Does sending email using BCC make it HIPAA Compliant?
Published: Thursday, April 9th, 2009
People have asked us if sending an email to someone via BCC (Blind Carbon Copy) is HIPAA-compliant. For example, a doctor’s office sending a newsletter to its patients via BCC. The presumption is that because when a message is sent via BCC, the recipient’s email address is not visible in the message that there is no way to identify the individual(s) to whom the message was sent and thus the messages do not contain any “personally identifiable health information” that is protected by HIPAA.
The short answer is “BCC is not good enough“. For the long answer, read on.
Read the rest of this post »