Tuesday, 5 December 2017

Why Secure Communication for HIPAA Compliance is Not Enough

Written by Orlee Berlove, Director of Marketing at OnPage

When you spend a lot of time writing about HIPAA compliance and its importance for healthcare providers, you sometimes forget the bigger question: What does HIPAA compliant communication mean for healthcare?

Yes, we know that HIPAA requires secure and encrypted clinical communication to ensure patient privacy. But is that where the argument starts and ends? Is patient privacy the only reason to embrace HIPAA compliant communication?

Turns out, there’s more to the riddle.

Why focus on secure email and secure mobile messaging

According to a 2015 study, healthcare employees use mobile messaging more frequently than voice calling for their business communication. 65 percent of healthcare respondents use email most frequently for business communication, followed by mobile messaging (22 percent) and voice calling (13 percent). The same study also reported that 91 percent of those interviewed use mobile messaging at least a few times per week.

Healthcare often uses mobile communication after receiving a pager alert. Unfortunately, pagers cause unnecessary friction to the process of patient care.

Pagers cost over $1.7 M per year in lost productivity. As such, it is important to find alternative to make healthcare communication processes as efficient and effective as possible.

Similarly, given the prominence of email and mobile communication in healthcare, it also makes sense to remove the friction that these communication cause in terms of efficiency.

If information cannot be easily exchanged through email due to HIPAA concerns or legacy pen-and-paper processes, then the workflow is bogged down.

Why is workflow important?

Efficient clinical workflow saves time, saves money, and saves lives. And in today’s industry, workflow can have a significant effect on reimbursement. As such, effective and efficient communication is key. Practices need to be choosy.

OnPage’s smartphone-based secure messaging tool and Paubox’s mobile friendly HIPAA secure email and forms are designed with secure communication in mind as well as improved workflow. OnPage is able to improve workflow as is Paubox.

And workflow is really where it’s at.

While HIPAA compliance is important to physicians, it is not as important as their patients. Physicians focus on seeing patients and improving patient lives.

Technology that improves practitioners’ efficiency and allow them to spend more time helping patients are meaningful.

How HIPAA secure messaging trumps workflow

As noted, pagers are a huge impediment to optimal workflow in hospitals.

Most paging systems utilize single-function pagers that only allow one-way communication, requiring recipients to disrupt workflow to respond to pages. Paging transmissions can also be intercepted, and the information presented on pager displays can be viewed by anyone in possession of the pager.

However, smartphone-based, HIPAA-compliant group messaging applications improve in-hospital communication. These applications save time as physicians and nurses do not need to receive messages on their pager and then respond via cellphone.

By only using cellphone based secure messaging applications, physicians and nurses have access to secure communication while providing the information security that paging and commercial cellular networks do not.

Additionally, secure messaging technologies enable persistent alerting that ensures messages aren’t dropped, missed or forgotten. By ensuring that messages are not lost, administrators do not need to waste time following up on sent messages.

How secure email and forms improve workflow

A doctor or practitioner must encrypt their emails when they communicate protected health information via email.

Unfortunately, most encrypted email providers use a portal to gate communication. Portals can make recipients take up to five extra steps just to view any messages. It also makes the experience of reading email on a mobile device cumbersome.

Not being able to send and receive emails quickly and easily can significantly bog down workflows.

When it comes to forms, online forms reduce the time patients spend in the office and make the process of patient engagement much more fluid.

Having web forms enables patients to enter their information online and include attachments such as photos or documents, then send in their forms directly to their healthcare provider’s inbox via a HIPAA compliant email provider like Paubox.

Electronic forms make archiving these documents much easier than their paper counterparts as well.

Conclusion

Overall, healthcare cannot ignore the importance of HIPAA compliance; however, healthcare technology also needs to focus on improving the workflow of physicians and practitioners.

As a healthcare provider or practitioner, you need to look for solutions that make communication more efficient.

About OnPage

Orlee leads the marketing function at OnPage, where she frequently speaks with client physicians and end users. OnPage provides HIPAA compliant, secure clinical communication for hospitals and clinics. OnPage’s secure messaging and alert automation are key to enabling enhanced collaborations among practitioners and improved patient outcomes.

