▾ G11 Media Network: | ChannelCity | ImpresaCity | SecurityOpenLab | Italian Channel Awards | Italian Project Awards | Italian Security Awards | ...
InnovationOpenLab

Healthcare Email Is Being Delivered to Unverified Servers, New Paubox Data Shows

#cyberattacks--An estimated 3 million email addresses may be at risk of exposure to common cyberattacks, such as man-in-the-middle attacks, because email delivery often proceeds even when certificate ...

Immagine

SAN FRANCISCO: #cyberattacks--An estimated 3 million email addresses may be at risk of exposure to common cyberattacks, such as man-in-the-middle attacks, because email delivery often proceeds even when certificate validation fails. New research from Paubox found that encrypted email is routinely sent to servers with expired or self-signed certificates, preventing reliable verification of the recipient’s identity.

In an analysis of outbound healthcare email traffic, Paubox found that approximately 4.5% of connections were delivered to servers with expired or self-signed certificates. The analysis examined 784,961 unique email outbound email traffic relays used by the healthcare sector.

Transport Layer Security (TLS) is widely relied on to encrypt email in transit. However, TLS depends on digital certificates to establish trust between sending and receiving servers. When certificates are expired or self-signed, encryption may still occur, but the integrity of the connection cannot be proven.

Paubox found that cloud email platforms frequently deliver messages even when certificate validation fails, prioritizing delivery over verification. As a result, sensitive healthcare communications may travel through untrusted paths without triggering alerts or errors for senders.

The issue is compounded by healthcare’s complex vendor ecosystem. Clinics, hospitals, billing companies, imaging services, and managed service providers routinely exchange email containing protected health information (PHI), often using aging or misconfigured infrastructure. According to Paubox’s mid-year breach data, 16% of email-related healthcare breaches in 2025 involved business associates.

“HIPAA doesn’t spell out ‘no self-signed certs’,” the report notes, “but the Security Rule requires organizations to verify the integrity of the connection.”

Paubox’s report outlines how its outbound encryption technology addresses this gap by enforcing certificate validation and automatically switching to secure delivery when certificate trust cannot be established. Unlike traditional TLS-only approaches, this model removes reliance on the recipient’s infrastructure behaving correctly.

The full report, Healthcare’s email security certificate crisis, details the data behind the findings, explains how TLS and certificates work in plain language, and outlines why expired and self-signed certificates pose a growing compliance risk for healthcare organizations.

The report is available at: https://hubs.la/Q03ZRGnG0

About Paubox

Paubox is a leader in HIPAA compliant communication and marketing solutions for healthcare organizations. According to G2 rankings, Paubox leads the industry for Best Secure Email Gateway, Email Security, HIPAA Compliant Messaging Software, and Email Encryption solution, and is the only HIPAA compliant email company listed on G2's 2025 Best Healthcare Software Products. Paubox solutions include Paubox Email Suite, Paubox Marketing, Paubox Email API, and Paubox Forms. Launched in 2015, Paubox is trusted by over 8,000 healthcare organizations, including AdaptHealth, Cost Plus Drugs, and Covenant Health.

Fonte: Business Wire

If you liked this article and want to stay up to date with news from InnovationOpenLab.com subscribe to ours Free newsletter.

Related news

Last News

RSA at Cybertech Europe 2024

Alaa Abdul Nabi, Vice President, Sales International at RSA presents the innovations the vendor brings to Cybertech as part of a passwordless vision for…

Italian Security Awards 2024: G11 Media honours the best of Italian cybersecurity

G11 Media's SecurityOpenLab magazine rewards excellence in cybersecurity: the best vendors based on user votes

How Austria is making its AI ecosystem grow

Always keeping an European perspective, Austria has developed a thriving AI ecosystem that now can attract talents and companies from other countries

Sparkle and Telsy test Quantum Key Distribution in practice

Successfully completing a Proof of Concept implementation in Athens, the two Italian companies prove that QKD can be easily implemented also in pre-existing…

Most read

Informatica Named a Leader in 2026 Gartner® Magic Quadrant™ for Data &…

Informatica from Salesforce, a leader in enterprise AI-powered cloud data management, today announced it has been named a Leader in the Gartner® Magic…

Omdia: Global PC Shipments Grew 9% in 2025 but Memory and Storage Supply…

#DRAM--The latest research from Omdia reveals that total shipments of desktops, notebooks and workstations in Q4 2025 grew 10.1% to 75 million units.…

BCG and Hippocratic AI Announce Strategic Collaboration to Deploy Agentic…

#GenAI--Boston Consulting Group (BCG) and Hippocratic AI today announced a global collaboration aimed at transforming the biopharma and medtech industries…

Triumph Announces Schedule for Fourth Quarter 2025 Earnings Release and…

Triumph Financial, Inc. (NYSE: TFIN) today announced that it expects to release its fourth quarter financial results and management commentary after the…

Newsletter signup

Join our mailing list to get weekly updates delivered to your inbox.

Sign me up!