VaultMailVaultMail
Risk & Compliance·6 min read

The cost of not encrypting: what one misdirected email really costs

The average breach now costs $4.88M, HIPAA fines start at $137 per record, and a single wrong recipient can trigger all of it. The math on skipping encryption has never been worse.

Padlock resting on a laptop keyboard lit in red and green

A standard email is a postcard. Every server it passes through — your provider’s, the recipient’s, whatever sits in between — can read it in full. Most days, nothing goes wrong. The problem is what happens on the day something does, because the receipts for unencrypted email are now very well documented.

The numbers, plainly

$4.88M
average cost of a data breach (IBM, Cost of a Data Breach)
$408
average cost per compromised healthcare record — the most expensive industry
60 days
maximum time to notify affected patients after a PHI breach

And that’s before the regulator arrives. HIPAA civil penalties are tiered by culpability, and they are assessed per record:

$137per record —unknowingTier 2reasonablecauseTier 3willful neglect,corrected$71,162per record — willfulneglect, uncorrectedCivil penalty tiers under 45 CFR § 160.404 — step height shows severity order, not scale
Illustrative — step heights show severity order, not dollar scale. Annual caps per violation category run to $1.5M+.

Tiered fines start at $137 per record for violations you didn’t even know about, and willful neglect that goes uncorrected tops out at $71,162 per record. A single misdirected email can contain a spreadsheet with thousands of records. Do that multiplication once and you never look at a “send” button the same way.

The breach is only the invoice’s first line

The fine is what people fear; the cascade is what actually hurts. A reportable PHI breach means notifying every affected patient in writing within 60 days, notifying HHS, and — past 500 records — landing on the Office for Civil Rights’ public breach portal, which the industry calls the “wall of shame.” Local press reads that portal. Patients read the local press. Clinics lose patients over trust, not over technology.

Encryption is the only line item on that invoice you get to cross out in advance.

The safe harbor most practices ignore

Here’s the part that should change behavior: under the HHS breach notification rule, properly encrypted PHI that leaks is not a reportable breach. If the data was unreadable — encrypted to NIST standards, keys held separately — the notification cascade never starts. No patient letters, no wall of shame, no press cycle. The regulation literally hands you an exit, and it costs less per seat than a lunch.

Do the math

VaultMail encrypts messages and attachments with AES-256-GCM, each under its own key, at $5 per seat per month — free for individual providers. Against a $137-per-record floor and a $4.88M average breach, “we’ll be careful” is not a strategy; it’s a deductible you haven’t priced.

One wrong recipient shouldn't cost seven figures.

Encrypt in one click inside Gmail and Outlook. Recall mis-sends before they're opened.

Add VaultMail to Chrome — free

Written by the VaultMail team · Published September 16, 2025