Saturday, 2 December 2017

Is it Possible to Keep My Current Email System with Paubox?

Is it Possible to Keep My Current Email System with Paubox?
This is one of the more common questions we encounter.


  • Paubox integrates nicely with cloud email systems like Office 365 and G Suite.
  • Paubox includes a BAA (at no additional charge) with all paid accounts.
  • The Outlook email client can still be used with Paubox.

We often get asked if our HIPAA compliant email solution works with existing email systems. It’s one of the more common questions we encounter.

Here’s a snippet from an inquiry we received today:

“I am interested in signing up for HIPAA-compliant business email. I have a few questions about your service- is it possible to keep my current email system? I have Outlook through my hosting and would like to keep that interface if at all possible.”

Keeping Current Email System with Paubox

If we dig into the above inquiry, the interested party is using Office 365 to host their company’s corporate email.

Paubox integrates nicely with Office 365.

In fact, we’ve detailed how to do it via our Help Center article, Setup Paubox Encrypted Email for Office 365.

It’s important to note that in this scenario, you must have a Business Associate Agreement (BAA) in place with both Microsoft and Paubox to maintain HIPAA compliance for your email system.

Paubox includes a BAA (at no additional charge) with all paid accounts.

SEE RELATED: Is Office 365 HIPAA Compliant?

Keeping the Outlook Interface with Paubox

The second part of the person’s inquiry deals with their desire to keep using Outlook as their email client. That’s a great question!

When we built Paubox, we kept usability top of mind. In other words, Paubox seamlessly integrates with all email clients, including Outlook.

So to answer the question: Yes, the Outlook email client can still be used with Paubox.

In fact, no setting changes in Outlook are needed or required.

What about G Suite?

The same is true with G Suite: Paubox integrates seamlessly with G Suite as well.

SEE ALSO: How to Make Gmail HIPAA Compliant

HIPAA Breach Report for December 2017

hipaa breach reporting, hipaa breach, hipaa, reporting

The Paubox Breach Report analyzed HIPAA breach reporting submitted to the U.S. Department of Health & Human Services (HHS) in November to analyze the types of breaches of unsecured protected health information (PHI) affecting 500 or more people.

HIPAA Breaches Ranked by People Affected

Paubox HIPAA Breach Report: December 2017 - Breaches Ranked by People Affected

Top Three Breach Types

  • Other breaches ranked the highest with 19,487 people’s PHI hacked or stolen in November. This is the first month this year to have Other as the top rank category.
  • Paper/Films breaches ranked second with PHI of 15,946 people breached.
  • Email breaches came in third with 10,708 people having their PHI breached.

Bottom Three Breach Types

  • Network Server ranked as the lowest number of people’s PHI being breached in November with 0 breaches.
  • Electronic Medical Record breaches ranked second lowest at 769.
  • Laptop were the third lowest type of breach as ranked by people affected with 1,409.

HIPAA Breaches Ranked by Occurrence

Paubox HIPAA Breach Report: December 2017 - Breaches Ranked by Occurrence

The Most Common

  • Paper/Films ranked as the most common breach types in November with 6 reported breaches.
  • Other came in as the second most common breach type with 3 incidents.
  • Email and Laptop tied for third with 2 breaches each.

The Least Common

  • Network Server was the least common breach type with 0.
  • Desktop Computer and Electronic Medical Record rounded out the bottom with 1 breach each.

Takeaways

November was another relatively “quiet” month for HIPAA breaches. It would be interesting to get more data from HHS on what constitutes the Other category.

As usual, Email breaches remained in the top 3 category, both for number of people affected and number of reported breaches.

Full Data

Click here to download the raw data.

About the Paubox HIPAA Breach Report

The Paubox HIPAA Breach Report analyzes breaches that affected 500 or more individuals as reported in the HHS Wall of Shame in November 2017.

Minimize the risk of email getting you on the list with Paubox Encrypted Email. Start your free trial today.

Friday, 1 December 2017

TLS 1.0 Disablement: What You Need to Know

TLS 1.0 Disablement - Paubox
Paubox ended support for the TLS 1.0 encryption protocol today.


