Episode 623: Now You Can Secure Outbound Email in Google Workspace
Release Date: 08/07/2026
Group Practice Tech
Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we chat with Julie Herres of GreenOak Accounting about how there’s still good money to be made in private practice, and what you need to know to make it. We discuss: Profitability and intentionality, and what it takes to stay on track Rate changes and cost of living changes impacting group practices How Julie would respond to practice owners who are feeling the squeeze right now Setting up the financials for a healthy practice Compensation for pre-licensed...
info_outlineGroup Practice Tech
Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we have an exciting update about how to make your Google Workspace email HIPAA-secure. We discuss: The encryption mechanism, TLS, and how it fits into HIPAA Security Rule standards Ways that behavioral health practices typically manage email security Escrow style email The transmission security standard under HIPAA Google’s transparency report about safer email HIPAA-friendly conventional email vs. HIPAA secure email Two limitations to be aware of and a...
info_outlineGroup Practice Tech
Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we debunk myths around documentation and fraud with Dr. Maelisa McCaffrey. We discuss: A recent article that is causing concern about whether submitting insurance claims before notes are complete constitutes fraud Fraud vs. mistakes, and consequences for mistakes in billing What constitutes fraud under the False Claims Act, with context from Eric Ström, HIPAA and mental health law attorney and practicing clinician Whether there are rules about when notes...
info_outlineGroup Practice Tech
Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we chat with Dr. Maelisa McCaffrey about how to properly document your therapy sessions. We discuss: Normalizing why documentation is such a struggle for clinicians Dispelling the myth that it is necessary to translate what you’re doing into CBT language for insurance reimbursement and why The danger of only considering insurance when documenting Documenting what actually happened in session Acknowledging that progress notes are never going to fully...
info_outlineGroup Practice Tech
Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we interview attorney Dan Pepitone about how to choose the right business entity for your group practice. We discuss: Building a strong business foundation to reduce risk and exposure to liability The distinctions between different business entities, and tax implications for each Why some states like New York and California require behavioral health care providers to practice under a professional entity like a PC or PLLC When you need to register your...
info_outlineGroup Practice Tech
Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we share what you need to know about public wi-fi networks & the security risks they pose to your devices and information. We discuss: The difference between privacy and security How the risks posed by public wi-fi networks have changed over time What security risks public wi-fi networks actually pose to your device How to use a risk analysis lens to put simple, accessible safeguards in place Listen here: For more, Resources: ...
info_outlineGroup Practice Tech
Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we share what we know about the proposed HIPAA Security Rule and steps to take to safeguard your practice in the meantime until we know more. We discuss: The current status of the proposed HIPAA Security Rule How regulatory uncertainty does not equal security uncertainty Takeaways from OCR Director Paula Stannard’s comments at the National HIPAA Summit that give insight into the rationale behind the proposed rule Risk analysis, encryption, reasonable...
info_outlineGroup Practice Tech
Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we have an important update for practice owners who bill insurance. We discuss: Why the change from CAQH to DataSpring is not just an administrative rebrand, as DataSpring is trying to position it Why this change is a big deal for practice owners who bill insurance The action steps recommended by The Group Practice Exchange Additional PCT-recommended action steps Who owns the infrastructure that healthcare depends on? Looking at this change from a risk...
info_outlineGroup Practice Tech
Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we have exciting updates for cross-jursidictional and multi-jurisdictional practice. We discuss: The Counseling Compact, and the states in which it is live The ETA for the Social Work Licensure Compact going live Access MFT’s licensure portability effort Portability-friendly laws and how they differ from rights for temporary practice PSYPACT updates Physical location restrictions and requirements for providers under compacts Details of our upcoming CE...
info_outlineGroup Practice Tech
Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we share a cautionary tale about a Talkspace client whose healthcare information was weaponized against them. We discuss: Venture capital firms buying therapy practices, monetizing, and weaponizing client data to make more money A recent case where a Talkspace client’s data was read aloud in court Platforms using client communication to train LLMs and AI platforms How these platforms are profoundly detrimental to clients, therapists, and the profession Why...
info_outlineWelcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech.
In our latest episode, we have an exciting update about how to make your Google Workspace email HIPAA-secure.
We discuss:
- The encryption mechanism, TLS, and how it fits into HIPAA Security Rule standards
- Ways that behavioral health practices typically manage email security
- Escrow style email
- The transmission security standard under HIPAA
- Google’s transparency report about safer email
- HIPAA-friendly conventional email vs. HIPAA secure email
- Two limitations to be aware of and a risk management and ethics perspective
- How to set up this configuration in Google Workspace
Listen here: https://personcenteredtech.com/group/podcast/
For more, visit our website.
PCT Resources:
- Article: A Practical Way to Secure Outbound Email in Google Workspace: What Mental Health Practices Need to Know
- Read PCT’s complete explanation of the global routing rule, what enforced TLS changes for mental health practices, what it does and does not protect, and the steps practices should take before relying on it for email containing protected health information.
- PCT’s Free Google Workspace Configuration Help Center
- Access PCT’s video tutorial demonstrating how to configure the global outbound routing rule, along with additional step-by-step guidance for configuring Google Workspace for HIPAA-compatible use.
- Office Hours for Solo Practitioners
- Get direct consultation and ongoing support for applying HIPAA requirements to the particular needs of your practice—including email, client communication, technology selection, policies, and implementation.
- Group Practice Office Hours
- Practice leaders can receive direct support with developing communication systems and workflows that are HIPAA-compatible, effective, efficient, and workable for the practice, its team, and its clients.
- Article: 3 Kinds of Email Security: How to Make an Informed and HIPAA-Aware Choice
- Learn about PCT’s framework for distinguishing among conventional email, TLS-secured email, and escrow or portal-style secure messaging—and choosing the option that fits the information, workflow, and client circumstances involved.
Resources:
- Google Workspace Admin Help: Send Email Over a Secure TLS Connection
- Google’s instructions for requiring TLS when sending email to specified recipients and preventing delivery when a secure connection cannot be established.
- Google Transparency Report: Email Encryption in Transit
- View Google’s current data on the percentage of email sent and received by Gmail that is encrypted while traveling between email providers.
- HHS: Does the Security Rule Allow for Sending Electronic PHI in an Email?
- HHS guidance explaining how the HIPAA Security Rule applies when electronic protected health information is transmitted by email.
- HHS: Does the HIPAA Privacy Rule Permit Providers to Use Email With Patients?
- HHS guidance addressing email communication with patients, reasonable safeguards, and patients’ requests to communicate through alternative means.