Is It HIPAA-Compliant to Send Eye Bank Tissue Matching Reports by Unencrypted Email? Guidance for Corneal Transplant Clinics

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

Is It HIPAA-Compliant to Send Eye Bank Tissue Matching Reports by Unencrypted Email? Guidance for Corneal Transplant Clinics

Kevin Henry

HIPAA

September 16, 2026

7 minutes read
Share this article
Is It HIPAA-Compliant to Send Eye Bank Tissue Matching Reports by Unencrypted Email? Guidance for Corneal Transplant Clinics

HIPAA Requirements for Transmitting ePHI

You handle electronic protected health information (ePHI) every time you receive or share eye bank tissue matching reports that identify a patient. Under the HIPAA Security Rule, you must safeguard the confidentiality, integrity, and availability of that ePHI during transmission. Encryption is an “addressable” implementation specification, which means you must adopt strong encryption protocols when reasonable and appropriate—or formally document why not and implement equivalent protections.

For routine clinic-to–eye bank exchanges, feasible encryption options exist and the data sensitivity is high. As a result, relying on unencrypted email is rarely defensible after a thorough risk analysis. You also must meet “minimum necessary” standards, authenticate senders/recipients, maintain audit controls, and ensure a Business Associate Agreement (BAA) is in place if the eye bank handles PHI on your behalf.

Patient-directed email is a narrow exception: if a patient clearly prefers unencrypted email after you warn them of the risks, you may accommodate that preference for communications with the patient. That exception does not extend to provider-to-provider transmissions like tissue matching reports between covered entities or business associates.

Risks of Using Unencrypted Email

Unencrypted email exposes ePHI to avoidable threats that typically fail a HIPAA risk analysis. Key risks include:

  • Interception over open networks, enabling unauthorized access to donor-recipient identifiers and clinical details.
  • Misdelivery from address auto-complete, reply-all mistakes, and outdated contact lists.
  • Persistent storage on third-party servers and backups outside your control, expanding exposure and retention.
  • Device compromise on recipient endpoints (lost phones, malware, or shared inboxes) without adequate safeguards.
  • Lack of assured encryption in transit and at rest; opportunistic TLS may downgrade or fail silently.
  • Metadata leakage; subject lines, headers, and routing data can reveal sensitive context even without attachments.
  • Automatic forwarding rules and shared mailboxes that bypass access controls and auditing.
  • Difficulty enforcing retention, revocation, or message expiration once an email leaves your environment.

Best Practices for Emailing Eye Bank Reports

If email is part of your workflow, configure it so that messages are protected end-to-end and your policies strictly limit risk. You should:

  • Enforce encryption protocols for all transmissions (for example, forced TLS with certificate validation, or end-to-end options like S/MIME or PGP) rather than relying on opportunistic encryption.
  • Use secure links in lieu of attachments whenever possible; send an expiring, access-controlled link to a secure repository rather than the file itself.
  • Apply the minimum necessary rule: exclude extraneous identifiers and redact donor data not needed for matching or clinical decision-making.
  • Protect attachments with strong encryption (e.g., AES-256) and share passphrases through a separate channel such as a verified phone call or secure text solution.
  • Harden address hygiene: disable global auto-complete, use verified address books, and require a second-person check for first-time recipients.
  • Deploy a secure email gateway with data loss prevention (DLP) to detect PHI, block outbound messages lacking proper safeguards, and log transmission details.
  • Keep PHI out of subject lines; use neutral descriptors and include confidentiality notices (not as a substitute for safeguards, but as a reminder).
  • Document your risk analysis and policy decisions; update them when you change vendors, workflows, or file formats.
  • Ensure a current BAA with the eye bank or exchange partner if they handle PHI on your behalf, and review their security posture annually.

When communicating directly with patients by email, obtain and record their preferences. Provide a clear explanation of unencrypted email risks, what types of information you may send, and safer options (such as a portal). Capture the patient’s chosen address and their acknowledgment in your EHR, and make opt-outs easy.

Patient preference does not override your duty to protect ePHI when sharing between covered entities or business associates. Do not use a patient’s consent as a basis to send tissue matching reports unencrypted to outside providers or eye banks. Apply role-based access, verify patient identity before sending sensitive results, and avoid mixing clinical detail with scheduling or general messages unless the entire exchange is appropriately secured.

