11 May 2026 · 14 min read
Email authentication for healthcare and HIPAA
HIPAA never names DMARC, but it asks for exactly what SPF, DKIM and DMARC deliver: protection of transmitted PHI, integrity, sender authentication and ongoing risk management. Here is how email authentication maps onto the HIPAA Security Rule, why DMARC reporting need not expose PHI, and the staged path to p=reject that does not break clinical email.
Read more arrow_forward