How to Conduct a Risk Assessment for PET CT Report Email Workflows to Outside Oncology Referral Groups

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

How to Conduct a Risk Assessment for PET CT Report Email Workflows to Outside Oncology Referral Groups

Kevin Henry

Risk Management

September 15, 2026

7 minutes read
Share this article
How to Conduct a Risk Assessment for PET CT Report Email Workflows to Outside Oncology Referral Groups

Identify Key Workflow Components

Map the end-to-end process

Start by diagramming how PET CT reports are generated, reviewed, attached, addressed, sent, received, stored, and archived. Include every handoff—radiologist to coordinator, coordinator to oncologist, and any automated steps in your email gateway or EHR messaging module.

Define actors, systems, and data

  • Actors: radiologists, technologists, schedulers, tumor board coordinators, IT admins, and recipients in outside oncology referral groups.
  • Systems: PACS, RIS/EHR, dictation tools, PDF generators, email clients, secure email gateways, mobile devices, and archives.
  • Data: PET CT reports, images or key images, patient identifiers, diagnosis codes, and scheduling details—classified as PHI requiring HIPAA compliance.

Catalog communication channels and destinations

  • Channels: standard email, secure portal notifications, automated EHR-to-email integrations.
  • Destinations: individual oncologists, group inboxes, shared mailboxes, and third-party coverage services associated with referral practices.

Inventory controls already in place

Document existing email security protocols, PHI encryption at rest/in transit, address verification steps, recipient whitelists, DLP rules, and message retention policies. Note any unauthorized access controls and approval checkpoints currently used.

Analyze Data Privacy and Security Risks

Confidentiality, integrity, and availability (CIA)

  • Confidentiality: exposure of PHI via misaddressed messages, weak authentication, or inadequate transport security.
  • Integrity: altered or mismatched patient data due to attachment errors or report version mix-ups.
  • Availability: delays from quarantines, bounces, or outages that impact clinical decisions.

Regulatory and governance considerations

Validate that workflows meet HIPAA compliance requirements and your healthcare data governance policies. Confirm role-based access, minimum-necessary disclosure, retention schedules, and data breach notification procedures aligned to organizational and legal expectations.

Technology and human-factor risk sources

  • Technology: inadequate TLS enforcement, missing S/MIME, weak endpoint protections, and inconsistent DLP tuning.
  • Human factors: address autocomplete errors, reply-all mishaps, rushed after-hours sends, and unverified recipient changes from referral offices.

Evaluate Threat Scenarios

  • Misaddressed email sends PHI to the wrong provider or domain.
  • Mailbox compromise via phishing leads to unauthorized email forwarding.
  • Unencrypted transport to a recipient server that does not support modern TLS.
  • Shared group inbox at a referral site lacks adequate access oversight.
  • Attachment contains the wrong patient or embedded metadata revealing extra PHI.
  • Device loss/theft results in local email cache exposure on laptops or phones.
  • Inadequate offboarding leaves former staff with residual access or cached data.
  • Automated rules (e.g., forwarding) bypass DLP or classification tags.
  • Vendor email gateway misconfiguration disables encryption or alters routing.
  • Excess retention exposes PHI beyond business need in sent folders.
  • Bounce or NDR handling re-sends to outdated or incorrect contacts.
  • Denial-of-service on email systems delays urgent oncology communication.

Assess Risk Likelihood and Impact

Define a scoring model

Use a 1–5 scale for likelihood and impact, multiply for a composite score (R = L × I), and map to a 5×5 matrix (low, moderate, high, critical). Establish risk acceptance thresholds and escalation paths before scoring.

Score representative scenarios

  • Misaddressed email with PHI: Likelihood 3–4; Impact 4–5 (often high to critical due to privacy exposure).
  • Unencrypted transport to external server: Likelihood 2–3; Impact 4–5 (depends on volume and sensitivity).
  • Mailbox compromise (phishing): Likelihood 2–3; Impact 5 (persistent exposure and mass export risk).
  • Excess retention in sent folders: Likelihood 4; Impact 3–4 (cumulative exposure over time).

Validate assumptions with evidence

Pull email gateway reports, DLP incident trends, TLS adoption statistics, and incident tickets to ground scores in current data. Document uncertainties and plan targeted tests to refine estimates.

Ready to assess your HIPAA security risks?

Join thousands of organizations that use Accountable to identify and fix their security gaps.

