I have to question the process by which a hyperlink which gives direct access to personal and private information can be included in an email communication and be considered secure.
Two Factor Authentication anybody?
By all means include a link to documentation, but ensure that access relies on the recipient subsequently logging in using a password known only to themselves.
While this particular instance was a result of the recipient inadvertently posting the information themselves, as noted previously not all are aware of the dangers and pitfalls inherent in online communications.
The incident would not have arisen if the original communication had not included an insecure link in the first place.
It's What I Do.
I Drink and I
Remember Things.