 &#8220;covered entities&#8221; such as doctors, hospitals, clinical laboratories, insurance companies, and others \u2014 must store and transmit PHI in secure ways.  We also sign &#8220;business associate agreements&#8221; (BAAs) with each other.  A BAA is basically a contract that says covered entities will only share PHI with other covered entities.<\/p>\n\n\n\n<p>While many people assume HIPAA exists to assure privacy, the law actually arose to <em>facilitate<\/em> electronic information exchange, often without the patient&#8217;s explicit consent.  For example, HIPAA allows behind-the-scenes sharing of PHI to &#8220;coordinate care.&#8221;  But for purposes of this review, I&#8217;ll focus on the privacy safeguards, not the many other parts of HIPAA.<\/p>\n\n\n\n<p>To be HIPAA-compliant, email must be protected at both ends, e.g., with passwords, and engineered to prevent interception and reading en route.  Technically, HIPAA does not demand that email be encrypted (translated into unreadable code), although that is typically the strategy used.  The email provider and the covered entity using that provider should sign a BAA.<\/p>\n\n\n\n<p>Regular email, in contrast, isn&#8217;t designed to be secure.  Messages are copied in readable form from one internet node to the next.  Bad actors can intercept them along the way.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>What I found<\/strong><\/h4>\n\n\n\n<p>So who offers HIPAA-compliant email?  One option are companies that provide complete electronic practice management systems.  These typically include secure messaging with patients as part of their larger range of services.  I didn&#8217;t deeply research this, as I&#8217;m not in the market for such a system.  Using one solely for secure messaging seemed too expensive, unwieldy, or both.  But I did briefly look into <a rel=\"noreferrer noopener\" aria-label=\"ChARM EHR (opens in a new tab)\" href=\"https:\/\/www.charmhealth.com\" target=\"_blank\">ChARM EHR<\/a> and <a rel=\"noreferrer noopener\" aria-label=\"Luminello (opens in a new tab)\" href=\"https:\/\/luminello.com\" target=\"_blank\">Luminello<\/a>, both of which include secure communication with patients, and offer a free version with limited features to try out.  ChARM is designed for all types of small medical practices, not just mental health, while Luminello is for mental health only, including non-medical therapists and &#8220;wellness clinicians.&#8221;  Perhaps thanks to its specificity, I found Luminello much more user-friendly; I&#8217;d seriously consider it if I were in the market.<\/p>\n\n\n\n<p>But I&#8217;m not, so I turned to free-standing email services.  <\/p>\n\n\n\n<p>Best I can tell, all HIPAA-compliant email is actually webmail.  That is, the recipient receives a regular email with a link to a secure website to pick up the message. &nbsp;Services differ with respect to email storage, often 1 to 5 gb; ways that non-subscribers, e.g., patients and potential patients, can reach you securely; whether you can use an existing email address versus having to get a new one; and whether you can choose an email address from a website domain you own (e.g.,&nbsp;therapist@mycompany.com). &nbsp;All include a BAA.<\/p>\n\n\n\n<p>Several companies provide secure email to larger clinics with multiple clinicians, administrative staff, and maybe a dedicated IT person.  They usually charge monthly fees to match.  That&#8217;s not my situation, and I do not review them here.  Instead, here are a few sized for the solo practitioner:<\/p>\n\n\n\n<p><strong>Hushmail for Healthcare<\/strong> (<a href=\"http:\/\/www.hushmail.com\/\">www.hushmail.com<\/a>) &#8211; $109\/yr:<br>Pros: Secure forms submission, with two nicely customizable forms at the above price. 10 gb storage. Can use your own domain for email.<br>Cons: Can\u2019t use an existing email address in a domain you don\u2019t own (e.g., gmail, hotmail, yahoo, etc). &nbsp;The price doubles for more forms.<\/p>\n\n\n\n<p><strong>MailHippo<\/strong> (<a href=\"http:\/\/www.mailhippo.com\/\">www.mailhippo.com<\/a>) &#8211; $60\/yr:<br>Pros: Arguably slightly stronger encryption than Hushmail (AES 256 bit&nbsp;versus OpenPGP). &nbsp;Can recall an email message, for example if addressed incorrectly. &nbsp;Uses your existing email address. &nbsp;Includes a personal URL so anyone can send you a secure email; adding this URL to your website, or to your signature at the bottom of regular email, invites secure messages from others.<br>Cons: No forms.