MANAGED
SECURITY
24/7 monitoring, advanced threat detection, proactive ramsomware defenses and inmediate incident response
MANAGED
SECURITY
24/7 monitoring, advanced threat detection, proactive ramsomware defenses and inmediate incident response
Still Using Gmail for Your Dental or Healthcare Practice?
If your practice uses a personal Gmail account for business communications — especially when patient information may be involved — there are important security, privacy, and HIPAA considerations you should understand.
Why Can Personal Gmail Be a Problem for a Healthcare Practice?
1. Who Actually Controls the Account?
With a personal Gmail account, the account is associated with an individual Google account.
A properly managed business email system allows the practice to centrally control its email accounts.
That becomes especially important when:
- An employee leaves the practice
- An employee changes roles
- A password is compromised
- A device is lost or stolen
- Someone needs emergency access to a mailbox
- An account needs to be disabled immediately
Your practice should control its business information — not depend on an account that is managed like a personal email account.
2. HIPAA Requires More Than a Password
Protecting electronic Protected Health Information (ePHI) involves more than choosing a strong password.
Healthcare organizations need to consider appropriate administrative and technical safeguards for systems that handle sensitive patient information.
Depending on how email is used, this may include controls such as:
- Access management
- Multi-factor authentication
- Account monitoring
- Appropriate security policies
- Employee access and termination procedures
- Audit capabilities
- Data retention and backup
- Incident response
- Appropriate agreements with service providers handling ePHI
Simply having an email address does not address all of these responsibilities.
3. What Happens If Your Gmail Account Is Compromised?
Email accounts are a valuable target for cybercriminals.
Once an attacker gains access to a practice mailbox, they may be able to:
- Read sensitive conversations
- Search historical email
- Reset passwords for other services
- Impersonate the practice
- Send phishing messages to employees or patients
- Redirect invoices or payment instructions
- Access documents stored or shared through the account
For a healthcare organization, an email compromise can become much more than an IT inconvenience.
It can become a security incident, business interruption, or potential data breach.
4. Employee Changes Can Create Another Problem
Consider a simple situation:
Your office manager has been using the practice’s Gmail account for years.
What happens when that employee leaves?
Who knows the password?
Is the recovery phone number theirs?
Is their personal email configured as the recovery address?
What devices are still signed into the account?
Does the practice know everywhere the password has been saved?
A professionally managed business email environment gives the organization centralized control over employee accounts and access.
5. Business Associate Agreements (BAA)
@gmail.com) and Yahoo (@yahoo.com) are not HIPAA compliant and cannot be made compliant. They do not offer a Business Associate Agreement (BAA), which is a required legal contract under HIPAAWhat Does Properly Managed Business Email Look Like?
Instead of:
your practice can communicate using:
But using your own domain is only part of the solution.
A properly managed environment can also provide:
✓ Organization-owned accounts
✓ Centralized administration
✓ Multi-factor authentication
✓ Employee access controls
✓ Security policies
✓ Account monitoring
✓ Better account recovery
✓ Email threat protection
✓ Backup and retention options
✓ Controlled employee onboarding and termination
✓ A more professional identity for your practice
“But We’ve Used Gmail for Years and Never Had a Problem.”
That’s common.
Many practices created a Gmail account when the business was small because it was easy and free.
The practice grew.
More employees gained access.
More information moved online.
And the original Gmail account simply stayed in place.
The fact that an account has never been compromised doesn’t necessarily mean the current setup provides the security controls your practice needs today.
Does Using @gmail.com Automatically Mean You’re Violating HIPAA?
No.
Seeing an @gmail.com address alone is not enough to determine whether an organization is HIPAA compliant.
HIPAA compliance depends on multiple factors, including what information is being transmitted or stored, how systems are configured, what safeguards are in place, how access is controlled, and the relationships and agreements with service providers.
However, if your healthcare practice relies on a personal/consumer email account for business communications, it is worth reviewing whether that setup provides the appropriate controls for your organization.
Not Sure About Your Practice’s Email?
We’ll Check It for You.
We offer dental and healthcare practices a complimentary Email Security Check.
We’ll help you determine:
✓ Whether you’re using personal or organization-managed email
✓ Whether your domain has business email configured
✓ Whether important email security protections are enabled
✓ Whether MFA is properly implemented
✓ Whether employee access is centrally controlled
✓ Whether backup and recovery should be improved
✓ Whether there are obvious security issues that should be addressed
No obligation. No complicated technical report.
We’ll simply tell you what we find and what we recommend.
Already Have Business Email?
Great.
If your practice already uses a properly managed business email system and Gmail is simply an old public contact address, you may already have many of these protections in place.
We can still review the configuration if you’d like a second opinion.
Protect Your Practice. Protect Your Patients. Protect Your Reputation.
Your email system is one of the most important communication tools in your practice, make sure it is being managed like one.
REQUEST MY FREE EMAIL SECURITY CHECK
This information is provided for general educational purposes and is not legal advice. HIPAA compliance depends on your organization’s specific circumstances, systems, policies, procedures, agreements, and use of technology.