Where did you install Firefox from? Help Mozilla uncover 3rd party websites that offer problematic Firefox installation by taking part in our campaign. There will be swag, and you'll be featured in our blog if you manage to report at least 10 valid reports!

Search Support

Avoid support scams. We will never ask you to call or text a phone number or share personal information. Please report suspicious activity using the “Report Abuse” option.

Learn More

Èròjà atẹ̀lélànà yii ni a ti fi pamọ́ fọ́jọ́ pípẹ́. Jọ̀wọ́ béèrè ìbéèrè titun bí o bá nílò ìrànwọ́.

Query regarding Thunderbird

  • 2 àwọn èsì
  • 1 ní ìṣòro yìí
  • 9 views
  • Èsì tí ó kẹ́hìn lọ́wọ́ apc2003

more options

We would like to install Thunderbird but our ITS team have some concerns about security. They would like to get feedback to the following questions. Your response is highly appreciated.

1. Is the data Encrypted at transmission? 2. Is the data Encrypted at rest? 3. Which of the following below are you compliant to?

   HIPAA 
   GDPR 
   SOC2 
   HITECH 
   FERPA 

4. Does your application protect Personally identifiable information (PII), as defined in GAO-08-536 Privacy Protection Alternative https://www.gao.gov/products/GAO-08-536 5. Does the application protect Research data as defined in Title 45 CFR §46.101 et seq https://www.hhs.gov/ohrp/regulations-and-policy/guidance/faq/45-cfr-46/index.html 6. Does your organization have a data privacy policy? 7. Have you had a significant breach in the last 5 years?

We would like to install Thunderbird but our ITS team have some concerns about security. They would like to get feedback to the following questions. Your response is highly appreciated. 1. Is the data Encrypted at transmission? 2. Is the data Encrypted at rest? 3. Which of the following below are you compliant to? HIPAA GDPR SOC2 HITECH FERPA 4. Does your application protect Personally identifiable information (PII), as defined in GAO-08-536 Privacy Protection Alternative https://www.gao.gov/products/GAO-08-536 5. Does the application protect Research data as defined in Title 45 CFR §46.101 et seq https://www.hhs.gov/ohrp/regulations-and-policy/guidance/faq/45-cfr-46/index.html 6. Does your organization have a data privacy policy? 7. Have you had a significant breach in the last 5 years?

All Replies (2)

more options

I will reply with exactly the same list of questions as this is a communication process.

Thunderbird can only use encrypted communications if the server supports it and it is not being intercepted by say an anti virus using self signed encryption certificates. So is your mail server HIPPA compliant? Does it store mail in an encrypted state when at rest? It is not a function of the mail client (which is a local application.) to be Hiipa complaint, it is a process involving all steps of the process from composition to delivery and archival storage. Have a look at this list of the 10 best HIPPA compliant email providers. Notice no Thunderbird, no Outlook, no locally installed mail clients at all.

Number 9 on that list proton mail does offer a Thunderbird bridge. But as for compliance, you might want to ask them. Thunderbird can use P2p and s/Mime for end to end communication. It does not force it. The proton mail bridge does apparently.

GDPR is is an EU standard. how you manage your emails is up to you, so if you are complaint or not is not a factor in the mail client but how it is used.

Your point 4 needs to be rephrased as does your device protect the data. Thunderbird stores dat on your hard disk, just as any other desktop application does. It is something for IT to decide if the security surrounding local storage of PII is sufficient or they need to upgrade their arrangements.

Thunderbird does have a privacy policy, but remember that none of the data about your clients or emails is actually stored remotely on Thunderbird servers. The email is stores locally on your device and on your designated mail server. Hence the way the privacy policy is worded. https://www.mozilla.org/en-US/privacy/thunderbird/

more options

Many thanks for your response. This is noted and forwarded to our ITS team.

Sorry but there is one more question from them. Please find it below. Many thanks for your assistance and patience in responding to our queries.

Which of the following below are you compliant to? HIPAA GDPR SOC2 HITECH FERPA