---
title: Stop Emailing PHI - ClearDATA
description: ClearDATA founder and Chief Privacy & Security Officer Chris Bowen outlines the reasons why healthcare organizations must stop emailing PHI.
image: https://cspm.cleardata.com/hubfs/Imported_Blog_Media/mad-fish-digital-1380945-unsplash-scaled-1-2.jpg
---

[Log in to the CyberHealth™ Platform](http://cyberhealth.cleardata.com/)

[Talk to a Cloud Expert](https://www.cleardata.com/consultation/)

[![Clear data](https://cspm.cleardata.com/hubfs/Cleardata_February2025/images/cleardata-logo.svg)](https://www.cleardata.com/)

- [CSPM for Healthcare](https://www.cleardata.com/cspm) 
    - - [Safeguards: HIPAA, HITRUST, GDPR, ISO, NIST, PCI](https://www.cleardata.com/cspm/#cspm-features)
          - [Automated Compliance](https://www.cleardata.com/cspm/#cspm-features)
          - [Cloud Risk Identification & Remediation](https://www.cleardata.com/cspm/#cspm-features)
          - [Compliance Risk Scores](https://www.cleardata.com/cspm/#cspm-features)
          - [PHI Leak Discovery](https://www.cleardata.com/cspm/#cspm-features)
          - [Audit-Ready Reporting](https://www.cleardata.com/cspm/#cspm-features)
- Services 
    - Managed Services 
          - [Cloud Compliance](https://www.cleardata.com/cloud-compliance/)
          - [Managed Detection & Response](https://www.cleardata.com/cspm/managed-detection-and-response/)
          - [Cloud Operations](https://www.cleardata.com/cspm/cloud-operations/)
    - [Professional Services](https://www.cleardata.com/cspm/cloud-transformation/) 
          - [Cloud Migration & Modernization](https://www.cleardata.com/cspm/cloud-transformation/#migration)
          - [Cloud Assessments](https://www.cleardata.com/cspm/cloud-transformation/#assessments)
          - [End-to-End Cloud Resilience](https://www.cleardata.com/cspm/cloud-transformation/#end2end)
- Solutions 
    - By Market 
          - [Healthcare Software & Services](https://www.cleardata.com/solutions-by-market/healthcare-software-services/)
          - [Medical Devices & Equipment](https://www.cleardata.com/solutions-by-market/medical-devices-equipment/)
          - [Healthcare Providers](https://www.cleardata.com/solutions-by-market/medical-devices-equipment/)
          - [Healthcare Payers](https://www.cleardata.com/solutions-by-market/healthcare-payers/)
    - By Topic 
          - - [Risk Visualization & Prioritization](https://www.cleardata.com/risk-visualization-prioritization/)
                  - [Threat Detection & Protection](https://www.cleardata.com/security-threat-protection/)
                  - [Cost & Performance Optimization](https://www.cleardata.com/cost-performance-optimization/)
                  - [Healthcare Cloud Compliance](https://www.cleardata.com/healthcare-cloud-compliance/)
                  - [Analytics & Reporting](https://www.cleardata.com/analytics-reporting/)
                  - [GxP for Life Sciences](https://www.cleardata.com/gxp-life-sciences/)
                  - [EHR Deployments in the Cloud](https://www.cleardata.com/ehr-cloud-deployments/)
- Resources 
    - - [View All](https://www.cleardata.com/resources/)
          - [Blog](https://www.cleardata.com/blog/)
          - [What Is Compliance Debt?](https://www.cleardata.com/blog/eliminating-compliance-debt-the-key-to-healthcare-tech-innovation/)
          - [Customer Stories](https://www.cleardata.com/stories/)
          - [Events](https://www.cleardata.com/events/)
- [About](https://www.cleardata.com/about-us/) 
    - - [Leadership Team](https://www.cleardata.com/about-us/leadership-team/)
          - [Careers](https://www.cleardata.com/about-us/careers/)
          - [News](https://www.cleardata.com/about-us/news/)
          - [Partners](https://www.cleardata.com/supported-clouds/)

