Back to Blog
Data Protection
9 min read

PHI Data Loss Prevention: Policies That Reduce Risk Without Blocking Care

DLP that blocks a clinician emailing a referral will be switched off within a month. Starting in monitor mode, tuning to real clinical traffic, and blocking only what is unambiguous.

GuardsArm Team

Security Experts

November 28, 2025

Data loss prevention

DLP has a poor reputation in healthcare for a specific reason: it is usually deployed in blocking mode against rules written for a corporate environment, it immediately stops a clinician sending a legitimate referral, and it is disabled or exempted into irrelevance within weeks.

The technology is not the problem. Sequencing is.

Clinical traffic is PHI
Most legitimate healthcare email contains exactly what naive rules flag
Monitor first
Every DLP deployment that survives started in observe mode
Block narrowly
A short list of unambiguous cases; everything else alerts

Why generic rules fail here

A rule that flags "a document containing a name, a date of birth and a diagnosis" describes an attack in a bank and a Tuesday in a hospital. Clinicians legitimately send PHI constantly — referrals, discharge summaries, specialist consultations, transfers.

The distinction DLP must make is not "does this contain PHI" but "is this PHI going somewhere it should not, in a volume or manner that does not fit the work". That is a harder question and it requires knowing what normal looks like first.


The sequence that works

DLP rollout sequenceDLP rollout sequence1DiscoverWeeks 1-4Where does PHI actually live? Endpoints, shares, cloud storage, mailboxes.2MonitorWeeks 4-12Rules on, blocking off. Build the picture of legitimate clinical traffic.3TuneWeeks 8-16Exempt the legitimate patterns explicitly. Expect this to dominate the effort.4Block the unambiguousWeek 16+A short list only. Everything else continues to alert.5Expand carefullyOngoingOne new blocking rule at a time, each preceded by its own monitor period.
The tuning phase is the work. Skipping it is why most healthcare DLP ends up disabled.

What is worth blocking

Keep this list short and defensible. Everything on it should be something no clinician would ever legitimately do.

RuleWhy it is safe to block
Bulk export above a threshold to personal cloud storageNo clinical workflow requires this
PHI to a known personal email domain in volumeDistinguishable from a single patient-requested copy
Unencrypted PHI to an external recipient where encryption is availableThe encrypted path exists and works
Copying a patient database to removable mediaShould route through an approved export process
PHI posted to a public site or paste serviceNever legitimate

Everything else — a single referral to a named external clinician, an attachment to a payer, a specialist consultation — should alert and log, not block.

Always leave a break-glass path
When DLP blocks something a clinician genuinely needs to send, there must be a documented override that takes under a minute and generates a reviewed alert. Without it, staff will find an unmonitored channel, and you will have made the problem invisible rather than smaller.

Cover the channels that matter

Email is where DLP is usually deployed and is rarely where the largest volume leaves.

Relative PHI egress exposure by channelIndicative relative exposure by channel, showing that email is neither the largest nor the least monitored path.Email30Where DLP is normally deployedCloud storage sync95Personal OneDrive, Dropbox, Google DriveRemovable media60USB, still common in clinical settingsWeb upload75File transfer sites, webmail, AI assistantsPrint40Rarely monitored at all
Indicative. The point is that email-only DLP leaves the larger channels uncovered.

Generative AI assistants deserve specific mention. Staff paste clinical text into them to summarise or rewrite, which is a disclosure to a third party and frequently to a model provider's retention. Decide the policy deliberately, provide a sanctioned tool if you can, and cover the unsanctioned ones in DLP.


Measuring it properly

  • Alerts per 1,000 messages — should fall sharply through tuning
  • False positive rate, sampled by hand, because the tool cannot self-assess
  • Blocked events with a successful override — high numbers mean the rule is wrong
  • Coverage by channel, not just by rule count
  • Time to review a genuine alert, which is the whole point of generating it

Where to start

Turn discovery on and find out where PHI actually sits. Most organisations are surprised — by the departmental file share, the spreadsheet of patients on a shared drive, the mailbox with a decade of attachments. Reducing standing PHI is often cheaper and more effective than policing its movement.

GuardsArm deploys and tunes DLP in clinical environments, including the monitor-mode baseline that makes enforcement survivable. Book a scoping call.

Written by GuardsArm Team

Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.

Take the next step on this topic

Talk to the GuardsArm team about how these services apply to your environment.