accessingencryptedemailsguidepdf
accessingencryptedemailsguidepdf
Page 1 of 120
Neil Bhatia shared this file. Want to do more with it?
  1. Accessing Encrypted Emails Guide for Non-NHSmail usersApril2017Version 2.1Copyright © 2017Health and Social Care Information Centre.The Health and Social Care Information Centre is a non-departmental body created by statute, also known as NHS Digital.
  2. ContentsIntroduction31.1.Purpose of Document3Receiving an encrypted email3Replying to and forwarding encrypted emails5Register to use encrypted email61.2.Start of registration71.3.Activating your account/Completing the registration9Keeping encrypted emails secure11Help and further guidance12Frequently asked questions12Copyright © 2017 Health and Social Care Information Centre.2
  3. Accessing Encrypted Emails Guide for Non-NHSmail usersIntroduction1.1.Purpose of DocumentTarget Audience: Recipients of encrypted emailssent from an NHSmail accountNHSmailis a national secure collaboration service for health and social care, designed to enable the secure exchange of information by email and other methods.NHSmail uses the Trend Encryption Micro service to support NHSmail users sendingsecure, encrypted emails to any email service free global hosted email services such as Gmail/Hotmail and other privately-run email services.This document provides guidance for recipients of encrypted emailswhich have beensent from an NHSmailaccount. It explains how to register for the service, open and read encrypted emails and send an encrypted reply.It also provides important guidance about information governance and ensuring sensitive information that has been received remains secure.Please note it is not possible for anyone other than an NHSmailuser to initiate an encrypted email exchange using the NHSmailencryption feature.If you are a non-NHSmailuser and wish to exchange information securely with a member of health or social care staff who uses NHSmail, please direct them to the document: Encryption Guide for NHSmail.Note:While encryption guidelines for NHSmail users in Scotland may differ, encryption is recommended as best practice for anyone exchanging sensitive or patient data Receiving an encrypted emailAn encrypted email sent from an NHSmailaddress (ending @nhs.net) will contain a link to access the encrypted message.The message reads:PRIVATE AND CONFIDENTIALYou have received an email message secured by Private Post.Please open the file called Encrypted_Message.htm to read the message.Fig 1.An encrypted NHSmailmessage in Gmail1.Open the file Encrypted_Message.htm. Your browser should allow you to either view the file directly, or to download and then open the fileCopyright © 2017 Health and Social Care Information Centre.3
  4. Accessing Encrypted Emails Guide for Non-NHSmail usersFig 2.The Encrypted_Message.htm file2.Click Open Messageand the account verification screen will appear•Not registered?If you have not previously received an encrypted NHSmail email, you will be redirected to an external website which will guide you through the registration process to create an account with the NHSmailencryption provider. This should only take a few minutes. See section fourof this document.•If you have previously registered with the NHSmailencryption provider, the system may display the Account Verification screen(Fig 3).3.If theaccount verificationscreen does not display your correct email address, click Change4.Enter your Password•Or click Forgot your password or answers?if you have forgotten your password.5.Select a time from the Keep me signed inlist.For the duration of the time selected, you will remain logged in to the TrendEncryptionMicro service. At the end of the time selected, you will be automatically signed out6.Click ContinueFig 3.Account VerificationThe system will display the encrypted message sent to you from NHSmail.Copyright © 2017 Health and Social Care Information Centre.4
  5. Accessing Encrypted Emails Guide for Non-NHSmail usersFig 4.A test encrypted emailYou will be able to:•Read the From, To, Sentand Subjectinformation•Read the email message•Reply to the sender•Reply to all recipients•Forward the email•Download attachmentsReplying to and forwarding encrypted emailsYou can reply to or forward encrypted emails. Your emails will be automatically encrypted. You can include attachments if required.To reply to or forward encrypted emails:1.Open the encrypted NHSmailemail2.Enter your password if the system prompts you3.Click Replyor Reply Allor Forward(as required)4.Enter the recipients in the TO: CC:and BCC:fields5.Edit the Subjectfield (as required)6.Add attachments (as required)7.Enter a message8.Click Send(Any recipient that hasn’t already registered to receive encrypted emails will need to go through the process outlined in section 2 before accessing the content)Copyright © 2017 Health and Social Care Information Centre.5
  6. Accessing Encrypted Emails Guide for Non-NHSmail usersFig 5.A decrypted emailRegister to use encrypted email If you have not previously received an encrypted email from the TrendEncryptionMicro service you will be redirected to the Trend Micro Private Post website. There you will be guided through the registration process to create an account with the NHSmailencryption provider.Note:Registered recipients don’t need to re-register to read subsequent encrypted emailmessages sent from any NHSmail user.Copyright © 2017 Health and Social Care Information Centre.6
  7. Accessing Encrypted Emails Guide for Non-NHSmail users1.2.Start of registrationFig 6.Start of Registration1.If your email address is not correctly displayed, click the (Not your email?)link2.Click Register•TheRegister Encryption Accountscreen will be displayed.Copyright © 2017 Health and Social Care Information Centre.7
  8. Accessing Encrypted Emails Guide for Non-NHSmail usersFig 7.Register Encryption Account3.Type and confirm your password –you will need to use this password to open encrypted emails sent to you4.Select a security question and type the answer5.Type an Identification word (this will appear on the authentication screens)6.Typein the code displayed in the “CAPTCHA” image (the obscured code at the bottom of the screen designed to prevent spam and fake registrations)7.Tick the box to confirm agreement to the Licence and Terms8.Once you have completed all the fields, click Continue•TheCheck your email to activate your account screenwill be displayed.Copyright © 2017 Health and Social Care Information Centre.8
