ProtonMail states that it enables HIPAA compliance. Healthcare organizations can use this secure email platform to send PHI through mobile and webmail apps.
Privacy and security features include end-to-end encryption and zero access data management. The service uses 4,096-bit RSA encryption for all stored communications. Data centers provide physical security for all data backups. The server hardware is located in Switzerland where the servers use fully encrypted hard disks, including multiple password layers in case the hardware is removed from the data center.
If a user’s device is stolen or lost, a remote wipe feature can protect PHI. Account owner authorization gives healthcare organizations control over who can access the information. Automated virus checking and data backups are standard. There is also a sophisticated monitoring system.
ProtonMail states that its employees don’t have access to PHI. ProtonMail states that it doesn't store paper copies or printed reports in its facilities.