Contact Us
IT Total Care

Blog

Close-up of a blue Help Desk key on a computer keyboard, the support path staff use when they need to send ePHI by encrypted email.

How to Send ePHI by Encrypted Email in a Home Health Agency

This guide covers why encrypted email matters specifically for home health agencies, how to set it up and run it yourself in five steps, and how IT Total Care manages the whole path for agencies that would rather not own it. The subject throughout is the email channel. Device encryption and network questions are separate problems with their own answers, and mixing them together is how agencies end up with a policy that covers none of them properly.

1. Why Does Knowing How to Send ePHI by Encrypted Email Matter for Home Health Agencies?

Email is the highest-volume path ePHI takes in and out of a home health agency, and it is the only path where the agency controls just half of the transaction. Nearly everything that arrives at intake and nearly everything that leaves for billing passes through a mailbox, usually with an attachment, usually under time pressure.

Where it shows up in a normal week:

  • Referral intake: Referral packets and face-to-face documentation arrive by email from physician offices and hospital discharge planners, often as attachments nobody renames, going to a shared intake mailbox several people can read.
  • Clinical clarification: A director of nursing emails a chart excerpt to a physician to clarify a verbal order, which is a small message carrying real clinical detail and no obvious moment to stop and think about encryption.
  • Revenue cycle: Billing files move to a clearinghouse or an outsourced coder on a schedule, which makes the exposure predictable and, for the same reason, easy to stop noticing.
  • The determination behind it: For nearly every home health workflow, the risk analysis will not support a decision to skip encryption, which is why the designation functions as a requirement in practice. The legal structure underneath that sits in our piece on HIPAA encryption requirements for home health agencies.
  • The half you do not control: The recipient’s mailbox sits outside your agency entirely, so a message that is protected the moment it leaves can still fail on arrival, and nobody at your end will hear about it.

What Does the Error Data Show?

The error data points the same direction. Verizon’s 2026 Data Breach Investigations Report found that Misdelivery, meaning data sent to the wrong recipient in any format, was the leading error type in healthcare breaches, and that staff errors have ranked among the sector’s top three breach patterns every year since 2014. That figure covers healthcare as a whole rather than home-based care specifically. The mechanism is identical in a forty-clinician agency, though: a message reaches the wrong person, and whether it was readable on arrival decides what happens next.

2. How to Send ePHI by Encrypted Email in Five Steps

Sending ePHI by encrypted email is a five-step setup: confirm the licensing supports encryption, enforce TLS with the partners you email constantly, build rules that apply encryption without anyone deciding, test what the recipient actually sees, and write the policy around the people who send the most. Steps one through three are configuration. Steps four and five are what make the configuration survive a busy week. Encryption sits on top of the basics rather than replacing them, so work through our guide to improving email security at an agency alongside it.

Step 1: Confirm Your Microsoft 365 Tier Includes Message Encryption

Confirm that your Microsoft 365 tier actually includes message encryption before writing a policy that assumes it. Microsoft Purview Message Encryption is included with Microsoft 365 Business Premium, Microsoft 365 E3 and E5, and Office 365 E3 and E5. It is not included with Microsoft 365 Business Basic, Business Standard, or Office 365 E1, where it has to be added through Azure Information Protection Plan 1, and every individual who sends protected mail needs a license that covers it. Agencies discover this in the worst possible order more often than they should: policy written, staff trained, and then a licensing gap that means the option does not exist for half the office. Check the tenant, check who is actually licensed, and do it before anything else on this list. Microsoft changes licensing terms regularly, so verify against current documentation rather than a summary from two renewals ago.

Step 2: Enforce TLS on Connectors to Your Regular Partners

Enforce TLS on connectors to the organizations you exchange ePHI with constantly, rather than relying on whatever encryption happens to negotiate itself. In a home health agency that list is short and knowable: referring physician offices, hospital discharge planning departments, your clearinghouse, and any outsourced coder. Opportunistic TLS protects a message when the receiving server supports it and falls back to plaintext silently when it does not, which means the protection is real on most days and absent on exactly the day that matters. A forced connector to a named domain removes the fallback. If the receiving side cannot negotiate a secure connection, the message does not go, and somebody finds out. Build the partner list first, because the connector configuration itself is straightforward and the list is the part agencies get wrong. Then monitor it, since partners migrate mail providers without telling anyone downstream.