- [CSPM for Healthcare](https://www.cleardata.com/cspm) 
    - - [Safeguards: HIPAA, HITRUST, GDPR, ISO, NIST, PCI](https://www.cleardata.com/cspm/#cspm-features)
          - [Automated Compliance](https://www.cleardata.com/cspm/#cspm-features)
          - [Cloud Risk Identification & Remediation](https://www.cleardata.com/cspm/#cspm-features)
          - [Compliance Risk Scores](https://www.cleardata.com/cspm/#cspm-features)
          - [PHI Leak Discovery](https://www.cleardata.com/cspm/#cspm-features)
          - [Audit-Ready Reporting](https://www.cleardata.com/cspm/#cspm-features)
- Services 
    - Managed Services 
          - [Cloud Compliance](https://www.cleardata.com/cloud-compliance/)
          - [Managed Detection & Response](https://www.cleardata.com/cspm/managed-detection-and-response/)
          - [Cloud Operations](https://www.cleardata.com/cspm/cloud-operations/)
    - [Professional Services](https://www.cleardata.com/cspm/cloud-transformation/) 
          - [Cloud Migration & Modernization](https://www.cleardata.com/cspm/cloud-transformation/#migration)
          - [Cloud Assessments](https://www.cleardata.com/cspm/cloud-transformation/#assessments)
          - [End-to-End Cloud Resilience](https://www.cleardata.com/cspm/cloud-transformation/#end2end)
- Solutions 
    - By Market 
          - [Healthcare Software & Services](https://www.cleardata.com/solutions-by-market/healthcare-software-services/)
          - [Medical Devices & Equipment](https://www.cleardata.com/solutions-by-market/medical-devices-equipment/)
          - [Healthcare Providers](https://www.cleardata.com/solutions-by-market/medical-devices-equipment/)
          - [Healthcare Payers](https://www.cleardata.com/solutions-by-market/healthcare-payers/)
    - By Topic 
          - - [Risk Visualization & Prioritization](https://www.cleardata.com/risk-visualization-prioritization/)
                  - [Threat Detection & Protection](https://www.cleardata.com/security-threat-protection/)
                  - [Cost & Performance Optimization](https://www.cleardata.com/cost-performance-optimization/)
                  - [Healthcare Cloud Compliance](https://www.cleardata.com/healthcare-cloud-compliance/)
                  - [Analytics & Reporting](https://www.cleardata.com/analytics-reporting/)
                  - [GxP for Life Sciences](https://www.cleardata.com/gxp-life-sciences/)
                  - [EHR Deployments in the Cloud](https://www.cleardata.com/ehr-cloud-deployments/)
- Resources 
    - - [View All](https://www.cleardata.com/resources/)
          - [Blog](https://www.cleardata.com/blog/)
          - [What Is Compliance Debt?](https://www.cleardata.com/blog/eliminating-compliance-debt-the-key-to-healthcare-tech-innovation/)
          - [Customer Stories](https://www.cleardata.com/stories/)
          - [Events](https://www.cleardata.com/events/)
- [About](https://www.cleardata.com/about-us/) 
    - - [Leadership Team](https://www.cleardata.com/about-us/leadership-team/)
          - [Careers](https://www.cleardata.com/about-us/careers/)
          - [News](https://www.cleardata.com/about-us/news/)
          - [Partners](https://www.cleardata.com/supported-clouds/)

# Stop Emailing PHI

 April 19, 2019

 7 minute read

<https://www.reddit.com/submit?url=https://cspm.cleardata.com/cleardata-blog/blog/stop-emailing-phi> <https://www.linkedin.com/sharing/share-offsite/?url=https://cspm.cleardata.com/cleardata-blog/blog/stop-emailing-phi> [mailto:?body=https://cspm.cleardata.com/cleardata-blog/blog/stop-emailing-phi](mailto:?body=https://cspm.cleardata.com/cleardata-blog/blog/stop-emailing-phi)