Take the Free Risk Assessment

Develop Risk Mitigation Strategies

Technical controls

  • PHI encryption: enforce TLS 1.2+ with MTA-STS and fallback to secure message portals; enable S/MIME for sender authentication and message-level protection.
  • Email security protocols: implement SPF, DKIM, and DMARC to reduce spoofing; tune DLP for medical terms, MRNs, and image-report patterns.
  • Access protections: require MFA for email, apply conditional access, and implement unauthorized access controls with least privilege and time-bound access.
  • Endpoint safeguards: full-disk encryption, locked screens, mobile device management, and remote wipe for lost or stolen devices.
  • Data minimization: strip unnecessary PHI from subject lines and body; use standardized, templated messages with identifiers limited to the minimum necessary.

Process and people controls

  • Address hygiene: verified address books, periodic recipient re-validation with referral groups, and optional two-person checks for new or high-risk recipients.
  • Attachment integrity: automated patient-to-report matching, final preview prompts, and PDF sanitization to remove hidden metadata.
  • Training and simulation: targeted education on autocomplete risks, reply-all pitfalls, and simulated phishing tied to just-in-time coaching.
  • Exception handling: bounce/NDR playbooks, monitored queues, and documented fallback to secure portals or fax only when policy permits.

Compliance and incident readiness

  • Policy alignment: codify HIPAA compliance expectations, retention limits, and acceptable use within email SOPs.
  • Third-party assurance: confirm covered-entity status of referral groups; maintain BAAs with email service providers as applicable.
  • Incident response: maintain breach triage criteria, legal review steps, patient communications, and data breach notification workflows.

Document Risk Assessment Findings

Produce a clear, actionable record

  • Risk register: scenario, cause, existing controls, score, owner, mitigation, due date, and residual risk.
  • Data flow diagram: systems, trust boundaries, encryption points, and alternate paths (e.g., portal).
  • Controls mapping: align to administrative, physical, and technical safeguards, and relevant internal policies.

Healthcare data governance and traceability

Embed the assessment within your healthcare data governance framework so stewardship, retention, and disposal rules guide daily operations. Ensure traceability from policy to control to evidence.

Audit trail documentation

Capture who sent what to whom, when, how it was protected, and any delivery anomalies. Preserve email gateway logs, DLP alerts, encryption outcomes, access attempts, and approval records to support audits and investigations.

Implement Continuous Monitoring and Improvement

Define metrics and thresholds

  • Encryption coverage rate across outbound messages to referral domains.
  • DLP incident volume, false-positive rate, and time-to-closure.
  • Phishing resilience metrics, MFA adoption, and anomalous forwarding rules detected.
  • Mean time to remediate misaddressed sends and bounce handling.

Operate, test, and recalibrate

Review dashboards weekly, run monthly sampling of sent messages for policy conformance, and conduct quarterly tabletop exercises on misdirected-email scenarios. Update DLP patterns and recipient whitelists as oncology partners change.

Conclusion

A rigorous, evidence-based approach lets you pinpoint where PET CT report email workflows expose PHI and apply targeted controls. By combining strong encryption, tuned email security protocols, practical process improvements, and disciplined audit trail documentation, you reduce risk while sustaining timely care coordination with outside oncology referral groups.

FAQs

What are the main risks in emailing PET CT reports to external groups?

The top risks include misaddressed messages, mailbox compromise through phishing, unencrypted transport to recipient servers, overexposed shared inboxes, and excessive retention in sent folders. Attachment errors and hidden metadata can also leak PHI if integrity checks and PDF sanitization are not enforced.

How can encryption improve PET CT report email security?

Encryption protects PHI in transit and at rest. Enforcing modern TLS between mail servers, using S/MIME for message-level protection, or delivering via a secure portal ensures only intended recipients can access reports. Strong key management and clear fallbacks when encryption cannot be negotiated are essential.

What compliance standards apply to sharing PET CT reports by email?

Workflows must meet HIPAA compliance requirements, including the Privacy, Security, and Breach Notification Rules. Your organizational policies and healthcare data governance standards also apply, and you should maintain evidence of controls, risk decisions, and data breach notification procedures when incidents occur.

How often should risk assessments for email workflows be updated?

Reassess at least annually, after any significant workflow, system, or partner change, and following security incidents or audit findings. Continuous monitoring metrics should inform interim updates so controls stay aligned with evolving threats and referral group changes.

Share this article

Ready to assess your HIPAA security risks?

Join thousands of organizations that use Accountable to identify and fix their security gaps.

Take the Free Risk Assessment

Related Articles