---
title: The Yahoo Email Breach and Healthcare
description: If you used Yahoo email to transmit PHI or PII, you could be at risk for HIPAA non-compliance. Read on for what to do.
image: https://www.ais-now.com/hubfs/Images/secutiry-breach.jpg
---

[Skip to main content](https://www.ais-now.com/blog/the-yahoo-email-breach-and-healthcare#maincontent)

[«  View All Posts](https://www.ais-now.com/learning-center)

# The Yahoo Email Breach and Healthcare

 November 7th, 2016 | 4 min. read

By [Monique Phalen](https://www.ais-now.com/blog/author/monique-phalen)

![secutiry-breach.jpg](https://www.ais-now.com/hubfs/Images/secutiry-breach.jpg)

![If you used Yahoo email to transmit PHI or PII, you could be at risk for HIPAA non-compliance. Read on for what to do.](https://www.ais-now.com/hs-fs/hubfs/Images/secutiry-breach.jpg?width=818&height=646&name=secutiry-breach.jpg)

In late September, Yahoo admitted that it's security failed and hackers, possibly sponsored by a foreign government, stole the credentials of 500 million users. This happened in 2014 and was undetected until just before the announcement. 

If you're reading this as the owner or CIO of a business, use Yahoo email for business, and are required to be compliant with one or more laws, you should investigate if the breach has any compliance implications for you. 

Also, go reset your password – now. The passwords that were stolen were encrypted and Yahoo believes the risk is low. Still, there is risk. Reset. If your Flickr account is linked to a Yahoo ID, you probably should change that password too – just to be safe.

If you've used Yahoo email to send protected health information (PHI), you could be in breach of HIPAA.

**Email and HIPAA**

There are three things to know about email and HIPAA relative to this Yahoo news.

1. You can't send PHI via email without encryption. Unencrypted email is like a postcard – anyone can read it. Encrypted information has been placed in an envelope.
2. Free versions of Gmail, Yahoo email, AOL, and Dropbox (for sharing information) are NOT HIPAA compliant. The way these services store metadata could leave PHI exposed and is a violation.
3. Don't share accounts or passwords for sending PHI. Anyone who sends PHI must do so from their own user account. Sharing accounts and passwords breaks chain of custody for PHI and is a HIPAA violation.

If you've used any of these services to send PHI (or if you aren't a healthcare provider, used any of these free services to send personally identifiable information):

1. Stop and begin the process of moving your email communications to a service that will encrypt communications.
2. If you are a HIPAA-covered entity, you need to investigate and then contact any of your patients who could have been exposed. You've got 60 days from the date of Yahoo's announcement to do so – so move fast!

**Quick Security Reminders**

Are there any other things you can do to protect yourself? Absolutely, I'll quickly go over four here: look into alerts and authentication, update, change passwords, and restrict access.

1. ** Alerts and Authentication**

Set up login verification for text message alerts when someone (even you) try to access your email account from a new or unrecognized device. Yahoo also has Account Key, Google has Google Authenticator, and Duo Security has Duo Mobile; all add a level of log-in security.

1. ** Update**

This is the easiest way for you to ensure your systems are protected. Software and operating system manufacturers are constantly making data security improvements and releasing them in the form of security patches. Make sure to sign up for automatic software and [anti-virus updates](https://www.ais-now.com/blog/anti-virus-software-the-first-security-layer-against-hackers) as non-updated operating systems and software are easy targets for hackers. You may also want to install and regularly update software to detect spyware.

1. ** Change passwords**

ALWAYS change the passwords on new hardware and software in your business. Default passwords and account names are easy targets for hackers if default settings aren't changed.

Users reuse passwords across online services. That's why stolen account credentials can be a goldmine for cybercriminals. Do you use the same password for your bank as for your credit card(s)? Is that the same password you use for work – say to log in to your CRM system? 

Use different passwords. Change them frequently. And use a combination of numbers, letters, and symbols (even if that's hard to type!). And don't write your passwords on a Post-it note and leave that on your desk or stuck on your monitor screen. 

You should also consider using a password manager application – which can generate long, random passwords; store them in an encrypted database; and enter them into the appropriate applications after a user enters a single master password.

