Change Healthcare told HHS's Office for Civil Rights that about 192.7 million people were affected by its breach.
One incident. A number bigger than most countries' populations.
That one wasn't an email leak, and DLP alone wouldn't have stopped it. But it's a reminder of how much healthcare data there is to lose, and DLP is one of the layers that's supposed to keep it where it belongs. When I build HIPAA-compliant DLP policies, I'm balancing two failures:
- Too loose, and sensitive data walks out in an email attachment
- Too tight, and people get blocked so often they start routing around the tool entirely
Both end the same way: protected data ends up somewhere it shouldn't.
Good DLP is investigation in advance. Know what your data looks like, where it legitimately goes, and which rules actually catch the bad cases instead of just making noise.