MDaemon Technologies Blog

Best Practices to Protect Email for Healthcare Organizations

By Brad Wyro

As long as healthcare organizations continue to use email, cybercriminals will find new ways to exploit security gaps, software bugs, and basic human nature to extort millions of dollars from their victims. The numbers bear this out. In 2025, 772 healthcare data breaches affecting 500 or more individuals were reported to the HHS Office for Civil Rights, exposing the protected health information of nearly 140 million people. Hacking and IT incidents accounted for the overwhelming majority of those breached records, and email accounts ranked as the second most common location of breached PHI, behind only network servers.

Security concept Lock on digital screen, illustration-1 (1)

 

So the question is: Is your healthcare organization doing everything possible to guarantee the security of your email systems? Compromised user accounts remain the entry point of choice. At the start of 2025, account compromise was the most prevalent threat facing healthcare organizations, affecting 74% of those running in cloud environments and 44% of those running on-premise. That’s why you need the additional protection offered by SecurityGateway for Email to protect against email-borne threats.

A quick note on the regulatory picture, because there’s been confusion about it: HHS proposed the most significant overhaul of the HIPAA Security Rule in more than 20 years in a Notice of Proposed Rulemaking published January 6, 2025. That rule would mandate encryption of ePHI in transit and at rest, require MFA, and remove the “addressable” designation from implementation specifications. It is still a proposed rule. OCR has not issued a final rule, and OMB has pushed final action out to July 2027. The current Security Rule remains in effect and OCR continues to enforce it. The recommendations below map to controls you should have in place regardless of how that rulemaking lands.

Here are our top 15 recommendations to protect your business from email-borne threats with Security Gateway 

 

 

SecurityGateway was designed to be easy to use while providing the strongest protection against spam, phishing and data leaks. While most security settings are configured for optimal protection by default, here are our top 15 recommendations to protect your healthcare facility from email-borne threats with SecurityGateway.

 

1. Verify That a User is Valid Before Creating an Account

With every incoming message addressed to an unknown local user, SecurityGateway needs to be able to verify that the account is a valid local user by querying Microsoft 365, Active Directory, MDaemon or another data source before creating the account and delivering the message. We recommend using one of the user verification sources found in SecurityGateway to validate accounts.

 

SecurityGateway for Email user verification source types including Microsoft 365, Active Directory, MDaemon, and LDAP

 

2. Use SMTP Authentication to Prevent Unauthorized Account Access

To help prevent unauthorized account access, we recommend requiring SMTP authentication unless a message is transmitted from a domain mail server.

 

SecurityGateway for Email SMTP Authentication settings requiring authentication for local accounts

 

3. Use Strong Passwords

Spammers will often try to hijack an email account by guessing its password. Therefore, passwords that are easy to guess should always be avoided. If SecurityGateway is configured to create accounts automatically by querying a user verification source, then make sure your user verification source is configured to require strong passwords. Passwords can also be assigned to users manually via the Domains and Users menu.

Tip: If you are using MDaemon as your mail server, a security feature will check all user passwords against a third-party list of compromised passwords that have appeared in a data breach. Better still, pair strong passwords with two-factor authentication - under the proposed Security Rule update, MFA on every system touching ePHI would move from best practice to requirement.

 

4. Enable Dynamic Screening

Dynamic Screening blocks connections that exhibit suspicious activity, such as failing too many authentication attempts, connecting too many times in a given time frame, attempting to keep a connection open too long, or sending to too many invalid recipients. Dynamic screening makes it more difficult for a malicious person to guess passwords by detecting the malicious activity and blocking the connections.

 

SecurityGateway for Email Dynamic Screening settings blocking IPs with suspicious connection behavior

 

5. Enable Account Hijack Detection

If a spammer guesses an account’s password, they can then use that account to send out spam. To limit the spammer’s ability to abuse a compromised account, enable account hijack detection and then enter the maximum number of messages that can be sent in a given time frame. Once the limit has been reached, the account is disabled and the administrator is notified.

Given that account compromise is now the leading threat to healthcare organizations, this is one of the highest-value settings on this list.

 

SecurityGateway for Email Account Hijack Detection settings limiting outbound messages per time window

 

6. Enable at Least One Default Mail Server

When email arrives for a domain that has not been assigned its own mail server, SecurityGateway needs to know where to send those messages. We recommend adding a default mail server for all SecurityGateway domains that have not had domain mail servers specifically associated with them.

 

SecurityGateway for Email New Mail Server dialog showing hostname, port, and authentication fields

 

7. Prevent Unauthorized Mail Relaying

Relaying occurs when mail that is neither to nor from a local account is sent through your server. Servers that are not properly configured to prevent relaying can end up on a blocklist. By default, SecurityGateway does not allow mail relaying.

 

SecurityGateway for Email Relay Control settings preventing unauthorized mail relaying

 

8. Protect Your Domain with IP Shielding

IP Shielding is a security feature that only honors SMTP sessions claiming to be from someone at one of the listed domains if they are coming from an IP address associated with that domain.