1. ** Restrict Access**

Try to limit employee access of sensitive information to essential personnel only. If you have employees who need remote access to your company computer system consider requiring a second, regularly changed password in addition to the original log-in information. You may also want to install software to monitor unusual activity on your system or that can monitor outbound communication to ensure private data is not being leaked and boost computer security.

Copiers, such as those used in healthcare and financial services industries, should also have restricted physical access to them when possible. Additional levels of security such as HID cards and biometrics can add additional layers of security to keep confidential information from general view. And be sure to have secure authentication protocols in place if you allow your copiers to scan to email – particularly in regulated industries.

[![Check out these 14 must know tips for backing up your data - Free Download >>](https://no-cache.hubspot.com/cta/default/2151016/4d40d69f-b85c-42dc-88fc-11e73215bc48.png)](https://cta-redirect.hubspot.com/cta/redirect/2151016/4d40d69f-b85c-42dc-88fc-11e73215bc48)

More on the Yahoo data breach:  
[http://www.nytimes.com/2016/09/29/technology/yahoo-data-breach-hacking.html](http://www.nytimes.com/2016/09/29/technology/yahoo-data-breach-hacking.html)**<http://www.nytimes.com/2016/09/29/technology/yahoo-data-breach-hacking.html>**[https://gma.yahoo.com/consumers-know-yahoo-security-breach-234046917--abc-news-topstories.html](https://gma.yahoo.com/consumers-know-yahoo-security-breach-234046917--abc-news-topstories.html)

<https://www.ais-now.com/blog/author/monique-phalen>

[ Monique Phalen ](https://www.ais-now.com/blog/author/monique-phalen)

Mo is the resident IT go-to lady at AIS. She has traveled the world, run a marathon, is a self-proclaimed crossword champion, and can do ventriloquism. She has an uncanny memory ....down to the detail. She has completed 4 half marathons and hates running. In her free time, she likes to spend time with her 7 siblings and 20 nieces and nephews.

 Connect: 

<https://www.linkedin.com/in/moniquephalen> <https://twitter.com/mophalen> [mailto:mphalen@ais-now.com](mailto:mphalen@ais-now.com)

 Topics:

[ IT Services ](https://www.ais-now.com/blog/topic/it-services)

[ Copiers & Printers ](https://www.ais-now.com/blog/topic/copiers-printers)

 Don't forget to share this post:

<https://www.facebook.com/sharer/sharer.php?u=https://www.ais-now.com/blog/the-yahoo-email-breach-and-healthcare> <https://www.linkedin.com/shareArticle?url=https://www.ais-now.com/blog/the-yahoo-email-breach-and-healthcare&title=The+Yahoo+Email+Breach+and+Healthcare&summary=If+you+used+Yahoo+email+to+transmit+PHI+or+PII%2C+you+could+be+at+risk+for+HIPAA+non-compliance.+Read+on+for+what+to+do.> <https://twitter.com/intent/tweet?text=The+Yahoo+Email+Breach+and+Healthcare&url=https://www.ais-now.com/blog/the-yahoo-email-breach-and-healthcare> <https://pinterest.com/pin/create/button/?url=https://www.ais-now.com/blog/the-yahoo-email-breach-and-healthcare&media=http://cdn2.hubspot.net/hubfs/2151016/Images/secutiry-breach.jpg&description=If+you+used+Yahoo+email+to+transmit+PHI+or+PII%2C+you+could+be+at+risk+for+HIPAA+non-compliance.+Read+on+for+what+to+do.>

## Related Articles

[### Why Small IT Problems Turn Into Big Business Problems | TMH Episode 5

 June 4th, 2026|2 min read 

](https://www.ais-now.com/blog/why-small-it-problems-turn-into-big-business-problems-tmh-episode-5)

[### What Are The Top 3 Video Surveillance Brands For My Business?

 May 28th, 2026|4 min read 

](https://www.ais-now.com/blog/top-video-surveillance-brands-business)

[### Cyber Security: What Is Malware And How To Avoid It?

 May 28th, 2026|5 min read 

](https://www.ais-now.com/blog/cyber-security-what-is-malware-and-how-to-avoid-it)

[### Managed IT Services: The Key to a Successful IT Roadmap

 May 27th, 2026|5 min read 

](https://www.ais-now.com/blog/managed-it-services-the-key-to-a-successful-it-roadmap)

[### Managed IT Cost Explained: What SMBs Are Actually Paying For

 May 12th, 2026|2 min read 

](https://www.ais-now.com/blog/managed-it-cost-explained-what-smbs-are-actually-paying-for)

[### 5 IT Headaches Managed Services Can Cure

 April 30th, 2026|5 min read 

](https://www.ais-now.com/blog/5-it-headaches-managed-services-solve)

[### How Can A Business Security Camera System Protect My Business?

