How to Redact PHI in SharePoint Automatically
Learn how to automatically redact Protected Health Information (PHI) in SharePoint using AI-powered DLP with OCR and real-time detection.
SharePoint is widely used in healthcare, but it lacks native PHI redaction capabilities. While SharePoint offers access controls, it does not inspect a file’s contents to identify HIPAA-sensitive information.
SharePoint’s PHI limitations include:
This exposes healthcare organizations to HIPAA violations and data breaches.
PHI shows up across many file types stored in SharePoint. Common examples include:
Strac detects and redacts PHI such as:
Healthcare data is highly sensitive, making automated redaction essential.
Redaction removes or masks PHI inside documents so the rest of the file remains usable. This allows teams to collaborate safely while protecting patient information.
Examples:
Original:
Diagnosis: Type II Diabetes
MRN: 00937284
Redacted:
Diagnosis: ***************
MRN: ********
Why redaction is critical for PHI:
Strac redacts PHI in:
Redaction events are logged for HIPAA auditing.

Strac continuously scans SharePoint libraries and synced OneDrive folders. When PHI is detected, it redacts sensitive fields instantly.
How Strac’s PHI redaction works:
Organizations can configure:
This creates a safe, HIPAA-aligned collaboration environment across all SharePoint ecosystems.
Example 1 — Medical intake PDF uploaded
Strac redacts patient name, DOB, MRN, and diagnosis descriptions.
Example 2 — Scanned insurance card
OCR detects policy numbers and redacts them.
Example 3 — Lab results spreadsheet
Strac selectively redacts PHI columns while preserving table structure.
Example 4 — Screenshots from an EHR system
Strac redacts names, IDs, and clinical details.
This minimizes exposure across every department handling healthcare information.
No. SharePoint does not detect or redact HIPAA-protected health information.
Yes. OCR detects PHI inside images, scans, and multi-layer PDFs.
Yes. Strac detects medical terminology, identifiers, and structured/unstructured PHI.
Yes. Policies can be targeted by site, library, user group, or sensitivity level.
Yes. Every redaction is logged for compliance.
Strac helps healthcare organizations automatically detect, classify, and redact PHI across SharePoint libraries, folders, synced OneDrive directories, and shared documents—ensuring HIPAA compliance and eliminating exposure risk.
.avif)
.avif)
.avif)
.avif)
.avif)


.gif)

