Compliance audit passed without the fire drill.
An 85-person healthcare clinic group found patient-adjacent documents being shared through anonymous links — with a compliance review already on the calendar. Leadership expected the worst; this is what happened instead.
Sharing that was fast, invisible — and about to be inspected.
Nobody at the clinic group set out to create a compliance problem. It grew out of the fastest way to get work done: when a referral letter, a scan report or an insurance form needed to reach someone, staff generated an "anyone with the link" share and pasted it into an email. No sign-in, no expiry, no questions — it just worked, so it became the habit across every clinic.
The cost of that convenience was invisibility. Links kept working long after the reason for sharing had passed. They worked for people who had left the organization, and for anyone a message was ever forwarded to. There was no record of who had opened what, and no way to produce an inventory of what was exposed — the documents sat adjacent to patient care, outside any access control the organization could actually describe.
Then the compliance review landed on the calendar. Leadership knew roughly what the auditors would ask — who can access these documents, how is that access governed, where are the policies — and knew they couldn't answer any of it. The default response is a panicked, all-hands fire drill in the final days before the review. They called us instead.
Find everything, close everything, govern everything.
A compliance scramble fails when it starts with policies instead of facts. We worked in the opposite order: establish what was actually shared, fix the exposure, then write the governance that keeps it fixed.
We inventoried every site, library and sharing link across the tenant and mapped who could actually reach what — the factual baseline the clinic group had never had.
Every anonymous "anyone with the link" share surfaced by the audit was revoked. Where sharing was still needed, it was reissued as sign-in-required access to named people.
Person-by-person permission grants were replaced with role-based Microsoft 365 groups, so access follows the job — and leaves with the person when they do.
Documents now carry retention labels that keep and dispose of content according to policy — behavior the organization can demonstrate rather than describe.
We wrote the governance policies the auditors asked to see: who may share what, how access is requested and reviewed, and how exceptions are handled.
The review came and went. Quietly.
The fire drill leadership was bracing for never happened. The numbers below are the whole story.
Every anonymous link surfaced by the sharing audit was revoked and replaced with governed, sign-in-required access.
The compliance review returned zero findings — the auditors got direct answers, and the policies they asked to see.
From the start of the engagement to a compliant tenant in three weeks, without disrupting clinic operations.
The service behind this project — and similar stories.
Facing your own compliance review?
Book a free 30-minute audit — we'll look at how your documents are actually shared and show you where the exposure sits before an auditor does.