The best way to secure outbound email is via SMTP authentication. However, for businesses that need to send email from a printer or other device that is not capable of authenticating, IP Shielding can be used to exclude certain IPs or ranges from having to authenticate. Messages from authenticated sessions can optionally be exempt from IP shielding requirements.

 

SecurityGateway for Email IP Shielding settings with domain and IP pair configuration

 

9. Enable SSL to Ensure Data Privacy

To protect the privacy of transmitted data, we recommend enabling the SSL/TLS encryption features for SMTP and HTTP. For healthcare organizations, encryption in transit is not optional, and the proposed Security Rule update would make it explicitly mandatory rather than “addressable.”

 

SecurityGateway for Email encryption settings enabling SSL, STARTTLS, REQUIRETLS, and MTA-STS

 

10. Enable Backscatter Protection

Most spam messages contain a forged return path. This often leads to users receiving thousands of delivery status notices, auto-responders and other messages in response to messages that the user never sent. This is known as backscatter. To combat it, SecurityGateway’s Backscatter Protection feature can help to ensure that only legitimate Delivery Status Notifications and auto-responders get delivered to your domains.

 

SecurityGateway for Email Backscatter Protection settings rejecting messages with forged return paths

 

11. Don’t Alowlist Local Email Addresses

In many cases, local IP addresses or host names may need to be added to an allowlist. However, we do not recommend allowlisting local email addresses. If a local address is added to the allowlist, messages sent to this address could bypass many of your security settings and put your server at risk of being blocklisted.

 

12. Protect Your Email Infrastructure from Virus and Spam Outbreaks

SecurityGateway scans all inbound and outbound mail using two antivirus engines: ClamAV and IKARUS Anti-Virus. IKARUS combines traditional antivirus defense methods with proactive detection technologies and updates its definitions automatically every 10 minutes.

SecurityGateway also includes Outbreak Protection, which uses Recurrent Pattern Detection to identify new outbreaks based on distribution patterns rather than signatures, catching new malware and variants within minutes of an outbreak, before conventional signatures exist.

Note for businesses running an older version. Cyren, the previous antivirus and Outbreak Protection provider, ceased operations in February 2023. MDaemon Technologies replaced the engine with IKARUS in SecurityGateway 9.0.2, and Outbreak Protection was later re-licensed from a new provider and re-integrated. If you are on a version still using Cyren, those definitions are no longer updating and you are effectively running with one engine. Check the critical updates page at mdaemon.com/pages/downloads-critical-updates and upgrade. If you previously disabled Cyren AV manually, confirm that IKARUS is enabled after upgrading; it does not always switch on by itself.

 

SecurityGateway for Email Virus Scanning settings with ClamAV and IKARUS Anti-Virus engines enabled

 

13. Prevent Data Leaks

SecurityGateway includes a large set of built-in Data Leak Prevention rules to help prevent unauthorized transmission of sensitive information such as personal identification numbers, credit card numbers and other types of confidential data. These rules can be configured to send messages containing sensitive content to the administrative quarantine for further review, redirect the message to a designated address, or encrypt the message.

For healthcare organizations, this is your last line of defense against an accidental PHI disclosure walking out the door in an outbound message. We recommend enabling the appropriate Data Leak Prevention rules to suit the needs of your specific organization, and customizing them via the Edit button where the defaults don’t fit your workflows.


SecurityGateway for Email Data Leak Prevention rules list including credit card, SSN, and passport number detection

 

14. Enable Location Screening

Use Location Screening to block inbound SMTP and HTTP connections from unauthorized countries. If your organization has no legitimate business need to communicate with a particular country, then refusing connections from that country can potentially block large amounts of spam. Alternatively, you can configure Location Screening to only prevent authentication from unauthorized countries - a useful middle ground for a clinic that still needs to receive mail broadly but should never see a login from outside its own region.

 

SecurityGateway for Email Location Screening settings blocking SMTP and HTTP connections by country

 

15. Enable Macro Detection in Microsoft Office Documents

Cybercriminals often use macros in email attachments to spread malware. SecurityGateway’s virus scanning settings include an option to detect macros in Microsoft Office documents and flag them as infected. SecurityGateway can refuse these messages or quarantine them for administrative review.

SecurityGateway for Email virus scanning option to flag Office document attachments containing macros

Download-the-_Settings-to-Protect-your-Mail-Server_-How-to-Guide

Would you like to learn more about how SecurityGateway for Email can help protect your healthcare facility and its data? Visit https://mdaemon.com/pages/security-gateway to sign up for hosted or on-premise email protection.

Tags: Email Gateway How-To, Email Privacy, Health Care Security

Brad Wyro

Written by Brad Wyro

Brad has worked in technical and marketing roles at MDaemon Technologies, where he contributes as Content Marketing Manager. Brad balances technical and creative information to develop easy to understand videos and content to educate prospects and customers.

BACK TO ALL ARTICLES

Subscribe to Email Updates