Skip to content

Exchange and IMAP

Who this page is for: practices on their own or hosted Exchange rather than Microsoft 365 - and the IT support who will prepare the current read-only IMAP path.

Available on Practice and Enterprise after activationread-only IMAP is built; the forwarding-address fallback is planned and no production address is issued today

Your IT support prepares a low-privilege IMAP service account with Refera.

Choosing Exchange or IMAP during signup records a preference only. It does not create a forwarding destination, store credentials or activate mailbox capture. Refera and the practice’s IT contact configure the IMAP path below, then verify a sealed patient-free arrival through that exact connector. Real patient data remains blocked until the separate activation controls clear.

Available path - the IMAP service account (30 to 60 minutes)

Section titled “Available path - the IMAP service account (30 to 60 minutes)”

After approved setup and activation, the original message stays in your mailbox. Refera reads it over TLS on port 993 (implicit TLS), without changing flags or deleting it, then processes and stores the ingested copy in the Refera AWS Sydney data plane. This path needs IMAP enabled and a dedicated low-privilege account. It avoids an extra capture mailbox, but Refera’s processing still belongs in the privacy collection notice and data processing agreement.

Where the server requires app passwords for non-interactive sign-in, use one - scoped to the service account, revocable on its own.

Refera is building a no-admin fallback for practices that prefer one server-side mailbox rule. It will issue an opaque, per-practice address and forward referral mail only, while the practice mailbox keeps its original. No production address is issued today. The path will remain unavailable until Sydney ingress, raw-message retention, tenant routing, patient-free connection testing, rotation, revocation and no-silent-drop alarms are all deployed and verified. Never invent an address or create a speculative rule.

Forwarding will not be end-to-end encrypted: delivery to Refera will require TLS, and the received copy will be encrypted in private Australian AWS storage. The arrangement must be named in the practice privacy collection notice and covered by its data processing agreement.

Refera tracks referral admin only. It does not triage patients.

Examples are fictional and contain no patient information. Practice staff approve every external action. Refera never auto-sends or independently contacts patients.

Refera homeStart account setupOpen ReferaPrivacyTerms

[email protected]AI-assisted product and setup support. For a person, use the contact form or email.