# Should I delete my work email account?

**URL:** https://boards.straightdope.com/t/should-i-delete-my-work-email-account/684650
**Category:** In My Humble Opinion
**Created:** [March 27, 2014, 12:33am UTC](https://boards.straightdope.com/t/should-i-delete-my-work-email-account/684650 "2014-03-27T00:33:24Z")
**Posts on this page:** 20
**Page:** 1

<div class="post-metadata">

### Author: ![huitzilopochtli](https://avatars.discourse-cdn.com/v4/letter/h/e99b99/32.png) [@huitzilopochtli](https://boards.straightdope.com/u/huitzilopochtli)
#### Post date: [March 27, 2014, 12:33am UTC](https://boards.straightdope.com/t/should-i-delete-my-work-email-account/684650/1 "2014-03-27T00:33:24Z")

</div>

I have just quit my job at a chiropractor’s office. My boss asked me to send him the password to my email. This email is one that I set up because it was too difficult to sort out work email from personal. I set it up and it is attached to my personal info. Is it best if I delete the account? There are emails from patients and I don’t want/need to have patient information available to me.

---

<div class="post-metadata">

### Author: ![Inna\_Minnit](https://avatars.discourse-cdn.com/v4/letter/i/5f8ce5/32.png) [@Inna\_Minnit](https://boards.straightdope.com/u/Inna_Minnit)
#### Post date: [March 27, 2014, 12:47am UTC](https://boards.straightdope.com/t/should-i-delete-my-work-email-account/684650/2 "2014-03-27T00:47:43Z")

</div>

If HIPAA effects a chiropractor practice, you could be in trouble with this. Under the new [HITECH](https://en.wikipedia.org/wiki/Health_Information_Technology_for_Economic_and_Clinical_Health_Act) Law, individuals can face fines and possible jail time for breaching confidentiality. How on earth did you set up your own work email that isn’t controlled and administered by your employer? And to set it up attached to your own personal email? Wow. Not smart.

---

<div class="post-metadata">

### Author: ![huitzilopochtli](https://avatars.discourse-cdn.com/v4/letter/h/e99b99/32.png) [@huitzilopochtli](https://boards.straightdope.com/u/huitzilopochtli)
#### Post date: [March 27, 2014, 1:07am UTC](https://boards.straightdope.com/t/should-i-delete-my-work-email-account/684650/3 "2014-03-27T01:07:52Z")

</div>

Thank you. I agree. Do you suggest I delete this account?

---

<div class="post-metadata">

### Author: ![huitzilopochtli](https://avatars.discourse-cdn.com/v4/letter/h/e99b99/32.png) [@huitzilopochtli](https://boards.straightdope.com/u/huitzilopochtli)
#### Post date: [March 27, 2014, 1:10am UTC](https://boards.straightdope.com/t/should-i-delete-my-work-email-account/684650/4 "2014-03-27T01:10:15Z")

</div>

And yes, of course HIPAA applies to chiropractic offices.

---

<div class="post-metadata">

### Author: ![huitzilopochtli](https://avatars.discourse-cdn.com/v4/letter/h/e99b99/32.png) [@huitzilopochtli](https://boards.straightdope.com/u/huitzilopochtli)
#### Post date: [March 27, 2014, 1:20am UTC](https://boards.straightdope.com/t/should-i-delete-my-work-email-account/684650/5 "2014-03-27T01:20:26Z")

</div>

It appears I made a mistake and would appreciate any real advice.

---

<div class="post-metadata">

### Author: ![Really\_Not\_All\_That\_Bright](https://avatars.discourse-cdn.com/v4/letter/r/e8c25b/32.png) [@Really\_Not\_All\_That\_Bright](https://boards.straightdope.com/u/Really_Not_All_That_Bright)
#### Post date: [March 27, 2014, 1:29am UTC](https://boards.straightdope.com/t/should-i-delete-my-work-email-account/684650/6 "2014-03-27T01:29:59Z")

</div>

If the account wasn’t provided by your employer, you are essentially within your rights to do whatever you like with it. I would forward any work-related e-mail to your employer and delete it.

---

<div class="post-metadata">

### Author: ![huitzilopochtli](https://avatars.discourse-cdn.com/v4/letter/h/e99b99/32.png) [@huitzilopochtli](https://boards.straightdope.com/u/huitzilopochtli)
#### Post date: [March 27, 2014, 1:38am UTC](https://boards.straightdope.com/t/should-i-delete-my-work-email-account/684650/7 "2014-03-27T01:38:03Z")

</div>

I appreciate the advice. I have done just that.