### [![2024-Threat-Report-data-1](https://cspm.cleardata.com/hubfs/Cleardata_February2025/images/2024-Threat-Report-data-1.jpg) Guide 2024 Healthcare Threat Report Learn More](https://www.cleardata.com/resources/healthcare-threat-report/)

#### Table of Contents

![](https://cspm.cleardata.com/hs-fs/hubfs/Imported_Blog_Media/Bowen-Chris-800-200x200-Sep-18-2025-09-15-45-0659-PM.jpg?width=200&height=200&name=Bowen-Chris-800-200x200-Sep-18-2025-09-15-45-0659-PM.jpg)

*by **Chris Bowen**Chief [Privacy](https://www.cleardata.com/legal/privacy-policy/) & Security Officer and Founder  
[ClearDATA](https://www.cleardata.com/)*

In the first quarter of 2019, 78 breaches were reported to the Department of Health and Human [Services](https://www.cleardata.com/services-descriptions/) (DHHS). Of those, 49 were considered “Hacking/IT Incidents.” Alarmingly, of those 49 incidents, nearly half (43%) involved disclosures of PHI via email compromise.

*The headlines from 2018 were bad enough on the topic:*

- **[“UnityPoint warns 1.4 million patients their information might have been breached by email hackers”](https://www.desmoinesregister.com/story/news/health/2018/07/30/unitypoint-data-breach-million-patients-email-hack-hacked-phishing-e-mail-health-care-iowa/866760002/)**
- **[“Email Hack on Vermont Provider Breaches 32,000 Patient Records”](https://healthitsecurity.com/news/week-long-hack-on-vermont-provider-breaches-32000-patient-records)**
- **[“HealthEquity Email Hack Breaches Data of 190K Patients”](https://healthitsecurity.com/news/healthequity-email-hack-breaches-data-of-190k-patients)**
- **[“24,000 Patient Records Breached in EyeSouth Partners Email Hack”](https://www.skyflok.com/2019/02/15/24000-patient-records-breached-in-eyesouth-partners-email-hack-2/)**
- [**“Aspire Health hacked by phishing scheme, lost ‘protected health information’”**](https://www.tennessean.com/story/news/health/2018/09/25/nashville-based-aspire-health-hacked-phishing-scheme-lost-health-information/1420135002/)

*However, 2019 had barely begun when another wave of healthcare-related email hacks threatened patient privacy:*

- **[“326,000 Patients Impacted in UConn Health Phishing Attack”](https://healthitsecurity.com/news/326000-patients-impacted-in-uconn-health-phishing-attack)**
- **[“Month-Long Email Hack on Ohio Dental Insurer Impacts Patient Data”](https://healthitsecurity.com/news/month-long-email-hack-on-ohio-dental-insurer-impacts-patient-data)**
- **[“Valley Hope Association Email Hack Breaches Patient Data”](https://healthitsecurity.com/news/valley-hope-association-email-hack-breaches-patient-data)**
- **[“Vermont hospital email hack exposes info of more than 72,000”](https://www.modernhealthcare.com/technology/vermont-hospital-email-hack-exposes-info-more-72000)**
- [**“23,300 Patients Affected by Critical Care, Pulmonary & Sleep Associates Email Hack”**](https://www.hipaajournal.com/23300-patients-affected-by-critical-care-pulmonary-sleep-associates-email-hack/)

*Since when did healthcare professionals decide that communicating patient information by email was secure or even acceptable? Examine a few causes of the breaches:*

- “an employee was duped by a phishing attempt”
- “hackers used ‘phishing’ techniques to break into the company’s email system”
- “an unauthorized user had accessed an employee email account”
- “hackers exploited an email configuration error to bypass the multi-factor and device authentication through a ‘sophisticated method.’”
- “an individual gained unauthorized access to an employee email account”
- “a phishing attack gained access to the internal email system”

One of the best ways to avoid breaches of PHI by email is…you guessed it, don’t allow PHI to find its way into email at all. Ever. While easier said than done, an up-to-date, accurate data inventory that also documents the safeguards and controls in place to protect PHI can provide the visibility necessary to prevent these insecure flows of PHI.

