> The current method is for insurance companies to install software on their SMTP server and that's about it.
I would hope that they require TLS encryption for any connection to their SMTP server. Otherwise, any communication containing PHI could easily be intercepted. This also doesn't address the issue of securing the IMAP or Exchange and MTA server(s) that the sender uses to send the email to the insurance company.
> much less chance of mistakes
Unless the sender CCs a copy to another address where the MTA doesn't require TLS encrypted connections and doesn't have any such software installed on the MTA. That's why the solution I proposed (having the client program automatically encrypt the email before sending it and relying on PKI to handle decryption on the other end) would be more fool-proof since, even if the email was CC'd to another address, it couldn't be decrypted by the unintended recipient.
As for the cost argument, I think it could be implemented as a nominal cost on top of the costs that the physician already incurs in the process of applying/renewing their license, the practice license, etc (e.g. name, mailing address, telephone number, fax number, email address along with your PKI state board signed certificate).
> Also, the vast majority of communication containing PHI is with insurance companies and the government
Doctors have to communicate with other physicians outside of their group practice, hospitals they may not be affiliated with, and pharmacies. How is PHI communication in this context currently handled?
> Of course there is no way to really tell unless we complete vet it out and put cost associations with everything and do PHI leak risk assessments.
That is true. But I think that the technology we currently have to secure communication between clients and webservers (that allows us to do things like buy things online, interact with the bank, file taxes, etc along with client side certificates) should work perfectly well with PHI containing information. The problem is setting up the PKI for that type of communication.
Since governments, universities, and private companies have already done this, there's no reason why hospitals (especially university affiliated hospitals), state boards, and health care providers can't also do this.