---

<div class="post-metadata">

### Author: ![Inna\_Minnit](https://avatars.discourse-cdn.com/v4/letter/i/5f8ce5/32.png) [@Inna\_Minnit](https://boards.straightdope.com/u/Inna_Minnit)
#### Post date: [March 27, 2014, 2:55am UTC](https://boards.straightdope.com/t/should-i-delete-my-work-email-account/684650/8 "2014-03-27T02:55:10Z")

</div>

> [@Really\_Not\_All\_That\_Bright](#):
>
> If the account wasn’t provided by your employer, you are essentially within your rights to do whatever you like with it. I would forward any work-related e-mail to your employer and delete it.

The problem isn’t the email account, but the protected PHI it contains.

OP you say “of course” HIPAA applies to the chiropractor’s practice. That being the case, I’m surprised that they didn’t have in-place a more secure set-up. Even if it’s just a small shop, the email should have been set up and controlled by the business.

If your email isn’t encrypted, and I would bet it’s not, it is not HIPAA compliant. You opened yourself up to a huge personal liability. As I understand the laws, they can and do go after individuals. No way in hell I would use a personal email for medical purposes.

:smack:

---

<div class="post-metadata">

### Author: ![huitzilopochtli](https://avatars.discourse-cdn.com/v4/letter/h/e99b99/32.png) [@huitzilopochtli](https://boards.straightdope.com/u/huitzilopochtli)
#### Post date: [March 27, 2014, 3:05am UTC](https://boards.straightdope.com/t/should-i-delete-my-work-email-account/684650/9 "2014-03-27T03:05:21Z")

</div>

I would still appreciate any real advice. Thanks

---

<div class="post-metadata">

### Author: ![Silophant](https://avatars.discourse-cdn.com/v4/letter/s/a698b9/32.png) [@Silophant](https://boards.straightdope.com/u/Silophant)
#### Post date: [March 27, 2014, 3:14am UTC](https://boards.straightdope.com/t/should-i-delete-my-work-email-account/684650/10 "2014-03-27T03:14:53Z")

</div>

What do you mean by real advice? You’ve been getting real advice.

If you mean legal advice, you’re probably out of luck here. We have lots of lawyers who are posters, but they don’t, as a rule, dispense official legal advice to random anonymous people on the internet.

---

<div class="post-metadata">

### Author: ![huitzilopochtli](https://avatars.discourse-cdn.com/v4/letter/h/e99b99/32.png) [@huitzilopochtli](https://boards.straightdope.com/u/huitzilopochtli)
#### Post date: [March 27, 2014, 3:39am UTC](https://boards.straightdope.com/t/should-i-delete-my-work-email-account/684650/11 "2014-03-27T03:39:47Z")

</div>

Thanks for the clarification silophant

---

<div class="post-metadata">

### Author: ![Dangerosa](https://avatars.discourse-cdn.com/v4/letter/d/22d042/32.png) [@Dangerosa](https://boards.straightdope.com/u/Dangerosa)
#### Post date: [March 27, 2014, 12:19pm UTC](https://boards.straightdope.com/t/should-i-delete-my-work-email-account/684650/12 "2014-03-27T12:19:31Z")

</div>

> [@Inna\_Minnit](#):
>
> The problem isn’t the email account, but the protected PHI it contains.
> 
> OP you say “of course” HIPAA applies to the chiropractor’s practice. That being the case, I’m surprised that they didn’t have in-place a more secure set-up. Even if it’s just a small shop, the email should have been set up and controlled by the business.
> 
> If your email isn’t encrypted, and I would bet it’s not, it is not HIPAA compliant. You opened yourself up to a huge personal liability. As I understand the laws, they can and do go after individuals. No way in hell I would use a personal email for medical purposes.
> 
> :smack:

I’m not - small chiropractors office - especially if they are starting out or if the chiropractor is older - IT isn’t going to be a big priority.

My dentist is still using paper calendars for scheduling. Its an older practice, I don’t think its a really lucrative one, and scheduling software hasn’t been a priority - they don’t HAVE email. You call them. No web presence.