  • Paubox now supports TLS 1.1 and 1.2 only.
  • PCI Compliance requires ending use of TLS 1.0 by 30 June 2018.
  • SSLv2, SSLv3 and TLS 1.0 are insecure protocols and are not supported.
  • The impact of the TLS 1.0 disablement will be minimal to customers and end users.

As previously announced, we ended support for the TLS 1.0 encryption protocol today.

Its more secure successor, TLS 1.1, will be the new minimum standard security protocol used by Paubox. We are doing this in order to align with industry-wide best practices for security and data integrity.

The impact of the TLS 1.0 disablement will be minimal to the end user.

What is TLS? (What is TLS 1.0?)

TLS, short for Transport Layer Security, is an encryption protocol that protects messages in transit from one server to another. The encryption protocol deploys whenever a web browser or application transmits data over a network.

All Paubox network traffic, whether it contains PHI or not, is encrypted using industry-standard transport encryption (TLS). TLS prevents emails from being read while in motion and ensures the communication is delivered to the appropriate recipient.

Currently, TLS has three versions: TLS 1.0, 1.1 and 1.2.

As an aside, there is a TLS 1.3 protocol. It’s a working draft however, with incomplete details.

Why is this happening?

At Paubox, we prioritize user experience, but not at the expense of security.

TLS 1.0 is vulnerable to a few attacks, such as the POODLE (Padding Oracle On Downgraded Legacy Encryption) and BEAST (Browser Exploit Against SSL/TLS).

RELATED: Make a Plan for the Middle Man

TLS 1.1 and 1.2, on the other hand, have no known weaknesses.

We are also acting in accordance with the PCI DSS (Payment Card Industry Data Security Standard). The PCI requires that TLS 1.0 no longer be used for secure communications, giving companies until 30 June 2018 to make the transition.

With this upgrade to TLS 1.1, you can continue sending encrypted HIPAA-compliant email with confidence that the highest security standards are in place and your sensitive information is safe.


Qualsys SSL Server Test screenshot of www.paubox.com
TLS 1.0 Disablement: What You Need to Know - Paubox

Wednesday, 29 November 2017

Free SSL Security Testing for HIPAA Compliance

Free SSL Security Testing for HIPAA Compliance - Paubox
www.paubox.com gets an A+ SSL Security rating.


  • SSL certificates can be used for securing both Web and Email Communication.
  • An SSL certificate is not the same as the SSL Protocol.
  • There are free SSL security tests online.

A county hospital in Illinois asked us today about our use of SSL certificates and how secure our setup is.

After successfully answering their question, it occurred to me others might want to learn more abut proper configuration and use of SSL certificates.

SSL Certificate: What is it?

An SSL Certificate provides secure, encrypted communication between a website and a user’s internet browser. SSL certificates can also be used for secure email transmission.

SSL Certificates are usually installed on websites that require users to submit sensitive information over the internet like credit card details, protected health information, or passwords.

SSL Certificates are not the same as SSL Protocols

SSL stands for Secure Sockets Layer and is the protocol which provides the encryption. It was originally developed by Netscape and released as SSL 2.0 (SSLv2) in 1995. An improved SSL 3.0 (SSLv3) was later released in 1996.

It should be noted however, both SSLv2 and SSLv3 are no longer considered secure protocols. Paubox therefore does not support SSLv2 and SSLv3.

Later this week, we will also be ending support for TLS 1.0.

An SSL Certificate is not the same as the SSL protocol.

In fact, an SSL certificate is not dependent on protocols and is rather an industry term more people are familiar with.

Free SSL Security Test

A free SSL Security Test that we like and use often is provided by Qualys, Inc.

The Qualsys SSL Server Test is an effective way to test your website’s SSL certificate, as well as a variety of other useful security checks.

The test takes a couple minutes to run and is well worth it if you haven’t done it before.

With careful configuration and attention, it’s possible to get an A+ SSL Security rating from the Qualys SSL Server Test.

When it comes to U.S. Healthcare and HIPAA compliance, we recommend doing business with vendors that get an A grade or higher.

Tuesday, 28 November 2017

Can I use Heroku and be HIPAA Compliant?

Can I use Heroku and be HIPAA Compliant? - Paubox

From time to time, we get asked by customers and prospects about Heroku and their ability to use it in a HIPAA compliant manner.