Step 3: Make Encryption Automatic Rather Than Manual

Build mail flow rules that apply encryption automatically based on recipient domain or detected content, so that no staff member has to make the call. Automatic rules beat manual tagging for one reason: a process that depends on a scheduler remembering to type a keyword into a subject line will fail during a busy intake week, and a busy intake week is precisely when the most ePHI moves. Rules keyed to recipient domain handle the partners you already know about. Rules keyed to detected content catch the message nobody anticipated. Choose deliberately between encrypt-only and do-not-forward, because the second sounds safer and blocks legitimate forwarding inside a physician practice, where the nurse who needs the chart is frequently not the person the message was addressed to. Most agencies want encrypt-only for routine clinical traffic and reserve do-not-forward for a narrow category, not the reverse.

Step 4: Test What the Recipient Actually Sees

Test the recipient experience from outside your tenant before rollout, including a recipient with no Microsoft account who lands on the one-time-passcode portal. That path is the one that breaks. A physician’s office front desk receives a message, sees a login screen it does not recognize, decides it is phishing, and never opens it, and your agency records a delivered message that was never read. When a recipient genuinely cannot open an encrypted message, the correct move is to route the content to a portal or a secure link and pick up the phone. It is never to resend in plaintext, which turns a control into a written record of the agency knowing better. Decide that fallback before anyone needs it, and tell your top referral sources what an encrypted message from your agency looks like, so the first one does not get deleted on sight.

Step 5: Write the Policy and Train the People Who Send the Most

Write the policy around what staff actually do, then train the people who send the highest volume. Three items belong in every version of it. First, ePHI never goes in a subject line, because subject lines are not covered by message encryption and travel in the clear even when the body does not. Second, patients have a right to receive their own PHI by unencrypted email if they ask for it, so the agency gives a brief warning about the risk, confirms the patient still wants it that way, sends it, and keeps the record of that exchange. Third, retain evidence that encryption actually applied rather than evidence that a policy required it, because a message trace showing the rule fired is something an auditor can use. Train intake and scheduling before anyone else, since referral packets and face sheets are the highest-volume ePHI in the building and the people handling them are usually the ones nobody told what counts.

Limitations: Encrypted email is easy to turn on and hard to keep honest. The configuration takes an afternoon; the failure modes arrive later. Staff start moving a referral packet through personal email because the encrypted path added a step during a week when nobody had a spare minute. Nobody tests what an external recipient sees, so encrypted messages sit unopened and get resent in the clear, which is worse than never encrypting. Encryption gets enabled on the office desktops and not on the phones where the same mailbox is read between visits. None of that is a technical failure. It is what happens when a control has no owner and no reporting, which is why agencies rarely fail at setting this up and often fail at keeping it running.

3. How Does IT Total Care Manage Encrypted Email for Home Health Agencies?

As a Bay Area MSP working with home health agencies, IT Total Care builds and runs the encrypted email path end to end, from the connectors through to the evidence, so that sending ePHI by encrypted email stops being something anyone has to think about. Your intake coordinator forwards the referral. The rule decides what happens to it. Our process includes the following.

What Our Encrypted Email Process Includes

  • TLS enforcement with your referral partners: We enforce TLS on connectors to referring physician offices, hospital discharge planning, and the clearinghouse, then monitor those connectors rather than assuming they are still working.
  • Automatic encryption rules: We configure mail flow rules so encryption applies by recipient domain and detected content, with no staff step left to forget during a heavy week.
  • Recipient experience testing: We test what external recipients see from outside your tenant before rollout, including the one-time-passcode path, so the first encrypted message you send is not the test.
  • Data loss prevention: We build rules that stop ePHI leaving in plaintext rather than logging it after the fact, which is the difference between preventing an incident and documenting one.
  • Closing the workaround: We block personal email and consumer file-sharing as an exfiltration path, so the friction workaround stops being available to staff who are simply trying to get the day finished.

What We Manage Around the Mailbox

  • Managed devices on the receiving end: We enforce and report device encryption per device through Intune, JumpCloud, or Apple Business Manager rather than assuming it from policy, with enrollment covering the personal phones running Axxess, WellSky, or Homecare Homebase apps, and remote wipe of agency data on a lost device or a clinician who leaves without notice, which is where device recovery meets your employee offboarding process.
  • Evidence for the file: We retain proof that encryption actually applied and produce encryption status as a report that goes into the risk analysis file, rather than something reconstructed from memory during a survey.

Ready to Stop Wondering Whether That Message Was Protected?

IT Total Care works with home health agencies throughout the San Francisco Bay Area on the full encrypted email path: licensing, connectors, automatic rules, recipient testing, and evidence that goes straight into the risk analysis file. Our home-based care IT support covers email protection, device management, and the documentation a survey asks for. Learn more about our approach to healthcare IT.

Contact Us to talk through what your agency needs.