HIPAA Audit Checklist for Corneal Transplant Eye Banks: Email Encryption and BAA Status

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

HIPAA Audit Checklist for Corneal Transplant Eye Banks: Email Encryption and BAA Status

Kevin Henry

HIPAA

September 17, 2026

8 minutes read
Share this article
HIPAA Audit Checklist for Corneal Transplant Eye Banks: Email Encryption and BAA Status

Email Encryption Standards

You handle electronic protected health information tied to donors, recipients, and surgical coordination. Your email program must ensure confidentiality in transit and at rest, prove encryption occurred, and provide safe fallbacks when counterparties cannot receive encrypted messages.

Required controls to verify

  • Force TLS 1.2 encryption or higher for all SMTP connections; disable TLS 1.0/1.1 and weak ciphers. Reject or auto-route to a secure message portal if enforced TLS is unavailable.
  • Use S/MIME or PGP for end-to-end protection when sending highly sensitive ePHI or when policy requires non-repudiation and message integrity.
  • Apply AES-256 encryption for mailboxes, message archives, and backups. Require full‑disk encryption on laptops and mobile devices that sync mail.
  • Validate certificates (no self‑signed in production), enable certificate pinning where supported, and monitor for downgrade attempts.
  • Prevent ePHI in subject lines; use message classification/sensitivity labels to trigger encryption or DLP actions automatically.
  • Harden the domain with SPF, DKIM, and DMARC to reduce spoofing risk that can lead to misdelivery of ePHI.

Key management expectations

  • Store keys in a hardened KMS or HSM; restrict access to security administrators only.
  • Rotate keys on a defined schedule and upon staff role changes or suspected compromise.
  • Document key escrow, recovery, and revocation procedures; test them at least annually.

Corneal transplant–specific notes

  • When emailing pathology results, serology, or match data to external surgeons or tissue processors, require enforced TLS or a secure portal—no opportunistic fallbacks.
  • Keep shipping emails free of ePHI; if unavoidable, encrypt attachments and minimize identifiers.

Business Associate Agreement Compliance

Confirm that every vendor with access to ePHI—directly or indirectly—has an executed business associate agreement. Typical examples include cloud email providers, secure messaging vendors, eFax services, managed IT, backup/archiving, DLP/IR tooling, and incident-response firms.

BAA checklist

  • Permitted and required uses/disclosures of ePHI and the minimum necessary standard.
  • Administrative, physical, and technical safeguards aligned to the HIPAA Security Rule.
  • Breach and security incident reporting duties, including timelines and cooperation.
  • Subcontractor “flow‑down” obligations ensuring the same protections and BAAs downstream.
  • Individual rights support (access, amendment, accounting of disclosures) to the extent handled by the vendor.
  • Return or destruction of ePHI at termination and contingency for infeasible destruction.
  • Right to audit/assess, change‑notification obligations, and indemnification/termination for cause.

Ongoing BAA governance

  • Maintain a single source of truth for BAA status, effective dates, and renewal cycles.
  • Review BAAs at least annually and after material service or regulatory changes.
  • Verify that vendors’ encryption, access control, and audit commitments match your policies.

Access Control Implementation

Strong identity and authorization guard who can access mailboxes that store ePHI. Build controls that assume phishing and credential theft will be attempted.

Identity and authentication

  • Issue unique user IDs; prohibit shared accounts for clinical coordination.
  • Enforce multi-factor authentication globally. Prefer phishing‑resistant factors (hardware keys or device‑bound authenticators) over SMS codes.
  • Block legacy protocols (POP/IMAP/SMTP AUTH without modern auth) and enforce conditional access for risky sign‑ins and unmanaged devices.

Authorization and mailbox governance

  • Apply least privilege and role‑based access; document approvals for delegated mailbox access.
  • Use time‑bound access for coverage and “break‑glass” accounts with extra monitoring.
  • Recertify access quarterly; remove permissions immediately when roles change.

Endpoint and client controls

  • Allow only compliant, encrypted devices; enable remote wipe for lost or stolen endpoints.
  • Disable external auto‑forwarding by default; require exceptions to be approved and logged.
  • Block unvetted third‑party mail apps; require modern authentication and device compliance.

Audit Logging Requirements

Audit logs must prove who accessed ePHI, what changed, and whether encryption and DLP controls worked. Logs should be tamper‑evident and centrally retained.

Ready to assess your HIPAA security risks?

Join thousands of organizations that use Accountable to identify and fix their security gaps.

Take the Free Risk Assessment

Events to capture

  • User sign‑ins (success/failure), MFA prompts, and risk signals.
  • Message send/receive, direction (internal/external), and TLS negotiation/encryption status.
  • Creation or change of inbox rules, auto‑forwarding, and delegated access.
  • Admin changes to policies, DLP rules, retention, and mailbox ownership.
  • Exports: eDiscovery, PST/mailbox exports, and large downloads.
  • DLP detections, overrides, and justifications.

Integrity, retention, and review

  • Stream logs to a SIEM or write‑once storage; time‑sync all systems.
  • Restrict log access; monitor for deletion attempts and configuration drift.
  • Retain security-relevant logs per policy; many organizations align critical audit logs to the six‑year documentation window used for HIPAA policies and procedures.
  • Review high‑risk alerts daily, standard reports weekly, and perform quarterly deep‑dives and after‑action reviews post‑incident.