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Secure Alternatives to Unencrypted Email

Replace unencrypted email with tools designed for regulated data exchange. Strong options include:

  • Direct Secure Messaging for provider-to-provider exchange with trusted certificates and delivery notifications.
  • EHR-integrated patient portals for secure messaging, document sharing, and automatic charting.
  • Managed file transfer (MFT) platforms using secure file transfer protocols (SFTP/FTPS) with granular access controls and audit trails.
  • Vendor portals provided by eye banks that use HTTPS with modern ciphers, multi-factor authentication, and explicit download permissions.
  • API-based exchange (e.g., FHIR) with OAuth2, token lifecycles, and server-side encryption at rest.

Whichever tool you choose, insist on multi-factor authentication, endpoint security, detailed logging, role-based access, and documented incident response. Bake these controls into your risk analysis and vendor due diligence.

Compliance Audit and Monitoring

Continuous oversight demonstrates diligence and helps you detect issues before they become breaches. Build a monitoring program that includes:

  • Periodic risk analysis and risk management updates when systems, partners, or data flows change.
  • Email security audits: TLS enforcement checks, DLP rule testing, simulated misdelivery drills, and review of blocked/flagged messages.
  • Comprehensive audit logs for message access, downloads, and link clicks, retained per your records policy.
  • Workforce training and sanctions policies focused on PHI handling, phishing awareness, and the pitfalls of unencrypted channels.
  • Vendor oversight: BAA reviews, security questionnaires, SOC reports where available, and remediation tracking.
  • Technical hardening: SPF, DKIM, and DMARC to reduce spoofing; mobile device management with encryption and remote wipe.

Mitigating Data Breach Consequences

If ePHI is exposed via unencrypted email, act immediately to contain, assess, and notify. A practical playbook looks like this:

  • Containment: attempt message recall from your secure gateway, disable links, and request recipient deletion and attestation. Secure affected accounts and devices.
  • Forensic assessment: determine what ePHI was involved, who accessed or could access it, whether it was actually viewed, and how long it remained exposed.
  • Risk assessment and documentation: evaluate the nature and volume of PHI, the unauthorized recipient, evidence of access, and mitigation steps. Retain detailed records.
  • Breach notification: when required, notify affected individuals without unreasonable delay and no later than 60 days after discovery; notify HHS, and when 500 or more residents of a state or jurisdiction are affected, notify prominent media as applicable.
  • Remediation: close control gaps (for example, enforce encryption, tighten DLP, revise procedures), retrain staff, and update your risk analysis and policies.
  • Post-incident monitoring: watch for misuse of data, strengthen vendor controls, and validate that corrective actions are effective.

FAQs.

What are the risks of sending ePHI via unencrypted email?

The main risks are interception, misdelivery, storage on third-party servers, device compromise, metadata exposure, auto-forwarding, and weak or failing transport encryption. These factors make it difficult to ensure confidentiality, integrity, auditability, and proper retention—all core requirements under the HIPAA Security Rule.

Patient preference can permit unencrypted email between you and the patient only after you explain the risks and document their choice. It is not a blanket permission for provider-to-provider exchanges. For tissue matching reports sent to or from other covered entities or business associates, you should use secure methods and enforce encryption based on your risk analysis.

What secure methods can replace unencrypted email for tissue matching reports?

Use Direct Secure Messaging, EHR portals, or managed file transfer solutions that rely on secure file transfer protocols (SFTP/FTPS). You can also employ enforced TLS with certificate pinning or end-to-end options like S/MIME/PGP, ideally via expiring secure links instead of attachments. Choose tools with multi-factor authentication, audit trails, and strong encryption at rest and in transit.

How should a clinic respond to a breach caused by unencrypted email transmission?

Move fast to contain exposure, perform a documented risk assessment, and follow breach notification requirements—contacting affected individuals without unreasonable delay and within 60 days if notification is required, and notifying regulators and media as thresholds dictate. Then remediate root causes, strengthen encryption protocols and DLP controls, retrain staff, and update your risk analysis and policies to prevent recurrence.

Share this article

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Related Articles