~Endpoint-based DLP monitors AI-related data transfers and applies real-time controls to prevent sensitive patient information from leaving the organisation
As hospitals increasingly use generative AI for clinical documentation, medical research, discharge summaries and administrative workflows, controlling what patient data employees share with external AI platforms has become a critical security challenge. Patient names, medical records, diagnoses, lab results, clinical histories and other protected health information can potentially leave an organisation’s security boundaries when entered into public AI tools such as ChatGPT, Claude and Gemini.
A multi-hospital healthcare network addressed this challenge by deploying eScan Business DLP, enabling clinicians and staff to use approved AI platforms for legitimate business and clinical activities while automatically preventing the transmission of sensitive patient information. During the implementation, the solution blocked or prevented hundreds of attempted transfers of patient data to public AI platforms.
Controlling Data Before It Reaches AI Platforms
The eScan deployment uses an endpoint DLP agent to monitor and control the movement of sensitive data across clinical workstations and administrative computers. The solution operates in the background, allowing users to continue their normal workflows while security policies are applied to the data being transmitted.
Before sensitive data is transmitted to an external AI platform, the DLP agent can inspect content, identify sensitive information, apply classification and enforce configured policies to allow, monitor or block the transfer. eScan Business DLP’s content-aware controls are designed to automatically discover, classify and protect sensitive information, with support for data categories including Aadhaar numbers, driving license numbers, passport numbers, PAN numbers and credit-card information.
The solution’s AI Platform Protection capability is designed to monitor and control data exposure to AI services including ChatGPT, Claude, Gemini and other AI platforms, helping prevent inadvertent sharing of sensitive information while allowing legitimate AI-powered tasks. eScan also highlights Neural Intelligence AI/ML, behavioural analysis, content-aware inspection and advanced data discovery as part of its DLP capabilities.
For a clinician, an attempted transmission containing sensitive patient information can be stopped based on the organisation’s configured policies before the data leaves the controlled environment. The approach allows security teams to apply different controls based on the sensitivity of the information and the approved use case.
AI Workflows with Security Controls
The healthcare network also established approved AI workflows for different clinical and administrative functions, allowing employees to use AI based on the nature and sensitivity of their work. General medical research queries can be routed through approved AI instances, administrative summarisation can use approved internal tools, while certain non-confidential queries can use public AI platforms.
Each approved workflow is supported by appropriate monitoring and audit controls, giving the organisation greater visibility into AI-related data activity while allowing clinicians to continue using AI where it is appropriate.
The approach allows the organisation to distinguish between legitimate AI use and potentially risky data transfers instead of treating all AI usage as a security threat.
Data Classification and Governance
A key part of the implementation was defining what constitutes sensitive patient information. The healthcare network established classifications covering patient information, personally identifiable information and other confidential clinical data, along with policies determining which AI platforms could be used for specific workflows.
The endpoint DLP controls were integrated into the organisation’s broader security and compliance framework. eScan Business DLP provides data-transfer monitoring, risk identification and reporting, audit trails and forensic logging, helping organisations maintain visibility into sensitive-data movement and support compliance reviews.
The solution also provides multi-channel filtering and monitoring across areas including email, file transfers, external storage devices and other data-transfer channels, enabling organisations to apply DLP policies beyond individual AI platforms.
Clinician adoption was another important part of the implementation. The healthcare network demonstrated that monitoring and policy controls could help prevent inadvertent exposure of patient information while approved AI workflows could continue supporting clinical and administrative productivity. Early adoption by clinical champions helped drive wider acceptance across teams.
Hundreds of Patient Data Transfers Blocked
During the implementation, the solution blocked or prevented hundreds of attempted transmissions of patient data to public AI platforms.
These were not necessarily malicious attempts. They were clinicians and staff using AI tools as part of their everyday workflows, highlighting how easily sensitive information can be shared inadvertently when employees use public AI platforms.
The blocked attempts included:
- Patient-identifiable information that could compromise patient confidentiality
- Medical histories and clinical information that should remain within controlled healthcare environments
- Laboratory results and diagnoses that could expose sensitive patient information
- Other confidential healthcare data entered into AI platforms as part of documentation, research or administrative tasks
The healthcare network also established audit trails covering data-transfer activity and the controls applied to potentially sensitive information.
Such visibility can support compliance reviews by providing organisations with a record of sensitive-data activity and the policies applied to it. eScan Business DLP’s incident response, reporting and forensics capabilities are designed to provide traceability around DLP violations and responses.
Enabling AI Without Losing Data Control
Healthcare organisations are increasingly looking at AI to improve clinical documentation, research, administrative efficiency and other workflows. But for organisations handling highly sensitive patient information, AI adoption also introduces a need for stronger data governance and visibility.
For healthcare organisations, the choice does not have to be between banning AI and accepting uncontrolled data exposure. The focus can instead be on controlling what data reaches which AI system, under what circumstances and with what level of oversight.
This requires visibility into sensitive-data movement, content-aware inspection and policy-based controls that can identify and prevent unauthorised transmission while allowing legitimate AI use. eScan Business DLP is designed to provide this through AI Platform Protection, content-aware controls, data-transfer monitoring, automated classification and audit capabilities.
Govind Rammurthy, CEO & MD, eScan, said: “Healthcare organisations are caught between two genuine pressures: enable innovation and protect patient privacy. Both matter. The solution is monitoring — knowing what data staff are sending to AI models hosted on the Internet, automatically blocking sensitive information while allowing legitimate queries. It requires visibility into data movement and the ability to enforce policies at the endpoint level. You don’t need to restrict innovation. You need to control data flow.”