<\/p>\n\n\n\n<p><strong>MD OfficeMail<\/strong> (<a href=\"http:\/\/www.mdofficemail.com\/\">www.mdofficemail.com<\/a>) &#8211; $23\/yr with their email address, $32\/yr with your own<br>Pros: Cheapest paid HIPAA-compliant email I could find. &nbsp;Includes a personal URL so anyone can send you a secure email.<br>Cons: User interface is old and clunky. &nbsp;No forms.<\/p>\n\n\n\n<p>The following offer encrypted email \u2014 and are based in Europe, not the US \u2014 but are not designed for HIPAA specifically, i.e., no BAA:&nbsp;<\/p>\n\n\n\n<p><strong>ProtonMail<\/strong> (<a rel=\"noreferrer noopener\" aria-label=\"www.protonmail.com (opens in a new tab)\" href=\"http:\/\/www.protonmail.com\/\" target=\"_blank\">www.protonmail.com<\/a>) &#8211; Free, or $48\/yr for more features and email storage<br><strong>Tutanota<\/strong> (<a rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\" href=\"http:\/\/www.tutanota.com\/\" target=\"_blank\">www.tutanota.com<\/a>) &#8211; 12 euro\/yr for \u201cbusiness,&#8221; free for \u201cprivate.&#8221; Includes a secure calendar and address book, which would make Tutanota my choice if I merely wanted these encrypted features for personal use.<\/p>\n\n\n\n<p>There are also a number of free, ad-supported apps that will encrypt email on handheld devices.  These aren&#8217;t HIPAA-compliant either.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">And the winner is&#8230; my patients<\/h4>\n\n\n\n<p>In the end I decided to go with Hushmail, mainly because it offered the secure forms I needed: a general contact form and an intake form for my website.  I also was able to use my own web domain (@stevenreidbordmd.com) for my new email address.  If I hadn&#8217;t needed the forms, I would have chosen MailHippo instead, to keep my existing email address.<\/p>\n\n\n\n<p>Once signed up, I converted the contact form and intake form on my website to Hushmail.  Then, using my old, unsecured email, I sent a final message to my active patients asking them to stop using that address, and to expect secure email from me going forward.  Since replying to a secure email also makes the reply secure, this is a good way to start a private, HIPAA-compliant email channel with each patient.<\/p>\n\n\n\n<p>One of the best uses I&#8217;ve found so far for secure email is sending monthly billing statements electronically, as pdf attachments, instead of by mail.  If patients or potential patients want to reach me securely before I send them anything, they use the contact form on my website to start the exchange.  So far, my new system has been working well.<\/p>\n\n\n\n<p>In the comments below, let me know how any of these solutions work for you, or if you have others to recommend.<\/p>\n\n\n\n<p><em>Image courtesy of Stuart Miles at FreeDigitalPhotos.net<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p> The problem <\/p>\n<p>In the months since the COVID-19 pandemic forced me to practice by video and phone, I&#8217;ve exchanged much more email with patients than I did before. Previously, I discouraged email from patients. For one thing, I knew it was an insecure channel, not &#8220;HIPAA-compliant.&#8221; It&#8217;s also somewhat less personal than a phone [&#8230;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[4,67],"tags":[13,81],"class_list":["post-1532","post","type-post","status-publish","format-standard","hentry","category-current-events","category-medical-practice","tag-ethics","tag-online-therapy","odd"],"aioseo_notices":[],"_links":{"self":[{"href":"http:\/\/blog.stevenreidbordmd.com\/index.php?rest_route=\/wp\/v2\/posts\/1532","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/blog.stevenreidbordmd.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/blog.stevenreidbordmd.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/blog.stevenreidbordmd.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/blog.stevenreidbordmd.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1532"}],"version-history":[{"count":9,"href":"http:\/\/blog.stevenreidbordmd.com\/index.php?rest_route=\/wp\/v2\/posts\/1532\/revisions"}],"predecessor-version":[{"id":1567,"href":"http:\/\/blog.stevenreidbordmd.com\/index.php?rest_route=\/wp\/v2\/posts\/1532\/revisions\/1567"}],"wp:attachment":[{"href":"http:\/\/blog.stevenreidbordmd.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1532"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/blog.stevenreidbordmd.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1532"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/blog.stevenreidbordmd.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1532"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}