How MDofficeMail & CryptnSend Works
Email, Protected Health Informaion, and HIPAA
Majority of us use free email service like Gmail or the one provided by the internet or web hosting service prodiver. Connection to most of these services is standard, unencrypted/unsecured (HTTP) and the servers may not be secure. Meaning any sensitive information sent using these email services can be intercepted and stolen.

HIPAA doesn’t prohibit using email as a medium for sending/receiving Protected Health Information (PHI) in spite of this potential threat. However, by setting up standards it has ensured that the security of patient information via email-based communication is not compromised.

MDofficeMail has implemented these standards in their services and is fully compliant with HIPAA policies by following recommended procedures aimed at maintaining the integrity of PHI by restricting unwarranted access.

In 2010, the HITECH Act went into effect, amending the HIPAA Privacy and Security Rules. One of the most important change is, the maximum penalty for a HIPAA violation is increased to $1,500,000 from $250,000. Fines as well as criminal penalties can be imposed on the violating institution and the individuals involved.

The fact is that, not only the sender, but also the recipient should use a secure service to protect the data sent through email.
How MDofficeMail, HIPAA compliant email hosting service works
MDofficeMail offers security at both the ends, sender and recipient: SSL & MDVault

At the sender's end MDofficeMail operates securely without the need for additional software, hardware, or certificates. using SSL over the Web or through your existing email client (MS Outlook/Apple Mail etc) Our Webmail and POP/IMAP are always secure with SSL. SSL establishes encrypted pipe to our servers providing rock-solid protection.

So far so good. What about emails sent to unsecured recipients?

MDofficeMail offers MDVault to overcome this most important factor. MDVault is an exclusive service for maximum security to any recipient outside our servers by continuing SSL security pipe past our servers meeting the security needed for HIPAA and other regulatory requirements.


With MDofficeMail you are using VeriSign's RSA-powered SSL/TLS, the most powerful and secure form of SSL available. Right at the connection point, well before any login or password information is entered you are communicating over a secure channel!

( see message flow diagram below )

Sender's End

Webmail: While using MDOfficeMail via Web browser, SSL establishes an encrypted pipe to our servers using VeriSign's RSA-powered SSL/TLS, the most powerful and secure form of SSL available, providing rock-solid protection. Right at the connection point you are communicating over a secure channel, well before entering username and password!!


MS Outlook and other client applications: MDofficeMail works only with SSL/TSL and secure ports for POP, IMAP and SMTP while using desktop and smart phone emaill client applications. Though MDofficeMail looks similar to any other email service, the difference is that all messages sent and received are protected by SSL/TLS security along with our advanced Anti-Virus and Spam Filters. MDofficeMail works only with port 995 for POP, 993 for IMAP and 465 and 25 for SMTP. This prevents unsecured connection with the server.

 

Messages are encrypted automatically without any mannual intervention for security at recipient's end if the recipient is a non-MDofficeMail user. Message is securely stored in MDofficeMail server and a message receipt intimation is sent.

 

When the recipient is a MDofficeMail user, for the convenience of recipient secure message is directly delivered without the additional MDVault encryption. This prevents unnecessary decryption process by the MDofficeMail recipient.

 

Messages can be direcly delivered to non-MDofficeMail users also just by typing :: in the subject line. This is very useful when no-PHI messages are sent and will be convenient to the recipient.

Recipient's End

MDofficeMail user: Secure and HIPAA compliant messages are delivered just like any other email service. Messages can be viewed without the necessity of passwords or decryption process.

Non-MDofficeMail users: Received secure message is stored in MDVault without delivering it. Instead the recipient will receive a simple message informing the receipt of a secure message. When the recipient clicks on the link provided in the message, a secure webpage opens up and a secure SSL connection is established with the server. Recipient can view the message by entering password.

 

First time recipients need to create their password. Same password can be used to view messages from any MDofficMail user, anytime in the future. Sender can evaluate the first time recipient by with a security code. This auto-generated code can be provided by the sender and this needs to be entered by the recipient to create password.

 

Recipient can reply securely from the same window. Message can be securely downloaded and saved in the local computer. Further, anyone can initiate a secure message to any MDofficeMail by going to https://EmailYourDoc.com