  9. Accessing Encrypted Emails Guide for Non-NHSmail usersFig 8.Check your email to activate your account•A message prompts you to check your inbox for a registration confirmation email message. Follow the instructions in the email message to confirm your encryption account (see next section for more details).9.Click Close Page.1.3.Activating your account/Completing the registrationFig 9.Registration confirmation email message1.Open the Registration confirmation email message in your Inbox. (If you do not see a registration confirmation email in your Inbox, check your spam folder.)Copyright © 2017 Health and Social Care Information Centre.9
  10. Accessing Encrypted Emails Guide for Non-NHSmail users2.Click the link in the Registration confirmation email message.•The Authentication Successfulmessage will be displayed.Fig10.Authentication Successful message3.Click Close PageThis will complete your registration. Once you have successfully registered, you will be able to open, read and download any attachments in encrypted NHSmail emails.After registration,you canreceive encrypted email from any NHSmail user and do not need to register again if another NHSmail user sends you an encrypted email.To read and reply to another encrypted message you just need to verify your identity using the credentials you registeredwithwhen you first signed up to the service.If you forget your password, the system includes a self-service password reset feature.Copyright © 2017 Health and Social Care Information Centre.10
  11. Accessing Encrypted Emails Guide for Non-NHSmail usersIf another organisation sends you an encrypted email using the same Trend Micro powered email encryption, your Trend Micro account credentials can be used to decrypt these messages too.Fig 11. Authentication screen once an account has been createdNote:You do not need to click on the Want to Reply?link to use the service. If you click on Want to Reply(shown in screenshot above), you’ll be given the opportunity to install a Microsoft Outlook ‘add-on’ that will provide you with the means to send encrypted replies to emails that you receive. You should be aware though that if you install the add-on to a shared computer, someone else could see confidential messages you have receivedas these will appear in your normal mailbox. Clicking on Want to Reply will give full guidance on how to download and install the add-on. Keeping encrypted emails secureBefore replying to an encrypted email, ensure that the recipient is expecting it and is ready to handle the contents appropriately as part of an agreed clinical or business partner sensitive data workflow, particularly if it contains sensitive or patient identifiable information.If you wish to keep any received emails we recommend you download them and store them safely as required.Although all attachments sent orreceived through the NHSmail encryption service will be virus checked we do recommend your organisation runs its own anti-virus software.Note for third-party/commissioned providerorganisations:it is your responsibility, on behalf of your employing organisation, to safeguard any data received in line with the data protection and information governance requirements agreed between your organisation and the sending organisation. If required, you should retain unencrypted copies of any encrypted email received in your local information repositoriesas per your local information governance policiesand processes.Copyright © 2017 Health and Social Care Information Centre.11
  12. Accessing Encrypted Emails Guide for Non-NHSmail usersIf you are a patientand are receiving information from health or social care staff using the NHSmail service, you should have given consent to the organisation to exchange informationwith you before they send it.Once received, it is your responsibility to look after any sensitive information sent to you.You should consider whether the computer on which you access the information is shared with other people –if so they may be able to view any information you receive.There are various excellent sources of guidance on how to keep information secure such as www.getsafeonline.org.Help and further guidanceFor help please visit the Trend Micro support site at: http://www.privatepost.com/support/faqs/aspxOr call the national NHSmailhelpdesk on 0333 200 1133 or email helpdesk@nhs.netRecipients of NHSmail encrypted emails that require help with registration should refer to the help provided on the registration website. Frequently asked questionsIf I want to forward an encrypted email I’ve received to someone else, will the email remain encrypted?Yes. Any recipient added will receive the message securely (encrypted).They will then have to register or log-in to an existing Trend Micro account, as detailed above. What is the maximum number of email addresses that can be included on a reply to an encrypted email or when the email is forwarded?You can reply or forward the encrypted email to a maximum of200 recipients. All recipients will then have to register or log-in to an existing Trend Micro account, as detailed above. Is message tracking (e.g. delivery or read receipts) available on encrypted emails?No.Email delivery over the Internet has no guarantees that a message will reach its intended recipient as Internet email can be silently lost.What is the maximum attachment size I can send on encrypted email replies/forwards?35Mb.What types of attachmentscan be included on encrypted email replies/forwards?Certain file types that can contain potentially harmful content are blocked by the NHSmail service and cannot be sent or received.Thelist of blocked attachments can be found in theCopyright © 2017 Health and Social Care Information Centre.12
We use cookies to provide, improve, protect and promote our services. Visit our Privacy Policy and Privacy Policy FAQs to learn more. You can manage your personal preferences, including your ‘Do not sell or share my personal data to third parties’ setting using the “Customize cookies” button below.