*The data inventory should be comprised of the following information:*

- Data owner: An accountable owner of the data is critical to maintaining, securing, and ultimately destroying or archiving the data successfully.
- Classification of the data: Data should be classified by sensitivity. The most sensitive data should be the most protected. Hint: PHI should never be stored or transmitted in an unsecured email account.
- Location of the data system: Understanding the system location in which your data resides allows you to align data privacy requirements, physical security, redundancy, and environmental considerations. (Ex: A server farm located under a helipad – yes this happens.)
- Source of the data: Knowing where the data originates allows you to determine data flows, consents, and possible third-party dependencies.
- Purpose and use of the data: Without an understanding of the purpose and use of the data, it is impossible to comply with minimum necessary principles.
- Storage location: If data is stored separately from the data system, the location of that storage is paramount to securing that data.
- Retention policy: Understanding the length of time that data should be kept allows you to comply with consent provisions, minimum necessary principles, and in some cases, regulatory requirements.
- Safeguards in place to protect the data: Data should be safeguarded according to its classification. Documenting the safeguards in place for each set of data allows you to determine whether the safeguards are sufficient and up to date.

Phishing attacks remain a significant threat to the security of PHI. Healthcare professionals should avoid storing or transmitting data in locations and systems that are easy to penetrate and compromise. Email systems are often configured insecurely, and easily penetrated by unsuspecting humans who fail to recognize a phishing attack.

Stop emailing patient data!

 Secure Your Healthcare Cloud

## Speak with a healthcare cybersecurity and compliance expert today.

[Speak with an expert](https://www.cleardata.com/consultation/)

### [![Cracking the Code, Ep. 2: Dissecting the SEC Proposal on Risk Management](https://cspm.cleardata.com/hubfs/Imported_Blog_Media/CTC-thumbnail-Sep-18-2025-09-15-53-8778-PM.jpg) Cracking the Code, Ep. 2: Dissecting the SEC Proposal on Risk Management](https://cspm.cleardata.com/cleardata-blog/blog/cracking-the-code-dissecting-sec-proposal-risk-management)

### [![Cracking the Code, Ep. 1: 2022 Security Predictions for Healthcare](https://cspm.cleardata.com/hubfs/Imported_Blog_Media/CTC-thumbnail-Sep-18-2025-09-23-27-6711-PM.jpg) Cracking the Code, Ep. 1: 2022 Security Predictions for Healthcare](https://cspm.cleardata.com/cleardata-blog/blog/cracking-the-code-2022-security-predictions-for-healthcare)

### [![Digital Health Dose, Ep. 3: Interoperability](https://cspm.cleardata.com/hubfs/Imported_Blog_Media/DHD-thumbnail-Sep-18-2025-09-08-52-0672-PM.jpg) Digital Health Dose, Ep. 3: Interoperability](https://cspm.cleardata.com/cleardata-blog/blog/digital-health-dose-ep-3-interoperability)

[![Clear data](https://cspm.cleardata.com/hubfs/Cleardata_February2025/images/cleardata-logo.svg "Clear data")](https://www.cleardata.com/)

<https://twitter.com/cleardatacloud>

<https://www.linkedin.com/company/cleardata-networks/>

<https://www.youtube.com/@_ClearDATA>

- [CSPM for Healthcare](https://www.cleardata.com/cspm) 
    - [Safeguards: HIPAA, HITRUST, GDPR, ISO, NIST, PCI](https://www.cleardata.com/cspm/#cspm-features)
    - [Automated Compliance](https://www.cleardata.com/cspm/#cspm-features)
    - [Cloud Risk Identification & Remediation](https://www.cleardata.com/cspm/#cspm-features)
    - [Compliance Risk Scores](https://www.cleardata.com/cspm/#cspm-features)
    - [PHI Leak Discovery](https://www.cleardata.com/cspm/#cspm-features)
    - [Audit-Ready Reporting](https://www.cleardata.com/cspm/#cspm-features)