---

<div class="post-metadata">

### Author: ![Really\_Not\_All\_That\_Bright](https://avatars.discourse-cdn.com/v4/letter/r/e8c25b/32.png) [@Really\_Not\_All\_That\_Bright](https://boards.straightdope.com/u/Really_Not_All_That_Bright)
#### Post date: [March 27, 2014, 1:09pm UTC](https://boards.straightdope.com/t/should-i-delete-my-work-email-account/684650/13 "2014-03-27T13:09:48Z")

</div>

> [@Inna\_Minnit](#):
>
> If your email isn’t encrypted, and I would bet it’s not, it is not HIPAA compliant.

Cite?

---

<div class="post-metadata">

### Author: ![stpauler](https://avatars.discourse-cdn.com/v4/letter/s/9d8465/32.png) [@stpauler](https://boards.straightdope.com/u/stpauler)
#### Post date: [March 27, 2014, 1:26pm UTC](https://boards.straightdope.com/t/should-i-delete-my-work-email-account/684650/14 "2014-03-27T13:26:45Z")

</div>

> [@Really\_Not\_All\_That\_Bright](#):
>
> Cite?

[Here ya go:](http://www.ama-assn.org/resources/doc/washington/hipaa-phi-encryption.pdf)

> [@](#):
>
> HIPAA Security Rule: Frequently asked questions regarding encryption of personal health information
> 
> The Health Information Technology for Economic and Clinical Health (HITECH) Act, part of the American Recovery and Reinvestment Act of 2009, made several important changes to the HIPAA Security Rule. These changes have raised a number of questions about encryption among physicians and other health care professionals as well as other HIPAA-covered entities and business associates.1 This resource addresses the most common of these questions. Physicians should also note that states may have laws and regulations that go above and beyond the federal requirements outlined in this fact sheet and should confirm if any local requirements may apply.
> 
> 1. I manage a small practice. Why should I care about the changes to the HIPAA Security Rule?  
> Perhaps the most significant change to the HIPAA Security Rule is the requirement for HIPAA-covered entities and their business associates to provide notification in the event of a breach of “unsecured protected health information (unsecured PHI).” For more information on breaches of unsecured information see our Breach Notification Fact Sheet. This means, for example, that if a hacker were able to gain access to a physician practice’s computer system, laptop, tablet, PDA, etc. that contained PHI that was not encrypted, the physician practice may need to notify the affected patients and the Department of Health and Human Services (HHS) of the breach. In some cases, the physician practice would also need to notify the media. Therefore, not only can lack of compliance result in reputational harm to your practice, it can risk exposure of your patient’s most sensitive information.
> 2. How can I mitigate the HIPAA breach notification requirements?  
> Physicians, however, can avoid these notification requirements if the data is secured through encryption: If the electronic PHI (or ePHI) is stored and transmitted in encrypted form, then you do not need to notify patients, even if there is a security breach. The National Institute of Standards and Technology (NIST), an institute within the Department of Commerce that establishes standards for a variety of industries including health care, has issued Special Publication 800–66–Revision 1, “An Introductory Resource Guide for Implementing the HIPAA Security Rule,” that describes the technologies and methodologies that physicians and other HIPAA-covered entities and their business associates can use to render ePHI unusable, unreadable or indecipherable to unauthorized individuals. This is extremely technical guidance, and the AMA recommends physicians work with their software vendors to ensure their computers and electronic devices have acceptable encryption software loaded. The HIPAA Omnibus Rule published January 25, 2013, reaffirmed that encryption and destruction, consistent with NIST guidelines, would alleviate notification in the event of a breach. While HIPAA-covered entities and their business associates are not required to follow this guidance, if your practice does implement the specified technologies and methodologies, you will avoid having to comply with the extensive notification requirements otherwise required by the HITECH Act in the event of a security breach.
> 
> **• Encrypt any email that contains ePHI.**  
> If you currently correspond with patients, health insurers or other health care professionals via email and those emails contain ePHI, then you could be susceptible to a security breach. There are two basic approaches to encrypting email: PGP and S/MIME. PGP is a technology that was  
> pioneered by the PGP Corporation, and S/MIME is the email encryption capability that is built into Microsoft Outlook®. For other options, perform an Internet search on “email encryption software.”

---

<div class="post-metadata">

### Author: ![Really\_Not\_All\_That\_Bright](https://avatars.discourse-cdn.com/v4/letter/r/e8c25b/32.png) [@Really\_Not\_All\_That\_Bright](https://boards.straightdope.com/u/Really_Not_All_That_Bright)
#### Post date: [March 27, 2014, 1:30pm UTC](https://boards.straightdope.com/t/should-i-delete-my-work-email-account/684650/15 "2014-03-27T13:30:41Z")

</div>

Exactly. Encryption is _good practice_, not a requirement.

