← Industries
For Healthcare Teams

One misdirected email carrying PHI is a breach — not an apology call.

Two similarly-named patient charts open at once, a rushed send between appointments, and autocomplete fills in the wrong recipient. That's not negligence — it's an understaffed clinic moving fast. But HIPAA doesn't grade on intent.

The problem

It's not carelessness. It's volume, understaffing, and identical names.

A front-desk coordinator or care manager sends dozens of patient-related emails a day — referrals, lab result summaries, scheduling notes — often between patients, often with two tabs and two nearly identical names open at once. Autocomplete doesn't know that "Jane Doe" in one thread isn't the "Jane Doe" you mean in this one. It just fills in whichever name it saw most recently.

Under HIPAA, an email carrying protected health information (PHI) sent to the wrong recipient is a reportable breach in most cases — not a technicality. Depending on scope, that can mean mandatory breach notification to the patient, potential notification to HHS Office for Civil Rights, and civil penalties that scale with how many records were exposed and whether the breach reflects a pattern rather than a one-off.

The cost isn't just the fine. It's the OCR complaint process, the corrective action plan, and — for a small practice — the reputational hit of a patient finding out their diagnosis or treatment details went to a stranger's inbox.

What the sender sees in Outlook — before the email leaves the outbox.

What teams already try

Training covers the policy. It doesn't cover the busy Tuesday.

Most practices run annual HIPAA training that includes "double-check the recipient before sending PHI." It's good guidance and it doesn't survive contact with a full waiting room — the moment staff are most rushed is exactly the moment they're least likely to pause and verify.

Encrypted email platforms help with interception in transit, but they don't stop the message from reaching the wrong person in the first place — encryption protects the pipe, not the address book. If the recipient is simply wrong, encryption faithfully delivers the PHI to them anyway.

Enterprise DLP tools can scan for PHI-shaped content (patterns like diagnosis codes or insurance numbers), but they're expensive to configure for a small or mid-size practice and still don't catch the simplest failure mode: the right patient's info sent to the wrong similarly-named recipient, where nothing about the content itself looks unusual.

How Sendasta helps

A check on who it's going to — right before it goes.

Sendasta checks the recipient list — To, Cc, and Bcc — against rules your practice sets, at the exact moment someone clicks Send in Outlook. It never reads the body or attachments, so it never touches PHI — which also means it doesn't add HIPAA exposure of its own.

  • Blocked domains — flag personal email domains (Gmail, Yahoo, etc.) or known-wrong destinations outright. If one shows up as a recipient, the send is paused before it goes out.
  • No-combine pairs — flag two domains that should never appear together on a thread, useful when the same staff member handles correspondence for multiple unaffiliated practices or referral partners.
  • Trusted pairs — mark legitimate recurring combinations (a lab partner, a referral network) as trusted once, so routine sends aren't interrupted.

For a clinic or practice group, an admin sets policy once and rolls it out to every staff member's Outlook via the Microsoft 365 Admin Center — no per-user configuration, and no relying on each employee to remember to slow down.

See pricing for practice-wide deployment
Questions from healthcare teams

Frequently asked

Does Sendasta read patient information in the email?

No. Sendasta only checks the addresses in the To, Cc, and Bcc fields against your organization's rules — it never opens the body or attachments, so it never sees PHI. The check runs locally in Outlook the moment someone clicks Send, and nothing is transmitted to a server.

Is Sendasta itself HIPAA compliant, since it touches recipient addresses?

Sendasta is designed with a minimal data footprint by intent — it doesn't transmit or store email content, and the business tier strips personally identifying fields from the anonymized usage analytics it does send. Because it never processes PHI, it doesn't require a Business Associate Agreement (BAA) to use. If your organization needs a signed BAA for procurement reasons regardless, reach out at info@sendasta.com.

Can it stop PHI from going to a personal email address, like a Gmail account?

Yes — flag personal email domains (gmail.com, yahoo.com, etc.) as blocked, and any email addressed to one is paused before it sends. This catches the common case of a staff member forwarding something to their own personal account "to work on later."

Will this slow down front-desk or clinical staff during a busy shift?

No — the check runs in under a second and only interrupts a send when it matches a rule. The other 99% of sends — appointment confirmations, internal notes, routine correspondence — go through exactly as fast as they do today.

Catch it before it becomes a breach report.

Get started free for personal use, or reach out and we'll walk you through setting up practice-wide policy for your team.