Email Encryption Software

Hello - we need to send some encrypted emails for only a few users for HIPAA requirements. What do you recommend?
LVL 4
Cobra25Asked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Dr. KlahnPrincipal Software EngineerCommented:
Depends on where you are sending them.

If it is all internal at one physical location you may be able to get away without encrypting them.

If it is internal but at some other physical location then a strongly encrypted network may solve the problem, which in a medical environment should be standard policy anyway.

If the emails are going outside your organization then two options might be:

  1. A strongly encrypted VPN between your organization and the recipients.
  2. You and the recipients agree to use either PGP or GPG.

For issues like this it is prudent to consult with a HIPAA IT specialist who deals with this every day and can recommend a specific product that will provably, legally, defensibly meet the legal requirements of both HIPAA and your state.
Cobra25Author Commented:
No we need to send to third party.

Is there a portal we can use like banks do and other companies.
Jason WeberSenior Security Platforms EngineerCommented:
I use Cipher mail for my medical customers the SME license is reasonable and gives you a bunch of options.  You can use portal or convert to encrypted PDF.  They have a free version as well but there are some features missing.

https://www.ciphermail.com/gateway.html
Get a highly available system for cyber protection

The Acronis SDI Appliance is a new plug-n-play solution with pre-configured Acronis Software-Defined Infrastructure software that gives service providers and enterprises ready access to a fault-tolerant system, which combines universal storage and high-performance virtualization.

arnoldCommented:
use 7zip to password protect an archive of the data you are transferring. the other side would either need to call you to get the password, or a mailed password .....

cms/mac uses this mechanism,

Encrypting emails as suggested by prior requires that all sides agree and exchange keys with which the sender will encrypt the data destined to a recipient.
Cobra25Author Commented:
I need a portal for this.
arnoldCommented:
Please clarify, there are secureemail.com services that some insurers use,.......

Are you creating your own portal that uses HTTPS with a messageing /buletin board like app?
Cobra25Author Commented:
I need to put the confidential content in an secure portal so i can email them the link, that would be easiest..
arnoldCommented:
As noted you are looking a messaging portal that notifies users when they receive an event, not too different from this or any other.
What resources do you have to undertake this, it might be more cost effective to use an existing provider

There are many examples, reliability unknown as no personal experience....
arnoldCommented:
Cisco like others have this type of service, https://res.cisco.com/websafe/login.action 
See whether the clearing house you use for billing, might include these types of services as well.
Cobra25Author Commented:
Barracuda has exactly what i am looking for.
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Encryption

From novice to tech pro — start learning today.