The review Survey of Techniques on Data Leakage Protection and Methods to Address the Insider Threat states that "data leakage is the disclosure of information to unauthorized entities or individuals." They go on to state that data loss prevention (DLP) will log and/or warn of data traveling through your network and may quarantine or block those messages.

When tracking the right metrics, administrators will be able to find what may be considered excessive without blocking care communication and create actionable items. Paubox’s DLP Observe and Report allows healthcare organizations to observe patterns of confidential data traveling through their email streams before putting a new rule in place.

 

What is DLP?

There are various types of DLP technology available for organizations to detect when private information may have been transmitted. DLP can detect emails or files with protected health information (PHI), financial information, user passwords and any sensitive information. Once detected DLP can take action depending on your organization's needs. Whether you want to simply flag the email, send it to an admin for further inspection, quarantine it or stop the email from being sent all together.

There is a difference between encryption and DLP. Encryption makes data unreadable to unauthorized users unless they have the appropriate key or access. However, DLP detects and applies policies to sensitive data. Depending on configuration, it may log, alert, quarantine, or block transmission. Just as you would want DLP to understand if there is any malicious intent behind your users. DLP can detect patterns, sensitive content, recipients, and contextual signals, but it does not inherently determine whether someone is clinically authorized or has a legitimate need to know. Organizations can implement a learning phase and discover what type of emails they typically send out.

Using Paubox DLP Observe and Report will help scan incoming and outgoing email traffic for potential leaks of PHI, PII, financial information, credentials, proprietary information, and legal information. It will provide you with a level of severity and display suggestion cards from the past 30 days. Messages sent from marketing or on a bulk list will not be shown.

According to Paubox, “It never holds or quarantines a message.” Allowing admins to gain insight into what may be occurring in their organization before adding a rule that could stop a message they would normally allow.

There should be information that displays what's going on in your email traffic, how much is happening, and whether adding a rule will cause workflow interruption.

 

The metrics to take note of

Observation volume by data category

One metric to look at when observing email traffic is how many observations are happening and by what category. Observing these numbers will help you build off of to decide which categories you may want to spend time on.

According to the Paubox 2025 Healthcare IT survey, 60% of healthcare organizations have been impacted by an email security incident in 2024. Knowing that we know that we will see observations around PHI and PII. But that doesn't mean all emails that contain that information should not be sent.

Review what types of categories are showing up in your observations and if that is something you expect when communicating about patients. Recurring PHI observations in referrals may call for a defined HIPAA compliant email workflow, while credentials in message bodies may require a separate sharing process. This can reduce risky handling without stopping necessary communication.

 

Severity distribution

Look at the percentage of observations you are getting by severity level. Start by reviewing observations with a high severity level.

The article Distinct Components of Alert Fatigue in Physicians' Responses to a Noninterruptive Clinical Decision Support Alert found that "Health systems should monitor providers' recent alert exposure as a measure of alert fatigue." They were more likely not to answer the clinical decision alert if they had received more recent alerts.

It is necessary to keep alert fatigue in the back of your mind, as DLP observations aren't meant to be clinical. Prioritize reviewing those high-severity alerts, and you can tackle the lower-severity ones in batches. This will allow your administrators to stay focused when it comes to HIPAA compliant email reviews.

 

Repeat patterns across workflows

Even a single observed instance can be a signal, but a recurring pattern is definitely something worth discussing with your team. You might even decide to develop a rule based on what you observe.

The study Nurse Information Security Policy Compliance, Information Competence, and Information Security Attitudes Predict Information Security Behavior was able to gather data from 200 clinical nurses. They found that information security policy compliance and information competence showed a strong correlation with attitudes toward information security.

When reviewing observations, look for any recurring patterns. Do you notice this during your referral packet or billing information transmissions? After pinpointing these problem spots, you can start showing your team why their messages triggered the DLP alerts and offer a way forward that lets them keep up their essential work.

 

Review outcome and rule-conversion rate

A Scoping Review of the Drivers and Barriers Influencing Healthcare Professionals' Behavioral Intentions to Comply With Electronic Health Record Data Privacy Policy stated that "human factors such as attitude, social influence, self-efficacy, and perception of usefulness are just as important as the technical aspects and should be taken into consideration when looking to increase compliance."

Consider the conversion rate of your observations into concrete rules. A high percentage might signal a need to re-examine your current rule. One consideration is that the number of rules might be excessive, or administrators could be acting too quickly without adequate review. You could realize that some of the messages your team sends are necessary to keep operations running smoothly.

 

The bottom line

A DLP observation period is most useful when it measures patterns, not just message counts. Healthcare organizations should track category, severity, recurrence, review outcome, workload, and change after action.

See also: Managing email data loss prevention (DLP) in healthcare

 

FAQs

How long should a DLP observation period last?

Start with one complete 30-day reporting window, then extend it if seasonal or low-volume workflows are not represented.

 

Who should approve a new DLP rule?

A small group representing privacy, compliance, IT, and the affected operational team should approve it together.

 

Should reviewers read every observed email?

No, they should prioritize by severity and recurring pattern, using the minimum message content needed to make a sound decision.

 

Can observation results be used for employee discipline?

The safer approach is to use them first for risk reduction and workflow improvement under a documented, consistently applied policy.