The cost of not encrypting: what one misdirected email really costs
The average breach now costs $4.88M, HIPAA fines start at $137 per record, and a single wrong recipient can trigger all of it. The math on skipping encryption has never been worse.

A standard email is a postcard. Every server it passes through — your provider’s, the recipient’s, whatever sits in between — can read it in full. Most days, nothing goes wrong. The problem is what happens on the day something does, because the receipts for unencrypted email are now very well documented.
The numbers, plainly
And that’s before the regulator arrives. HIPAA civil penalties are tiered by culpability, and they are assessed per record:
Tiered fines start at $137 per record for violations you didn’t even know about, and willful neglect that goes uncorrected tops out at $71,162 per record. A single misdirected email can contain a spreadsheet with thousands of records. Do that multiplication once and you never look at a “send” button the same way.
The breach is only the invoice’s first line
The fine is what people fear; the cascade is what actually hurts. A reportable PHI breach means notifying every affected patient in writing within 60 days, notifying HHS, and — past 500 records — landing on the Office for Civil Rights’ public breach portal, which the industry calls the “wall of shame.” Local press reads that portal. Patients read the local press. Clinics lose patients over trust, not over technology.
Encryption is the only line item on that invoice you get to cross out in advance.
The safe harbor most practices ignore
Here’s the part that should change behavior: under the HHS breach notification rule, properly encrypted PHI that leaks is not a reportable breach. If the data was unreadable — encrypted to NIST standards, keys held separately — the notification cascade never starts. No patient letters, no wall of shame, no press cycle. The regulation literally hands you an exit, and it costs less per seat than a lunch.
Do the math
VaultMail encrypts messages and attachments with AES-256-GCM, each under its own key, at $5 per seat per month — free for individual providers. Against a $137-per-record floor and a $4.88M average breach, “we’ll be careful” is not a strategy; it’s a deductible you haven’t priced.
One wrong recipient shouldn't cost seven figures.
Encrypt in one click inside Gmail and Outlook. Recall mis-sends before they're opened.
Add VaultMail to Chrome — freeWritten by the VaultMail team · Published September 16, 2025