---

<div class="post-metadata">

### Author: ![Inner\_Stickler](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/inner_stickler/32/318_2.png) [@Inner\_Stickler](https://boards.straightdope.com/u/Inner_Stickler)
#### Post date: [March 27, 2014, 1:57pm UTC](https://boards.straightdope.com/t/should-i-delete-my-work-email-account/684650/16 "2014-03-27T13:57:31Z")

</div>

Encryption of data either at rest or in motion is listed as Addressable in the HIPAA Privacy rule. So, no, it’s not required but a covered entity is supposed to perform a risk assessment and if it’s reasonable and appropriate to implement the protocol, they are supposed to do so or implement an alternative protocol that is equivalent and if they choose not to implement the standard then they need to have their rationale for skipping it written down in case of an OCR audit.

---

<div class="post-metadata">

### Author: ![Really\_Not\_All\_That\_Bright](https://avatars.discourse-cdn.com/v4/letter/r/e8c25b/32.png) [@Really\_Not\_All\_That\_Bright](https://boards.straightdope.com/u/Really_Not_All_That_Bright)
#### Post date: [March 27, 2014, 2:08pm UTC](https://boards.straightdope.com/t/should-i-delete-my-work-email-account/684650/17 "2014-03-27T14:08:17Z")

</div>

Since the OP is deleting the account, it won’t be her problem anymore. In any event, while it contains “emails from patients” it doesn’t necessarily contain any PHI. It might just be appointment requests and such.

---

<div class="post-metadata">

### Author: ![Inner\_Stickler](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/inner_stickler/32/318_2.png) [@Inner\_Stickler](https://boards.straightdope.com/u/Inner_Stickler)
#### Post date: [March 27, 2014, 2:15pm UTC](https://boards.straightdope.com/t/should-i-delete-my-work-email-account/684650/18 "2014-03-27T14:15:03Z")

</div>

I make no claims as to what the OP should or should not do.

---

<div class="post-metadata">

### Author: ![Quercus](https://avatars.discourse-cdn.com/v4/letter/q/7ab992/32.png) [@Quercus](https://boards.straightdope.com/u/Quercus)
#### Post date: [March 27, 2014, 2:35pm UTC](https://boards.straightdope.com/t/should-i-delete-my-work-email-account/684650/19 "2014-03-27T14:35:03Z")

</div>

My advice – and I don’t know anything about HIPAA requirements – is to try and make sure your (now former) boss sets up a good e-mail account for the office (not his personal e-mail), forward all work-related e-mails from the old account to the new office e-mail, set up a new personal account for yourself and forward all personal e-mails to that account. Then delete all the work e-mails from the old mixed account, and set up an auto-reply from the old mixed account, saying “This e-mail account is no longer being read. If you want to contact \<Chiropracter\>, please e-mail \<new work account\>, if you want to contact **huitzilopochtli** , e-mail \<new personal account\>.”  
After six months or a year, delete the old account.

That’s my advice, anyway.

---

<div class="post-metadata">

### Author: ![Joey\_P](https://avatars.discourse-cdn.com/v4/letter/j/919ad9/32.png) [@Joey\_P](https://boards.straightdope.com/u/Joey_P)
#### Post date: [March 27, 2014, 2:55pm UTC](https://boards.straightdope.com/t/should-i-delete-my-work-email-account/684650/20 "2014-03-27T14:55:09Z")

</div>

> [@Quercus](#):
>
> My advice – and I don’t know anything about HIPAA requirements – is to try and make sure your (now former) boss sets up a good e-mail account for the office (not his personal e-mail), forward all work-related e-mails from the old account to the new office e-mail, set up a new personal account for yourself and forward all personal e-mails to that account. Then delete all the work e-mails from the old mixed account, and set up an auto-reply from the old mixed account, saying “This e-mail account is no longer being read. If you want to contact \<Chiropracter\>, please e-mail \<new work account\>, if you want to contact **huitzilopochtli** , e-mail \<new personal account\>.”  
> After six months or a year, delete the old account.
> 
> That’s my advice, anyway.

If you do that, I’d worry that patients will still email huitzilopochtli at the new personal email account. Besides, I wouldn’t want to give patients my personal email address. Personally, I’d just delete the account and new emails to it will bounce. Patients will be forced to find a new way to contact the office.

[Next page](https://boards.straightdope.com/t/should-i-delete-my-work-email-account/684650.md?page=2)