Data Loss Prevention Measures

Data loss prevention policies stop ePHI from leaving via unsafe channels and enforce encryption automatically. Combine pattern detection with workflow‑friendly exceptions.

Design effective DLP policies

  • Detect PHI patterns (e.g., MRNs, donor IDs, SSNs) and use medical dictionaries relevant to corneal transplant terms and forms.
  • Scan attachments and images with OCR; require encryption or block on detection to external recipients.
  • Trigger warnings or approval workflows for borderline cases; require business justification for overrides and log them.
  • Quarantine risky messages; restrict mass external sends and large BCC lists.

Strengthen with classification and rights

  • Auto‑label messages containing ePHI; apply encryption and “no forward/print” rights as needed.
  • Block external auto‑forwarding and unsanctioned cloud shares to protect auditability.

Measure and educate

  • Track top DLP violations, root causes, and time‑to‑remediate.
  • Run targeted training based on real violations; test with simulations and tune rules to reduce false positives.

Risk Analysis and Management

Your risk analysis anchors every “reasonable and appropriate” control decision. Map where ePHI flows, who touches it, and how email systems can fail.

Structured assessment

  • Inventory systems (mail, archiving, mobile, backups) and third parties under a business associate agreement.
  • Diagram data flows for donor/recipient coordination, lab results, and surgical scheduling.
  • Score threats like misaddressed email, mailbox compromise, misconfigured TLS, and stale BAAs for likelihood and impact.

Treat and track risks

  • Mitigate with controls (forced TLS, MFA everywhere, DLP, logging), transfer via contracts/insurance, accept with justification, or avoid by changing processes.
  • Record owners, deadlines, and residual risk; revisit after changes or incidents.

Eye bank context

  • Plan for after‑hours coordination and volunteer access using managed devices and strong MFA.
  • Whitelist trusted partners; require encryption and confirmation workflows before sending sensitive recipient data externally.

Incident Response Planning

Email incidents happen—wrong recipient, lost device, or compromised mailbox. A rehearsed plan limits exposure, speeds notification, and strengthens future controls.

Prepare playbooks and teams

  • Create playbooks for misdirected email, mailbox compromise, lost/stolen device, DLP violations, and vendor breaches.
  • Define a contact tree (privacy officer, security lead, legal, clinical operations, vendors) and required evidence to collect.

Detect, triage, and contain

  • Use alerts for impossible travel, unusual send volumes, or new auto‑forwarding rules.
  • Immediately revoke tokens, reset credentials, disable forwarding, and isolate affected devices.
  • Scope what ePHI was exposed using audit logs and DLP artifacts; preserve evidence.

Eradication, recovery, and notification

  • Remove malicious rules, re‑enroll MFA, and reimage compromised endpoints as needed.
  • Notify affected individuals and partners and make any regulator notifications required by the HIPAA Breach Notification Rule; coordinate with counsel.
  • Conduct lessons learned; update risk analysis, BAAs, training, and controls.

Conclusion

By enforcing TLS 1.2 encryption or stronger, applying AES-256 encryption at rest, executing and governing every business associate agreement, hardening access with multi-factor authentication, maintaining actionable audit logs, deploying data loss prevention, and rehearsing incident response, your corneal transplant eye bank can demonstrate a defensible, efficient, and HIPAA‑aligned email program.

FAQs

What encryption protocols are required for HIPAA-compliant emails?

HIPAA is technology‑neutral, but you should require TLS 1.2 encryption or higher for email in transit and use end‑to‑end options like S/MIME or PGP when sensitivity or partner policy demands it. Protect stored messages, archives, and backups with AES-256 encryption and use FIPS‑validated crypto modules where available. Document your choices in the risk analysis and enforce a secure portal fallback if enforced TLS is unavailable.

How often should audit logs be reviewed for ePHI access?

Set real‑time alerts for high‑risk events, review summary reports at least weekly, analyze trends monthly, and perform quarterly deep‑dives with sample validation. Always conduct an immediate ad‑hoc review after suspected incidents or major changes. Ensure audit logs include sign‑ins, encryption status, mailbox rule changes, admin policy edits, DLP events, and exports.

What key elements must be included in a Business Associate Agreement?

Include permitted uses/disclosures, minimum necessary, required safeguards, breach and incident reporting, subcontractor flow‑down, support for individual rights where applicable, return/destruction of ePHI at termination, right to audit/assess, change‑notification, and termination for cause. Keep signed copies centrally and review after service or regulatory changes.

How can auto-forwarding impact HIPAA compliance?

Auto‑forwarding can bypass encryption, defeat data loss prevention, and create disclosures you cannot track or revoke—especially to personal email. Most programs disable external auto‑forwarding by default, allow exceptions only for vetted destinations with a business associate agreement, and require enforced encryption plus logging and alerts for any allowed forward rules.

Share this article

Ready to assess your HIPAA security risks?

Join thousands of organizations that use Accountable to identify and fix their security gaps.

Take the Free Risk Assessment

Related Articles