Is PHI allowed on external e-mails?
Many members would like to communicate via e-mail, which may include some PHI. Although not prohibited, the security rule requires a health plan to address whether such e-mails should be encrypted or some alternative protection should be in place to reduce the likelihood of disclosure to inappropriate parties. At this time, it is our policy that we will not send unencrypted e-mail responses with PHI. We may receive e-mails with PHI, but will normally seek a more secure method of communication in a response. If a member insists on e-mail communication, we will work with the member to obtain the appropriate protection.