Secure email: HIN, SEPPmail and encryption gateways
Secure email in regulated environments is my focus: HIN connectivity in Swiss healthcare, SEPPmail and other encryption gateways, transport encryption and the rule sets in between. I consult and build on a project basis, with particular attention to traceability and reversibility.
- HIN
- SEPPmail
- Encryption Gateways
- S/MIME
- TLS
- Rule Sets
- Healthcare
- Switzerland
Typical starting points
A clinic or group practice has to connect its own mail infrastructure to HIN. An encryption gateway is due for replacement or a major release upgrade, but nobody fully understands the grown rule set any more. An audit asks whether patient data is actually transported encrypted. Projects like these rarely fail on the technology; they fail on unknown dependencies in the existing environment, and that is exactly where I start.
Services
- HIN connectivityConnecting the HIN mail gateway to Exchange or other mail systems, defining routing and exceptions cleanly, supporting platform changes.
- Gateway projectsIntroduction, release upgrades and replacement of SEPPmail and other encryption gateways, including LDAP integration and certificate management.
- Rule set clean-upsEvaluating grown rule sets as a graph, finding dead paths, planning and executing the rebuild with a way back.
- Transport encryptionReviewing TLS configuration and certificates, introducing MTA-STS, proving rather than assuming that mail is transported encrypted.
How an engagement runs
- Intro call and goal definitionNo obligation, directly with me. Clarify the starting point and scope, then an offer with transparent terms.
- InventoryDocumenting rule set, routing and dependencies before anything is changed; in regulated environments the basis for every approval.
- Implementation in verifiable stepsEach change individually testable, with a defined way back; delicate cutovers outside peak hours.
- Proof and handoverA test protocol and documentation that stands up to an audit.
Real-world examples
- HIN: secure email in the Swiss healthcare sector: reference article on the architecture of the HIN mail gateway.
- Connecting the SEPPmail admin GUI to Active Directory: LDAP authentication as of firmware 15.0.6, step by step.
- Rebuilding gateway rule sets structurally: method and tooling for cleaning up grown rule sets.
- Mail DNS check: SPF, DKIM, DMARC, MTA-STS and DANE for a domain, right in the browser.