SecurityPatient Communication

The disclaimer is the confession

Why “this email may contain confidential health information” means your patient communication is already broken — and what a channel that doesn't need an apology looks like.

MThe Moxcares team
5 min read
An envelope dissolving into light beside a small locked door

Read the footer like a patient would

You've seen the paragraph. It rides at the bottom of half the emails in healthcare:

“CONFIDENTIALITY NOTICE: This message may contain protected health information. If you are not the intended recipient, please delete it and notify the sender immediately.”

Read it again, slowly. What is it actually saying? It's saying: we just sent something sensitive somewhere we can't control, and if it landed in the wrong place, we're asking the stranger who received it to be a good sport about it.

That paragraph isn't protection. It's a confession — an admission, printed on every single message, that the channel itself can't keep a secret.

The theater of the disclaimer

These footers spread the way most healthcare habits spread: one legal team added one, everyone copied it, and twenty years later it's wallpaper. So let's be precise about what it actually does.

  • It has no meaningful legal force. A disclaimer doesn't bind someone who received a message by mistake. Regulators evaluating a breach look at what safeguards existed — not at what your signature block hoped.
  • It arrives after the harm. By the time anyone reads the notice, the PHI has already traveled through mail servers, spam filters, backups, and a lock-screen notification. The disclaimer is at the bottom. The information came first.
  • It puts the burden on the wrong person. The accidental recipient — the one party with no duty, no training, and no relationship to your patient — is who the footer assigns cleanup to. That's outsourcing compliance to a stranger.

Underneath the legal theater is a technical reality: email and SMS were never designed for this. Every hop is a copy, and every copy is a place PHI now permanently lives — the sending server, the receiving server, every synced device, indefinitely, outside your control and fully discoverable. The disclaimer fixes none of it. It just documents that you knew.

The question that dissolves the problem

Here's the reframe that changed how we built patient communication at Moxcares: what if the message never carried the information at all?

Not “what if we encrypt harder” — encryption in transit doesn't help when the destination is an unsecured inbox. The real design question is what travels. And the answer is: only a knock on the door.

In a secure-channel design, the email or text your patient receives contains no health information whatsoever. It says, in effect: you have a new message from your clinic. Nothing to breach, nothing to leak, nothing for a wrong recipient to see — because there's nothing there. A misdirected notification is a non-event.

The actual conversation — the result, the instruction, the attached form — lives inside an authenticated space. The patient taps through, proves who they are, and then the content renders. Access happens before information, not after. Links expire, so a forwarded message goes stale instead of leaking. And every access is recorded, so “who saw this and when” has an audit trail instead of a shrug.

Notice what disappears in this design: the disclaimer. Not because a lawyer said you could remove it, but because there's nothing left for it to apologize for.

If your patient communication needs a disclaimer, it needed a different channel.

This is a design choice, and it's available now

None of this is exotic. Banks figured it out years ago — your bank doesn't email your statement, it emails you that your statement is ready. Healthcare, handling information far more intimate than a checking balance, still blasts it into inboxes with an apology stapled to the bottom.

The honest reason is inertia. Email is easy, and secure channels used to mean clunky portals patients never logged into — so clinics chose convenience and let the disclaimer carry the guilt. That trade-off is dead. Modern secure messaging feels exactly like texting: the patient gets a text, taps once, verifies, and they're in a conversation with your front desk. The security lives in the architecture, not in the patient's patience.

At Moxcares this isn't a bolt-on feature — it's the only way patient communication works on the platform. Messages carry a notification, never the contents. The conversation happens in an authenticated thread. Access is verified before anything renders, links expire, and the audit trail writes itself.

The test for your own clinic

Pull up the last message your practice sent a patient. Scroll to the bottom. If there's a confidentiality disclaimer down there, ask the only question that matters: why does this message need one?

The answer, every time, is that the channel couldn't be trusted with what the message carried — and everyone involved knew it, including whoever wrote the footer.

Patient messaging that doesn't need an apology

Secure threads, expiring links, verified access, and an audit trail on every view — built in, not bolted on.

See how it works
← All postsMoxcares Blog