The practice address has been @yahoo.com since 2004
A two-provider practice has used the same Yahoo address for twenty years. It is on the referral pads, the payer files and the sign outside. Nobody chose it as a compliance decision; it was simply the address the practice had when it opened.
- Does PHI genuinely pass through it, or only appointment logistics and vendor mail?
- Who else knows the password, and has that ever changed?
- Is two-step verification switched on for the account?
- Whose personal phone number is the recovery method?
- What happens to this account when that person retires?
- Is anything forwarded from it, or into it?
- Which devices hold a copy of twenty years of mail?
- Could the practice produce or search this mailbox if it had to?
- Is there an agreement covering the service, and can anyone produce it?
The email address alone doesn't tell you whether the practice is compliant. What it does tell you is that the vendor agreement question and the continuity question both need answers, and on a consumer mailbox those answers are usually "nobody has checked".