- Services 
    - Managed Services 
          - [Cloud Compliance](https://www.cleardata.com/cloud-compliance/)
          - [Managed Detection & Response](https://www.cleardata.com/cspm/managed-detection-and-response/)
          - [Cloud Operations](https://www.cleardata.com/cspm/cloud-operations/)
    - [Professional Services](https://www.cleardata.com/cspm/cloud-transformation/) 
          - [Cloud Migration & Modernization](https://www.cleardata.com/cspm/cloud-transformation/#migration)
          - [Cloud Assessments](https://www.cleardata.com/cspm/cloud-transformation/#assessments)
          - [End-To-End Cloud Resilience](https://www.cleardata.com/cspm/cloud-transformation/#end2end)

- Solutions 
    - By Market 
          - [Healthcare Software & Services](https://www.cleardata.com/solutions-by-market/healthcare-software-services/)
          - [Medical Devices & Equipment](https://www.cleardata.com/solutions-by-market/medical-devices-equipment/)
          - [Healthcare Providers](https://www.cleardata.com/solutions-by-market/healthcare-providers/)
          - [Healthcare Payers](https://www.cleardata.com/solutions-by-market/healthcare-payers/)
    - By Topic 
          - [Risk Visualization & Prioritization](https://www.cleardata.com/risk-visualization-prioritization/)
          - [Threat Detection & Protection](https://www.cleardata.com/security-threat-protection/)
          - [Cost & Performance Optimization](https://www.cleardata.com/cost-performance-optimization/)
          - [Healthcare Cloud Compliance](https://www.cleardata.com/healthcare-cloud-compliance/)
          - [Analytics & Reporting](https://www.cleardata.com/analytics-reporting/)
          - [GxP For Life Sciences](https://www.cleardata.com/gxp-life-sciences/)
          - [EHR Deployments In The Cloud](https://www.cleardata.com/ehr-cloud-deployments/)

- Resources 
    - [View All](https://www.cleardata.com/resources)
    - [Blog](https://www.cleardata.com/blog/) 
          - [What Is Compliance Debt?](https://www.cleardata.com/blog/eliminating-compliance-debt-the-key-to-healthcare-tech-innovation/)
    - [Events](https://www.cleardata.com/events/)
    - [Customer Stories](https://www.cleardata.com/cloud-case-studies/)
- About 
    - [Leadership Team](https://www.cleardata.com/about-us/leadership-team/)
    - [Careers](https://www.cleardata.com/about-us/careers/)
    - [News](https://www.cleardata.com/about-us/news/)
    - [Cloud Partners](https://www.cleardata.com/supported-clouds) 
          - [Microsoft Azure](https://www.cleardata.com/cspm/microsoft-azure/)
          - [Amazon Web Services (AWS)](https://www.cleardata.com/cspm/aws/)
          - [Google Cloud Platform](https://www.cleardata.com/cspm/google-cloud/)

© 2026 CLEARDATA All rights reserved

- [Privacy Policy](https://www.cleardata.com/legal/privacy-policy)
- [Notice of Copyright Infringement](https://www.cleardata.com/legal/notice-of-copyright-infringement)
- [Acceptable Use Policy](https://www.cleardata.com/legal/acceptable-use-policy/)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Chris Bowen",
    "url" : "https://cspm.cleardata.com/cleardata-blog/author/chris-bowen"
  },
  "dateModified" : "2025-09-18T21:16:59.400Z",
  "datePublished" : "2019-04-19T09:09:29.000Z",
  "headline" : "Stop Emailing PHI - ClearDATA",
  "image" : [ "https://cspm.cleardata.com/hubfs/Imported_Blog_Media/mad-fish-digital-1380945-unsplash-scaled-1-2.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://cspm.cleardata.com/cleardata-blog/blog/stop-emailing-phi",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://cspm.cleardata.com/hubfs/ClearDATA-logo-1540.png"
    }
  }
}
```