That doesn't sound right - at least here in the US, we have privacy law called HIPAA which controls how PHI (Personal Health Information) and PI (Personal Information) is communicated and sending that stuff in regular email unencrypted is a big no-no. The fines for Hippaa violations can be significant btw.
Hospitals are instructed to avoid sending sensitive information over email and only send the minimum needed to address what ever they're trying to address, i.e., not sending an entire medical record if its only focusing on one symptom for example but even then, if you can avoid sending it you should (within the network or outside the network)
That's why many hospitals encrypt sensitive data, I work with some banks where thy do something similar where I get notified by email, and I have to log in using my credentials just unencrypt the data from their site, it never sits on our email servers.