We know the HIPAA industry is vast so we can empathize with just how many people need to use cloud-based services in this sector.

In previous posts, we’ve covered the following cloud providers and their capabilities for HIPAA compliance:

The purpose of this post is to determine if Heroku offers HIPAA compliance or not.

SEE ALSO: HIPAA Breaches and Cloud Providers

About Heroku

Heroku is a cloud Platform as a Service (PaaS). It supports several programming languages including Java, Node.js, Scala, Clojure, Python, PHP, and Ruby.

Known as one of the first cloud platforms, Heroku launched in 2007. In 2010, it was bought by Salesforce for $212 million.

Heroku and the Business Associate Agreement

We’ve previously talked about how a Business Associate Agreement (BAA) is a written contract between a Covered Entity and a Business Associate. It is required by law for HIPAA compliance.

We checked Heroku’s site and found a page called Heroku Security, Privacy, and Compliance.

In it, Heroku states:

“Customers who want to build healthcare applications on Heroku that complies with US HIPAA can contact sales@heroku.com regarding a Business Associate Addendum to the Master Subscription Agreement that is required for HIPAA compliance.”

Does Heroku Offer HIPAA Compliant Service?

The Business Associate Agreement is a key component to HIPAA compliance between a Covered Entity and a Business Associate.

Since Heroku offers a BAA that would be added to their Master Subscription Agreement, we conclude that Heroku can be configured to be a HIPAA compliant service.

G Suite email isn’t HIPAA compliant out of the box.
Download the Quick Guide to HIPAA Compliant Email for free.

Conclusion: Heroku can be configured to be HIPAA Compliant. Make sure you sign a BAA with Heroku first.

Monday, 27 November 2017

Can I use G Suite (Google Apps) and be HIPAA Compliant?

Can I use G Suite (Google Apps) and be HIPAA Compliant? - Paubox

We often get asked by customers and prospects about G Suite (formerly Google Docs) and their ability to use it in a HIPAA compliant manner.

We know the HIPAA market is vast so we can empathize with just how many people need to use cloud-based storage services in this sector.

In previous posts, we’ve covered the following cloud solutions and their capabilities for HIPAA compliance:

The purpose of this post is to determine if Google’s G Suite offers HIPAA compliance or not.

SEE ALSO: HIPAA Breaches and Cloud Providers

About G Suite (Google Docs)

G Suite is Google’s brand of cloud computing, productivity and collaboration tools. It’s most popular services are Gmail, Google Calendar, and Google Drive (including Docs, Sheets, Slides, and Forms).

While these services are typically free to use for consumers, G Suite adds enterprise features such as branded email addresses at a domain (@yourcompany.com), as well as phone and email support.

Formerly known as Google Docs, Google rebranded the service to G Suite in September 2016.

G Suite and the Business Associate Agreement

We’ve previously talked about how a Business Associate Agreement (BAA) is a written contract between a Covered Entity and a Business Associate. It is required by law for HIPAA compliance.

We checked Google’s site and found a G Suite Administrator Help article called HIPAA Compliance with G Suite.

In the article, Google points out:

“Google offers a BAA covering Gmail, Google Calendar, Google Drive (including Docs, Sheets, Slides, and Forms), Google Hangouts (chat messaging feature only), Hangouts Meet, Google Keep, Google Cloud Search, Google Sites, Jamboard, and Google Vault services.”

Does Google’s G Suite Offer HIPAA Compliant Service?

The Business Associate Agreement is a key component to HIPAA compliance between a Covered Entity and a Business Associate.

Since Google offers one that covers G Suite, we conclude that Google’s G Suite is a HIPAA compliant service.

It’s important to note however:

  • You must sign a BAA with Google. It is not included by default.
  • Google’s BAA does not cover email sent or received in transit.

G Suite email isn’t HIPAA compliant out of the box.
Download the Quick Guide to HIPAA Compliant Email for free.

Conclusion: G Suite, formerly known as Google Apps, is HIPAA Compliant. Make sure you sign a BAA with Google and that you have a solution in place to address email sent in transit.

SEE ALSO: How to Make Gmail HIPAA Compliant