We need to maintain HIPPA compliance for forms on our website that are currently mailed to an internal email address. While the user/customers provides the info over HTTPS, we still want to make sure that we remain compliant…
Are there any plugins for ensuring that emails sent from the WordPress application to a recipient are encrypted?
Essentially, I want to make sure that the data is secured from the time a customer gives us the data to the time it arrives on our encrypted mail server.
Update on HIPPA Compliance
Disclaimer: I am not an attorney nor a compliance official. What follows is my interpretation of the rules and laws and it may not be accurate. I would encourage you to exhaust your resources to make sure that your organization is meeting all compliance requirements where applicable by law or morals.
- HIPPA FAQ Site on Email
- HIPAA Security Rule requirements at 45 C.F.R. Part 164, Subpart C
From a quick read of the above 2 links, it seems that the requirement is to simply try to ensure all possible and appropriate safeguards are in place. If the data can be encrypted, then it should. I am seeking further guidance from a compliance officer to ensure that we are doing everything possible to safely transport customer data to our staff.