 April 30th, 2026|4 min read 

](https://www.ais-now.com/blog/how-can-a-business-security-camera-system-protect-my-business)

[### Cybersecurity And The Workplace: Keep Your Office Copiers and Printers Secure

 April 30th, 2026|5 min read 

](https://www.ais-now.com/blog/cybersecurity-office-copiers-printers-secure)

[### How To Avoid the Most Common Phishing Scams

 April 29th, 2026|5 min read 

](https://www.ais-now.com/blog/avoid-most-common-phishing-scams)

[### Top 7 Reasons Managed IT Services Improve Your Business & Work Days

 April 29th, 2026|4 min read 

](https://www.ais-now.com/blog/the-joy-of-outsourcing-managed-it-services-will-improve-your-business-and-your-work-days)

[### How To Save Money with Managed IT Services

 April 28th, 2026|6 min read 

](https://www.ais-now.com/blog/how-to-save-money-managed-it-services)

[### Security Compliance: How A Managed IT Services Provider Keeps Your Business Safe

 April 28th, 2026|5 min read 

](https://www.ais-now.com/blog/security-compliance-business-safe-managed-it-services-provider)

[### Security Moves SMBs Can Do Now | Tech Made Human Episode 3

 April 3rd, 2026|1 min read 

](https://www.ais-now.com/blog/security-moves-smbs-can-do-now-tech-made-human-episode-3)

[### Why Internal IT Teams Burn Out (And How to Fix It)

 March 26th, 2026|6 min read 

](https://www.ais-now.com/blog/why-internal-it-teams-burn-out-how-to-fix-it)

[### Cyber Insurance Requirements: What Your IT Must Include

 March 26th, 2026|7 min read 

](https://www.ais-now.com/blog/cyber-insurance-requirements-what-your-it-must-include)

[### The Cost of Doing Nothing: Delaying IT Upgrades Explained

 March 26th, 2026|6 min read 

](https://www.ais-now.com/blog/cost-of-doing-nothing-delaying-it-upgrades-explained)

[### The Danger of “Set It and Forget It” IT Support

 March 24th, 2026|4 min read 

](https://www.ais-now.com/blog/danger-of-set-it-and-forget-it-it-support)

[### Why Most IT Assessments Miss Critical Risks

 March 24th, 2026|4 min read 

](https://www.ais-now.com/blog/why-most-it-assessments-miss-critical-risks)

[### What Questions Smart Buyers Ask Before Choosing an Office Technology Provider?

 March 23rd, 2026|5 min read 

](https://www.ais-now.com/blog/what-questions-smart-buyers-ask-before-choosing-an-office-technology-provider)

[### IT Support for Law Firms: What Makes It Different?

 March 23rd, 2026|4 min read 

](https://www.ais-now.com/blog/it-support-law-firms-what-makes-it-different)

[### How to Evaluate an IT Provider’s Cybersecurity Stack

 March 23rd, 2026|4 min read 

](https://www.ais-now.com/blog/how-to-evaluate-it-provider-cyber-security-stack)

[### How Much Should Managed IT Cost for a 20, 50, or 100 Employee Company?

 March 18th, 2026|8 min read 

](https://www.ais-now.com/blog/how-much-managed-it-cost-for-20-50-100-employee-company)

[### The Connection Between IT Strategy and Business KPIs

 February 18th, 2026|5 min read 

](https://www.ais-now.com/blog/connection-between-it-strategy-and-business-kpi)

[### Evaluating IT Infrastructure Maturity: A Step-by-Step Guide

 February 18th, 2026|4 min read 

](https://www.ais-now.com/blog/evaluating-it-infrastructure-maturity-step-by-step-guide)

[### Office Technology for Your Business: What to Replace First... Phones, IT, or Copiers?

 February 12th, 2026|5 min read 

](https://www.ais-now.com/blog/office-technology-business-what-to-replace-first-phones-it-copiers)