SAN FRANCISCO–(BUSINESS WIRE)–#cyberattacks–An estimated 3 million email addresses may be at risk of exposure to common cyberattacks, such as man-in-the-middle SAN FRANCISCO–(BUSINESS WIRE)–#cyberattacks–An estimated 3 million email addresses may be at risk of exposure to common cyberattacks, such as man-in-the-middle

Healthcare Email Is Being Delivered to Unverified Servers, New Paubox Data Shows

SAN FRANCISCO–(BUSINESS WIRE)–#cyberattacks–An estimated 3 million email addresses may be at risk of exposure to common cyberattacks, such as man-in-the-middle attacks, because email delivery often proceeds even when certificate validation fails. New research from Paubox found that encrypted email is routinely sent to servers with expired or self-signed certificates, preventing reliable verification of the recipient’s identity.

In an analysis of outbound healthcare email traffic, Paubox found that approximately 4.5% of connections were delivered to servers with expired or self-signed certificates. The analysis examined 784,961 unique email outbound email traffic relays used by the healthcare sector.

Transport Layer Security (TLS) is widely relied on to encrypt email in transit. However, TLS depends on digital certificates to establish trust between sending and receiving servers. When certificates are expired or self-signed, encryption may still occur, but the integrity of the connection cannot be proven.

Paubox found that cloud email platforms frequently deliver messages even when certificate validation fails, prioritizing delivery over verification. As a result, sensitive healthcare communications may travel through untrusted paths without triggering alerts or errors for senders.

The issue is compounded by healthcare’s complex vendor ecosystem. Clinics, hospitals, billing companies, imaging services, and managed service providers routinely exchange email containing protected health information (PHI), often using aging or misconfigured infrastructure. According to Paubox’s mid-year breach data, 16% of email-related healthcare breaches in 2025 involved business associates.

“HIPAA doesn’t spell out ‘no self-signed certs’,” the report notes, “but the Security Rule requires organizations to verify the integrity of the connection.”

Paubox’s report outlines how its outbound encryption technology addresses this gap by enforcing certificate validation and automatically switching to secure delivery when certificate trust cannot be established. Unlike traditional TLS-only approaches, this model removes reliance on the recipient’s infrastructure behaving correctly.

The full report, Healthcare’s email security certificate crisis, details the data behind the findings, explains how TLS and certificates work in plain language, and outlines why expired and self-signed certificates pose a growing compliance risk for healthcare organizations.

The report is available at: https://hubs.la/Q03ZRGnG0

About Paubox

Paubox is a leader in HIPAA compliant communication and marketing solutions for healthcare organizations. According to G2 rankings, Paubox leads the industry for Best Secure Email Gateway, Email Security, HIPAA Compliant Messaging Software, and Email Encryption solution, and is the only HIPAA compliant email company listed on G2’s 2025 Best Healthcare Software Products. Paubox solutions include Paubox Email Suite, Paubox Marketing, Paubox Email API, and Paubox Forms. Launched in 2015, Paubox is trusted by over 8,000 healthcare organizations, including AdaptHealth, Cost Plus Drugs, and Covenant Health.

Contacts

Media Contact:

Dawn Halpin

press@paubox.com

Market Opportunity
MAY Logo
MAY Price(MAY)
$0.01399
$0.01399$0.01399
-0.85%
USD
MAY (MAY) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

NVIDIA Blackwell Enhances AI Inference with Superior Performance Gains

NVIDIA Blackwell Enhances AI Inference with Superior Performance Gains

The post NVIDIA Blackwell Enhances AI Inference with Superior Performance Gains appeared on BitcoinEthereumNews.com. Felix Pinkston Jan 08, 2026 09:09 NVIDIA
Share
BitcoinEthereumNews2026/01/09 04:43
IP Hits $11.75, HYPE Climbs to $55, BlockDAG Surpasses Both with $407M Presale Surge!

IP Hits $11.75, HYPE Climbs to $55, BlockDAG Surpasses Both with $407M Presale Surge!

The post IP Hits $11.75, HYPE Climbs to $55, BlockDAG Surpasses Both with $407M Presale Surge! appeared on BitcoinEthereumNews.com. Crypto News 17 September 2025 | 18:00 Discover why BlockDAG’s upcoming Awakening Testnet launch makes it the best crypto to buy today as Story (IP) price jumps to $11.75 and Hyperliquid hits new highs. Recent crypto market numbers show strength but also some limits. The Story (IP) price jump has been sharp, fueled by big buybacks and speculation, yet critics point out that revenue still lags far behind its valuation. The Hyperliquid (HYPE) price looks solid around the mid-$50s after a new all-time high, but questions remain about sustainability once the hype around USDH proposals cools down. So the obvious question is: why chase coins that are either stretched thin or at risk of retracing when you could back a network that’s already proving itself on the ground? That’s where BlockDAG comes in. While other chains are stuck dealing with validator congestion or outages, BlockDAG’s upcoming Awakening Testnet will be stress-testing its EVM-compatible smart chain with real miners before listing. For anyone looking for the best crypto coin to buy, the choice between waiting on fixes or joining live progress feels like an easy one. BlockDAG: Smart Chain Running Before Launch Ethereum continues to wrestle with gas congestion, and Solana is still known for network freezes, yet BlockDAG is already showing a different picture. Its upcoming Awakening Testnet, set to launch on September 25, isn’t just a demo; it’s a live rollout where the chain’s base protocols are being stress-tested with miners connected globally. EVM compatibility is active, account abstraction is built in, and tools like updated vesting contracts and Stratum integration are already functional. Instead of waiting for fixes like other networks, BlockDAG is proving its infrastructure in real time. What makes this even more important is that the technology is operational before the coin even hits exchanges. That…
Share
BitcoinEthereumNews2025/09/18 00:32
XRP Technical Outlook Flips Bearish as Psychological Support at $2.00 Tested

XRP Technical Outlook Flips Bearish as Psychological Support at $2.00 Tested

The post XRP Technical Outlook Flips Bearish as Psychological Support at $2.00 Tested appeared on BitcoinEthereumNews.com. XRP’s early‑2026 rally stalled on Jan
Share
BitcoinEthereumNews2026/01/09 04:28