I searched for email and found only this thread - not wanting to duplicate something discussed before. I have a patient who wants to communicate by email. I don't want to go to the hassle of signing up for some encryption service. If I have them sign a form requesting this form of communication, understanding it is not encrypted, should that be sufficient? Anyone else doing this?
I'm no expert by any stretch , but have asked this question of an "expert". There is no downside for the patient SENDING you PHI, but if you send it back using unsecure methods, even if he or she has said it is OK, you could be at risk, if your account got hacked or the email intercepted. Big if, but big exposure if it happened.
Having said that I have sent some what watered down responses (e.g. you renal function is unchanged).