Confidential email for healthcare and legal practices: what actually matters

Tobava Security Team · · 7 min read
← All articles

No email product is "HIPAA-compliant" on its own — compliance is a property of how you operate, not a badge a vendor can sell you. But the provider you choose either makes it achievable or makes it impossible.

First, the claim to be sceptical of

Any vendor advertising "HIPAA-compliant email" as a feature is overselling. HIPAA compliance depends on your safeguards, your policies, your staff training, your breach procedures — and a Business Associate Agreement with the vendor. A provider can be *suitable for use in a compliant workflow*. It cannot be compliant on your behalf.

The same applies in Australia under the Privacy Act and the Australian Privacy Principles, and to legal professional privilege: the obligation sits with the practice.

What the rules actually require of email

Across HIPAA, the APPs and professional conduct rules for lawyers, the common requirements are:

Where ordinary email falls short

Standard SMTP is not confidential by default. Transport encryption is opportunistic — if the receiving server doesn't offer TLS, many senders deliver in plaintext anyway. You cannot rely on the other end being configured well.

Provider access is the usual gap. If your provider can read message content, that content is disclosed to a third party. That's precisely what a Business Associate Agreement exists to govern under HIPAA — and if no such agreement exists, using that provider for patient data is a problem regardless of how good its security is.

Misdirected email is the most common breach of all. Not hacking — autocomplete picking the wrong "David." Every practice should assume this will happen and control for it.

Practical controls for a small practice

The highest-value change most practices can make isn't cryptographic: use a secure portal for sensitive documents and send an email that merely says a document is waiting. It removes the content from email entirely, which sidesteps most of the risk in one step.

Questions to ask any provider

  1. Can you sign a BAA (US) or a written data processing agreement (Australia)?
  2. Where is data physically stored, and under whose jurisdiction?
  3. Is content scanned for advertising or model training — and is that contractually excluded?
  4. What encryption is used at rest, and who controls the keys?
  5. What audit logging is available to us, and for how long?
  6. What's the documented breach notification commitment?
  7. On exit, can we export everything in a standard format?

Where Tobava Mail sits

Australian owned and operated, AES-256-GCM encryption of received message bodies at rest, DKIM-signed outbound mail, and multi-factor authentication — with no advertising, profiling, or content scanning for marketing. Two things we will not overstate: subjects, attachments and sent mail are not encrypted at rest today, and we do not offer end-to-end encryption where the key is yours alone. If your obligations require either, ask us before relying on it. The policies, training and procedures still have to be yours regardless.

Try Tobava Mail free

Encrypted email, a private inbox, and a full workspace — built by a cybersecurity company. No ads, no tracking, no message scanning.

Create your free account