[mh_key_takeaways]
Encryption is a checkbox item on most email security procurement forms. It sits next to inbound filtering, DLP, archiving, and identity controls. Buyers who focus on one checkbox at a time miss how the layers depend on each other.
This guide covers how encryption and email security fit together in a working stack. Where a healthcare team needs the outbound layer without integrating four vendors, a dedicated secure email service with a BAA in the base plan often solves the immediate compliance gap.
Read the sections in order. Each layer covers a different threat and a different auditor concern.
The Email Security Stack Has Five Layers
A complete email security posture combines five functional layers. Each addresses a different risk.
- Inbound filtering removes phishing, malware, and business email compromise before delivery.
- Identity controls including MFA and conditional access stop credential theft at the mailbox.
- DLP scans outbound messages for sensitive content and enforces policy actions.
- Outbound encryption protects message content in transit and at rest for regulated data.
- Archiving preserves all inbound and outbound mail in tamper-evident storage for compliance.
Skipping any layer creates a gap. Filtering without encryption leaves outbound leakage. Encryption without filtering leaves the inbox exposed to the phishing that steals the credentials that bypass the encryption.
Buyers evaluating a single feature should confirm what covers the other four.

Encryption Handles Outbound Confidentiality
Email encryption operates on outbound messages. It transforms the body and attachments into ciphertext readable only by the intended recipient.
TLS handles server-to-server transport encryption. S/MIME or hosted portal services handle content encryption end to end. Both layers combine to protect messages from interception and unauthorized access.
Related guide: email encryption covers the methods and standards in depth. See also encryption for email and files.
Encryption does not protect against outbound errors. A workforce member emailing PHI to the wrong recipient still commits a HIPAA breach even when the message is encrypted correctly to that wrong address.
The DLP layer catches that case. Encryption alone does not.
Inbound Filtering Blocks Threats Before Delivery
Inbound filtering scans every incoming message against spam signatures, malware analysis, URL reputation, and behavioral indicators of business email compromise.
Microsoft Defender for Office 365 and Google Workspace Security Sandbox both bundle inbound filtering with their mail platforms. Third-party vendors like Proofpoint, Mimecast, and Barracuda offer specialized inbound protection.
Filtering catches most commodity threats. Sophisticated targeted attacks still get through occasionally. That is why the layer above it, identity controls, matters.
The CISA guidance on phishing and ransomware covers the current threat landscape that inbound filtering has to handle.
Healthcare senders face specific targeting because PHI has direct resale value. Filtering configuration for healthcare typically runs stricter than for general business.
[mh_example]
DLP Enforces Policy on Sensitive Content
Data loss prevention scans outbound content for defined patterns and enforces automatic policy actions.
Common patterns include Social Security numbers, credit card numbers, medical record numbers, ICD-10 codes, and custom keyword lists specific to the organization.
Policy actions include block and notify the sender, quarantine for admin review, redirect to a manager, or apply encryption automatically. That last option closes the gap between manual encryption decisions and consistent compliance.
Microsoft Purview DLP and Google Workspace Data Loss Prevention both include predefined content types. Custom rules cover organization-specific patterns.
Test DLP rules against a monitored test mailbox before pushing to production. False positives on internal messages create friction that pushes users toward personal accounts.

VPNs Add a Network Layer That Overlaps Partially
A VPN encrypts the network path between a client device and the VPN provider. It matters when workforce members send email from public Wi-Fi or shared networks.
The VPN protects the traffic from the coffee shop to the VPN endpoint. From there, the traffic exits to the mail server as normal internet traffic protected by the mail platform TLS.
Once the message leaves the sender mail server and travels to the recipient mail server, the VPN provides no protection. The message needs TLS between the mail servers and content encryption for the body itself.
A VPN is not a substitute for email encryption. It protects the first mile only. HIPAA-regulated content still requires end-to-end encryption on the message itself.
Practices deploying VPNs should still deploy email encryption. The layers cover different segments of the message journey.
Archiving Preserves Compliance Evidence
Archiving captures every inbound and outbound message at the gateway and stores it in tamper-evident form for defined retention periods.
HIPAA calls for six-year retention of documentation supporting security policies, which includes evidence of PHI communications. SOX requires seven years of financial records. FINRA requires three years of broker communications with clients.
The archive protects against message tampering after delivery, which matters during litigation and audit. Users cannot delete archived copies from their mailbox to hide activity.
Some vendors bundle archiving with encryption in one product. Others sell them separately. Buyers should confirm which vendor covers each function to avoid gaps or duplicate contracts.
The archive itself must also be encrypted at rest. Vendors typically use AES-256 with keys managed by the customer or the vendor per contract.
[mh_protip]
Identity Controls Guard the Mailbox Access Point
Encryption and filtering both fail when an attacker holds the legitimate mailbox credentials. Identity controls prevent that scenario.
Multi-factor authentication blocks most credential theft attacks. Conditional access rules restrict logins to known devices, networks, or geographies. Session timeout controls limit exposure when devices are left unattended.
Microsoft Entra ID and Google Workspace identity both include MFA and conditional access as core features. Enforce MFA for every workforce member with mailbox access.
Compromised mailbox credentials are the entry point for most business email compromise attacks. See the Microsoft business email compromise guidance for attack patterns and defenses.
Identity controls are cheap compared to the breach cost they prevent. Deploy them before adding more expensive encryption or filtering products.
HIPAA Requires the Full Stack for Covered Entities
HIPAA covered entities need every layer of the stack for the Security Rule and Privacy Rule requirements.
Encryption meets the transmission security safeguard. Inbound filtering supports the malicious software safeguard. DLP supports the administrative safeguard against workforce error. Archiving supports the six-year documentation retention requirement.
Each vendor that touches PHI signs a business associate agreement. Consolidated platforms simplify BAA management by putting encryption, filtering, and archiving under one contract. Specialized services require separate BAAs.
The HHS Security Rule guidance lists every safeguard the covered entity must implement.
Practices running patient-facing websites face parallel obligations. See healthcare website security features for the site-side controls that pair with the email stack.
Choosing Between Consolidated and Best-of-Breed Vendors
Buyers face a decision between one platform that covers every layer and multiple specialized vendors that each cover one layer well.
Consolidated platforms from Microsoft, Google, or major security vendors deliver encryption, filtering, DLP, and archiving through one console. Reporting is unified. One contract covers everything. Small practices favor this model for administrative simplicity.
Specialized vendors focus on one layer and often deliver a better recipient experience or specific compliance feature. Larger organizations mix a consolidated inbound filter with a specialized outbound encryption service like Mailhippo that delivers encrypted email without portal friction.
Related guides: email encryption solutions comparison, email encryption solutions for Outlook and Gmail, and HIPAA compliant texting and email.
Match the vendor mix to the operational team size. A one-person IT department cannot maintain four separate consoles. A dedicated security team can extract value from specialized products that a consolidated platform cannot match.
Neither approach is wrong. The wrong choice is buying encryption in isolation and ignoring the other four layers.
[mh_faqs]

















