It's unlikely they'll receive a complaint/investigation for installing that software.
It's unlikely they'll receive a complaint/investigation for installing that software.
Dear member,
You have a new message from *Redacted Healthcare System*
Please click on the link below, or copy and paste the link into your browser.
So from the email it's impossible to tell if it's even a message for me, or someone else in my household that I'm authorized to receive healthcare information for. And it hardly seems any more revealing than the weekly "wellness emails" that every healthcare system seems to send to its members.HHS specifically allows a provider to use email:
The Privacy Rule allows covered health care providers to communicate electronically, such as through e-mail, with their patients, provided they apply reasonable safeguards when doing so. See 45 C.F.R. § 164.530(c).
http://www.hhs.gov/hipaa/for-professionals/faq/570/does-hipa...
I'll go further to say it's probably one of the best models a company can use since vast majority of INFOSEC research and product development goes into exactly that sort of construction and tech. Even high assurance sector has solutions for some of that. Plus it has high usability and compatibility. Win across the board.