Skip to content
The DDMARC Blog

DMARC for Healthcare: HIPAA, Email Security, and What Auditors Actually Check

HIPAA doesn't name DMARC, but auditors increasingly expect enforced email authentication for ePHI. How DMARC maps to the Security Rule, and how to roll it out in a clinic.

PlatOps Security TeamCompliance6 min read

Healthcare runs on email — appointment reminders, lab results, billing, referrals, vendor coordination — and that makes it one of the most targeted industries for phishing and business email compromise. A forged message from billing@yourhospital.org or noreply@yourclinic.com is a credible path to credentials, fraudulent payments, or a foothold near electronic protected health information (ePHI).

DMARC is the control that stops attackers from sending mail that forges your domain. The question compliance teams ask is whether it's required — and the honest answer is more useful than a yes or no. Let's map DMARC to what HIPAA actually says, and to what an auditor actually looks for.

Where email authentication sits in HIPAA's Security Rule

HIPAA's Security Rule (45 CFR Part 164) is deliberately technology-neutral. It doesn't name DMARC, SPF, or any specific protocol. What it requires is a process and a set of safeguards:

  • A risk analysis identifying threats to ePHI — and email-borne phishing is one of the most significant.
  • Administrative, physical, and technical safeguards addressing the risks you find, including protection against malicious software and unauthorized access.
  • Transmission security for ePHI moving over electronic networks.

Email spoofing is squarely a threat to ePHI: it's how attackers harvest credentials and impersonate trusted staff. Because the rule is risk-based, the expectation isn't "implement DMARC" — it's "identify the phishing risk and apply a reasonable control." DMARC is the reasonable control for the specific risk of someone forging your domain. Start with what DMARC is if you need the mechanics.

It's not just HIPAA — HHS recommends it directly

Where the Security Rule is neutral, federal guidance is specific. HHS's 405(d) Health Industry Cybersecurity Practices (HICP) — the recognized practices the agency points the sector toward — calls out email protection, including authentication like SPF, DKIM, and DMARC, as a core defense against the email threats that drive most healthcare breaches. NIST guidance points the same way.

That matters for two reasons. First, "recognized security practices" can influence how regulators weigh enforcement after an incident. Second, it gives your auditor a concrete yardstick: email authentication is no longer exotic — it's expected baseline hygiene for a covered entity.

What an auditor actually wants to see

An auditor isn't grading your DNS syntax. They want evidence that you identified the risk and applied — and monitor — a control. For DMARC, that evidence pack is:

  • A risk analysis that names email phishing/spoofing as a threat to ePHI.
  • An enforcing DMARC policy (p=quarantine or p=reject) on your sending domains — not just a p=none record you published and forgot.
  • Coverage: your primary domain and the subdomains and parked domains attackers could otherwise forge.
  • Monitoring records: aggregate reports showing you actually watch who sends as your domain, with a process for reviewing them.
  • Documentation tying the control back to the identified risk.

The gap auditors find most often is a domain stuck at p=none — detection with no enforcement. That demonstrates awareness without protection, which is a weaker position than not having started.

DMARC enforcement as a control

The value of DMARC to a covered entity is specific and provable: at an enforcing policy, mail that forges your exact domain is refused or quarantined by receiving servers, and the aggregate reports give you an auditable record of every source sending under your name — legitimate or not. That's both a preventive control and a monitoring control, which is exactly the pairing HIPAA's risk framework rewards.

Be precise about scope, though — overclaiming hurts credibility with auditors. DMARC stops exact-domain spoofing. It does not stop lookalike domains (yourhospita1.org) or display-name tricks, and it isn't a substitute for encryption of ePHI in transit. It's one strong control in a layered program, and it should be documented as exactly that.

Rolling it out in a clinical environment

Healthcare environments are hard precisely because so many systems send mail as you: the EHR, the patient portal, appointment-reminder services, billing and clearinghouse vendors, labs, and a long tail of departmental tools — many of them third parties handling ePHI under a Business Associate Agreement. Flip to p=reject blind and you risk blocking legitimate patient and clinical mail.

The path is the same staged, evidence-driven rollout we cover in the DMARC rollout playbook, with a healthcare-specific first step:

  1. Inventory every sender, including vendors that send on your behalf. Cross-reference your BAA list — anyone touching ePHI should be authenticating as you correctly.
  2. Publish p=none and read the reports until every legitimate clinical and administrative source is authenticated and aligned.
  3. Align the third parties one by one (the EHR and portal are usually the trickiest).
  4. Move to p=quarantine, then p=reject once the reports are clean.
  5. Keep monitoring — new vendors and systems appear constantly in healthcare, and each is a new sender to verify.

This is the work our healthcare solution and broader security program are built to support — managed monitoring so the reports get read, not just collected.

Frequently asked questions

Does HIPAA require DMARC? Not by name. HIPAA's Security Rule is technology-neutral — it requires safeguards against threats to electronic protected health information, including the phishing and spoofing that email enables, but it doesn't mandate a specific protocol. DMARC is a widely recommended control for that risk, and HHS's own 405(d) cybersecurity practices call out email authentication, so auditors increasingly expect to see it.

How does DMARC help with HIPAA compliance? DMARC stops attackers from sending email that forges your domain — a primary vector for phishing and business email compromise in healthcare. Implementing and enforcing it gives you a documented technical control that maps to HIPAA's risk-management and transmission-security expectations, and the aggregate reports provide audit evidence that you monitor who sends as your domain.


For a covered entity, DMARC isn't a checkbox HIPAA hands you — it's the obvious answer to a risk HIPAA makes you address. Identify the phishing threat, enforce authentication on every domain you own, and keep the reports under review. See where your domains stand, then close the gaps before an auditor — or an attacker — finds them.

ShareX / TwitterLinkedIn
Free to start · 14-day trial · cancel anytime

From spoofed to enforced.

p=none
5 min
p=quarantine
Week 2
p=reject
Week 4–6

Billed when your 14-day trial ends · cancel anytime before then