HIPAA (the Health Insurance Portability and Accountability Act) is the US law governing the privacy and security of protected health information (PHI), enforced through its Privacy, Security and Breach Notification Rules. It applies to covered entities (providers, plans, clearinghouses) and to their business associates, vendors that touch PHI, under signed agreements. See HHS.gov for the official rules.
Key facts:
- The Security Rule requires administrative, physical and technical safeguards for electronic PHI, calibrated to risk.
- Breach notification duties reach individuals, the HHS and sometimes media, on defined timelines (verify current specifics at hhs.gov).
- Hacking of email accounts is consistently among the leading breach types reported to HHS; phishing against healthcare staff is the standard entry.
Email and PHI
PHI lives in mailboxes far more than policies admit: referrals, lab discussions, patient correspondence. A single compromised healthcare mailbox is routinely a reportable breach affecting every patient mentioned in it. That makes email protection and fast compromise detection two of the highest-leverage technical safeguards a covered entity or business associate can deploy. Organizations also subject to GDPR face parallel notification duties for the same events.
Where email security fits, honestly
Sentaro supports the Security Rule's technical safeguards where they meet email: protection against phishing and account takeover, detection that makes breach assessment and notification timelines workable, and visibility into third-party apps holding access to mailboxes containing PHI. Risk analyses, policies, agreements and the notification process remain organizational obligations. Vendors serving US health systems typically pair HIPAA duties with HITRUST or SOC 2 for customer assurance.
This page is general guidance, not legal advice.