Other Outstanding Facilities & Features
  • Facility to expire already sent message:  When an encrypted message consisting of PHI is sent to   wrong recipient, the sender can prevent the recipient from viewing that message by force expiring it.
  • Legal Archival: As required by HIPAA, all incoming and outgoing emails are stored in a secure remote   server which neither can be edited nor deleted.
  • Automatic Session timeout for web browser as well as MDVault, as required by HIPAA.
  • Access logs and Audit controls: Access logs can be viewed for each user, as required by HIPAA.
  • Facility to validate new recipient. New recipient needs to enter a 6-digit code to access email received. This auto-generated code can be provided only by the sender of the message.
  • "Email Your Doc" Anyone can initiate secure message to MDofficeMail user.
  • Mobile phone access: Our service is HIPAA compliant with most of the smart phones.
  • BCC Archiving: Domain level BCC archiving can be configured so that all the incoming and outgoing messages of all users can be saved into a specific mail account.
  • Customization: MDofficeMail offers very high level of UI customization. Custom logos, banners, and look&feel is possible for domain plans.
  • Calendar, a great planning tool. Set reminder messages for appointments and work deadlines. Since MDoffice Mail calendar automatically stores information on your email server, you can access your schedule from any computer you use. Optionally share your entire calendar or just particular events with other users.
  • Emergency Glass Break. Administrator can access the email messages of other users in the domain   in case of emergency.
  • Security is strictly enforced. MDofficeMail can be accessed only with https and ports 995, 993, 465, and 25
  • Encryption is enforced by default for all emails that are leaving MDofficeMail server. Configurable to send plain msgs by default and encrypted msgs manually for domain accounts.
  • End-to-end protection. Secure access not only at sender's end, but also at recipient's end irrespective of the email service the recipient is using. Learn how...
  • Secure but plain message are sent to all MDofficeMail users and"Family & Friends" automatically. Our service is capable of detecting other users of MDofficeMail service and automatically plain messages are sent to them. Email ids of friends and family can be configured so that they will receive plain messages automatically.
  • Facility to send plain messages: Unencrypted emails can be sent just with a single click.
  • File sharing, a great feature to share files, pictures, patient education forms, etc.
  • Advanced spam prevention and virus filtering: MDoffice Mail offers advanced features to identify   undesirable spam email, block virus infected mail and prevent abuse of your mail server by spammers.   Naturally these features can be individually configured.
  • Auto migration. Migrate messages from the inbox of your other email account with ease.
  • Change password reminder: User is prompted to change password after 80th day. As HIPAA compliance  recommends to change password every 90 days, users are automatically reminded to change password.
  • Strict Privacy Policy: MDofficeMail strongly believes in safe-guarding their client details. Client information   including name, address, and phone number will not be given to any third party. MDofficeMail never stores credit card details. Credit card payments are processed by PayPal and details are securely saved by PayPal and MDofficeMail doesn't have access to those details.
How Crypt-n-Send, Email Encryption Service works
CryptnSend offers security for any email account, at both sender and recipient's ends

CryptnSend email encryption service is meant for providing security and compliance to Gmail, Yahoo and other free email service users, CryptnSend also for any email acccount that is hosted elsewhere.

 

CryptnSend operates securely using SSL over the Web or through your existing email client (Outlook Express/MS Outlook etc) without the need for additional software, hardware or certificates. Our Webmail and POP/IMAP are always secure with SSL. Additionally, SSL establishes an encrypted pipe to our servers using VeriSign's RSA-powered SSL/TLS, the most powerful and secure form of SSL available, providing rock-solid protection. Right at the connection point you are communicating over a secure channel, well before entering username and password!!

 

Sender's End of CryptnSend subscriber:

  • Continue to use your existing email account as before.
  • Subscribe to Crypt-n-send service for your current email id and setup CryptnSend password.
  • Url for CryptnSend Webmail and SMTP server details will be provided to you.
  • You are ready to send secure messages in four different ways:
    1. Compose-Webpage
    2. Webmail
    3. iPhone/Android App
    4. MS Outlook / Apple Mail / Any other email client application

    Compose-Webpage, Webmail, and iPhone/Android App: Login with your email id and CryptnSend password, compose and send. For MS Outlook / Apple Mail / Any other email client application, create a new account in the application using your email id, CryptnSend password and CryptnSend SMTP server details. Use this account to send secure messages and your regular account to send other messages without PHI.
  • Message sent is using any of the above methods are routed through the SMTP server of CryptnSend service instead of the SMTP of original service provider of that email account.
Recipient's End of CryptnSend message

MDofficeMail users: Secure and HIPAA compliant message is delivered just like any other email service. Messages can be viewed without the necessity of passwords or decryption process.

Non-MDofficeMail users: Message send using CryptnSend is stored in MDVault without delivering it. Instead the recipient will receive a simple message informing the receipt of a secure message. When the recipient clicks on the link provided in the message, a secure webpage opens up and a secure SSL connection is established with the server. Recipient can view the message by entering password.

 

First time recipients need to create their password. Same password can be used to view messages from any MDofficMail user, anytime in the future. Sender can evaluate the first time recipient by with a security code. This auto-generated code can be provided by the sender and this needs to be entered by the recipient to create password.

 

Recipient can reply securely from the same window. Such replies will be encrypted and delivered to the regular (original) Inbox of CryptnSend user. Message can be securely downloaded and saved in the local computer.

Compare MDofficeMail (hosting), Crypt-n-Send, and other email services. Click here...

Default Message Flow & Properties with MDofficeMail
HIPAA email message flow diagram

 

 

 

 

 

 

Who we are

 

 

MDofficeMail is Illinois-based LLC with registered office at Naperville, IL . MDofficeMail is the sister concern of:

 

 

 

 

 

 

 

Vision Infonet Inc

 

Vision Infonet is a 12-year-old Illinois corporation serving US Healthcare Industry with software development, medical billing, and medical transcription and other back-office services. Vision Infonet is serving more than 2000 clients across United States.

 

 

 

 

 

 

 

 

Practice Management System LLC

 

Practice Management System is a 50-year-old California LLC located at Burlingame, CA. PMS is one of the oldest billing service providers in the State of California.

 

 

 

and

 

 

MDCare EMR.

 

MDCare EMR/PMS is a high-end, web-based Electronic Medical Records and Practice Management System from Vision Infonet. MDCare is offered as software product as well as web-based service to medical offices in the United States.

 

 

 
HIPAA email

© Copyright 2012. MD Office Mail. All Rights Reserved

Privacy Policy Support Webmail Help Designed by Vinfonet