-

Paubox Report Exposes Encryption Failures by Microsoft and Google That Put Users at Risk

SAN FRANCISCO--(BUSINESS WIRE)--A new investigative report from HIPAA compliant email provider Paubox has exposed a hidden security failure in Microsoft 365 and Google Workspace, two of the most widely used email platforms. Despite claims of encryption and compliance, both platforms fail under real-world conditions that could expose sensitive information without the sender or receiver knowing.

Any organization relying on Microsoft 365 or Google Workspace for email encryption could be unknowingly exposing sensitive information.

Share

The report, How Microsoft and Google Put PHI at Risk, details a series of controlled experiments in which messages sent from both platforms were delivered either using obsolete encryption protocols or unencrypted in cleartext. In all test cases, the sender was never notified of the failure—there was no bounce, no alert, and no visible log.

A test of real-world encryption

The Paubox research team simulated how email behaves when sent to outdated or noncompliant servers—a realistic scenario in healthcare, where digital infrastructure is often fragmented across clinics, vendors, and legacy systems.

  • Google Workspace still transmits emails using obsolete encryption protocols like TLS 1.0 and TLS 1.1—versions explicitly prohibited by the NSA.
  • Microsoft 365 silently delivers emails in cleartext when encryption cannot be negotiated, exposing sensitive data to potential interception with no warning to senders or recipients.
  • In both cases, there was no bounce, no alert, and no audit trail. The only evidence was buried in the message headers.
  • Outdated TLS configurations and certificate mismanagement are consistently listed among the top security risks, even in API environments.

Critically, these weren’t configuration mistakes.

Cleartext delivery and outdated encryption put data at risk

This isn’t just a healthcare problem. Any organization relying on Microsoft 365 or Google Workspace for email encryption could be unknowingly exposing sensitive information. These platforms do not consistently enforce strong encryption, and many IT teams are unaware of the gaps.

“Using obsolete encryption provides a false sense of security because it seems as though sensitive data is protected, even though it really is not.” – NSA, Eliminating Obsolete TLS, 2021

These flaws violate the NSA’s guidance to eliminate TLS 1.0 and 1.1, and directly contradict RFC 8996, which states that outdated protocols “MUST NOT be used.”

With no audit trail, no bounce, and no alert, messages appear to be protected, even when they’re not.

When encryption fails, organizations are left vulnerable to regulatory violations, legal action, and reputational damage, even when they believe they’ve done everything right.

Next steps for IT and compliance teams

Paubox urges IT leaders to stop assuming encryption is working and start testing it for themselves. The report walks through the testing process in detail and includes annotated message header examples that show what encryption downgrade looks like in practice.

The full report is available now at https://hubs.la/Q03tg5-k0.

About Paubox

Paubox is a leader in HIPAA compliant communication and marketing solutions for healthcare organizations. According to G2 rankings, Paubox leads the industry for Best Secure Email Gateway, Email Security, HIPAA Compliant Messaging Software, and Email Encryption solution, and is the only HIPAA compliant email company listed on G2's 2025 Best Healthcare Software Products. Paubox solutions include Paubox Email Suite, Paubox Marketing, Paubox Email API, Paubox Forms, and Paubox Texting. Launched in 2015, Paubox is trusted by over 6,000 healthcare organizations, including AdaptHealth, Cost Plus Drugs, and Covenant Health.

Contacts

Media Contact:
Dawn Halpin
press@paubox.com

Paubox


Release Versions

Contacts

Media Contact:
Dawn Halpin
press@paubox.com

Social Media Profiles
More News From Paubox

73% of Rural Healthcare Orgs Say They Struggle to Maintain HIPAA Compliance Due to Staffing and Funding Gaps

SAN FRANCISCO--(BUSINESS WIRE)--As cyber threats grow more frequent and sophisticated, rural hospitals and clinics face challenges on all fronts—tight budgets, limited staff, inadequate training, complex technology, and unsupportive vendors. Many are left trying to manage security tools without the IT resources to support them. Rural healthcare organizations are encountering more roadblocks to cybersecurity than their urban peers—and not just in one or two areas. The findings are part of a broa...

Paubox Awards 2025 Kahikina Scholarships to Native Hawaiian Students Pursuing STEM Degrees

HONOLULU--(BUSINESS WIRE)--The 2025 class of Paubox Kahikina Scholarship recipients was announced today. The scholarship’s mission is to encourage Native Hawaiians to pursue careers in STEM or technology in general. The scholarship is recurring in nature. In other words, recipients receive $1,000 per year until they graduate. Now in its seventh year, this year’s class of 17 recipients is the largest to date. Awardees graduated from high schools in Hawaiʻi, Nevada, and Texas. This year’s recipie...

Microsoft’s Email Encryption Behavior May Violate HIPAA, New Paubox Report Warns

SAN FRANCISCO--(BUSINESS WIRE)--A new report from Paubox, a leader in HIPAA compliant email, reveals that Microsoft 365’s email encryption behavior could be putting healthcare organizations at serious risk of noncompliance. In a series of controlled TLS experiments, Paubox researchers found that Microsoft 365 may transmit messages in cleartext when encryption fails, without bouncing the message, alerting the sender, or logging any evidence of the failure. This occurred when messages were sent t...
Back to Newsroom