412-624-HELP
Service Announcements

Automatic Encryption Coming to External Emails Containing Sensitive Data

In February 2026, Pitt Digital introduced sensitivity labels in Microsoft 365, giving individuals a way to securely share and encrypt sensitive emails. However, these labels must be applied manually, and sensitive data may still be sent without encryption.  

To address this gap, Pitt Digital piloted automatic encryption for outgoing external emails within our department and with groups that regularly handle HIPAA-protected data. This capability runs on Microsoft’s Data Loss Prevention framework, which scans outgoing messages and attachments for sensitive information, such as protected health information, financial data, or personally identifiable information. Following a successful and well-received pilot, Pitt Digital is expanding this capability to the full University community on Wednesday, Oct. 28.

Once implemented, any outgoing email sent to a non-Pitt or non-UPMC email address that contains unencrypted sensitive information will be encrypted automatically before delivery. The sender will receive a confirmation that the message was encrypted — no further action is needed. Recipients will need to verify their identity by logging in to their organization’s Microsoft 365 account or by using a one-time password before accessing the message.

This automatic encryption serves as a safety net to protect restricted University data. It is not a replacement for sensitivity labels, which remain the most effective way to protect sensitive content in email messages.