How come they did not password protect the file?
And send the password via other media, if the information is of that high importance.This is normal practice.
That's what we used to do when I worked in the medical industry. It works, but at least once a day I had to field phone calls asking me what the password to a file I sent 3 weeks ago was. Eventually we just had to switch to using just one file, which obviously reduces security significantly.