How to Block PHI in SharePoint Automatically
Learn how to automatically block Protected Health Information (PHI) from entering SharePoint using AI-powered DLP detection and real-time enforcement.
SharePoint is widely used across hospitals, insurance companies, health tech, and telemedicine, but it has no built-in PHI blocking capabilities. SharePoint does not inspect content for HIPAA-sensitive information, leaving healthcare organizations exposed.
SharePoint limitations:
This means staff can unknowingly upload highly sensitive medical data into SharePoint libraries—even into publicly accessible folders—without any safeguards.
PHI enters SharePoint constantly through common healthcare workflows. Strac’s PHI blocking rules need to trigger for:
Strac blocks PHI categories such as:
These uploads must be blocked to prevent accidental exposure.
Blocking PHI means stopping the file before it touches SharePoint storage, preventing HIPAA violations and unauthorized access. Unlike alerting or redaction, blocking ensures the PHI never enters an unapproved location.
Strac’s PHI blocking applies to:
Blocking actions include:
Blocking is essential when SharePoint is not designated as a HIPAA-compliant storage location.

Strac inspects each file as it is uploaded, synced, created, or updated in SharePoint. If PHI is detected, Strac blocks the action instantly—before the sensitive data is stored or accessed.
How Strac’s PHI blocking works:
Organizations can configure blocking based on:
Example 1 — Clinic staff uploads a PDF lab report
Strac blocks the upload and prevents PHI from entering the library.
Example 2 — Insurance team tries to sync scanned member forms via OneDrive
Strac blocks the sync and logs the incident.
Example 3 — HR department uploads employee medical documents
Upload is blocked due to PHI detection.
Example 4 — A contractor attempts to share a patient document externally
Strac blocks the share action and revokes access.
Every blocked action includes a full log entry with user, file name, timestamp, and PHI category.
No. SharePoint cannot detect or block PHI natively.
Yes. OCR detects PHI in images, scans, and layered PDFs.
Yes. Strac blocks PHI before it reaches SharePoint storage.
Yes. PHI blocking rules can be targeted by data category.
Yes. Blocking prevents PHI from being stored in unauthorized systems.
Strac helps healthcare, insurance, and clinical organizations automatically detect, classify, and block Protected Health Information (PHI) across SharePoint libraries, folders, synced OneDrive directories, and shared environments—preventing HIPAA exposure before it happens.
.avif)
.avif)
.avif)
.avif)
.avif)


.gif)

