Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 11-10-2010, 12:16 PM
Active Member
 
Posts: 39
Default Deactive webmail (HIPPA Reasons)

I have a client who would like to allow users to access zimbra only through Outlook (no webmail). I can't find anywhere where it's an option.

Alternately, can I force a specific domain to access the webmail only through https while allowing everyone else to get in through http?

They're needing this for HIPPA compliance. Our regular configuration allows users to access through either http or https and I really can't force all 2000 other users to have to start using https just because of this one client's compliance requirements.

Any suggestions?

thanks,
altimage
Reply With Quote
  #2 (permalink)  
Old 11-11-2010, 07:48 PM
Special Member
 
Posts: 149
Default

You may vote for this feature here: Bug 16099 – disable webmail access to particular user/domain
Reply With Quote
  #3 (permalink)  
Old 11-15-2010, 06:39 PM
Moderator
 
Posts: 1,209
Default

Quote:
Originally Posted by altimage View Post
I have a client who would like to allow users to access zimbra only through Outlook (no webmail). I can't find anywhere where it's an option.

Alternately, can I force a specific domain to access the webmail only through https while allowing everyone else to get in through http?

They're needing this for HIPPA compliance. Our regular configuration allows users to access through either http or https and I really can't force all 2000 other users to have to start using https just because of this one client's compliance requirements.

Any suggestions?

thanks,
altimage
I think you'll find that the HIPAA Security Rule is fine with web access, provided however that the transmission is encrypted end to end.

If you configure your Zimbra server to force users from http to https you should be OK.

Alternatively, you could just block ports 80 and 443 and the firewall to stop all web access.

I'm surprised at the requirement for Outlook; many users will turn off ssl/tls when they have any sort of connectivity options; you can't control that like you can the Zimbra https redirect, so it's a bit confusing why your practice wants to do things that way.

FWIW, we take care of a number of medical practices on our manged services side, plus we've also configured our Zimbra farm to be HIPAA compliant. Not pitching here, just letting you know that you have options with Zimbra.

One other easy way to break HIPAA compliance with Outlook is forwarding, again, which you can control in Zimbra but not in Outlook. The practitioner sets up an Outlook rule to forward emails to their ISP's home email account. Many ISP's email servers won't do server-to-server TLS, so the forwarding is done unencrypted, leading to a defacto HIPAA violation.

We actually encourage our practices to drop Outlook, so as to make enforcing HIPAA compliance easier with Zimbra.

Hope that helps,
Mark
__________________
___________________________________
L. Mark Stone, CIO


"Uptime. All the time."

477 Congress Street | Portland, ME 04101-3431 | (207) 772-5678

proactive maintenance and monitoring | technology consulting
Zimbra groupware | EMR implementations | private cloud hosting
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.