HomeCase StudiesHealthcare compliance audit
Healthcare clinic group · 85 people

Compliance audit passed without the fire drill.

An 85-person healthcare clinic group found patient-adjacent documents being shared through anonymous links — with a compliance review already on the calendar. Leadership expected the worst; this is what happened instead.

200+open links closed
0audit findings
3 wksto compliant
The problem

Sharing that was fast, invisible — and about to be inspected.

Nobody at the clinic group set out to create a compliance problem. It grew out of the fastest way to get work done: when a referral letter, a scan report or an insurance form needed to reach someone, staff generated an "anyone with the link" share and pasted it into an email. No sign-in, no expiry, no questions — it just worked, so it became the habit across every clinic.

The cost of that convenience was invisibility. Links kept working long after the reason for sharing had passed. They worked for people who had left the organization, and for anyone a message was ever forwarded to. There was no record of who had opened what, and no way to produce an inventory of what was exposed — the documents sat adjacent to patient care, outside any access control the organization could actually describe.

Then the compliance review landed on the calendar. Leadership knew roughly what the auditors would ask — who can access these documents, how is that access governed, where are the policies — and knew they couldn't answer any of it. The default response is a panicked, all-hands fire drill in the final days before the review. They called us instead.

What we did

Find everything, close everything, govern everything.

A compliance scramble fails when it starts with policies instead of facts. We worked in the opposite order: establish what was actually shared, fix the exposure, then write the governance that keeps it fixed.

01
Permission & sharing audit

We inventoried every site, library and sharing link across the tenant and mapped who could actually reach what — the factual baseline the clinic group had never had.

02
Killed 200+ open links

Every anonymous "anyone with the link" share surfaced by the audit was revoked. Where sharing was still needed, it was reissued as sign-in-required access to named people.

03
Access rebuilt on Microsoft 365 groups

Person-by-person permission grants were replaced with role-based Microsoft 365 groups, so access follows the job — and leaves with the person when they do.

04
Retention labels applied

Documents now carry retention labels that keep and dispose of content according to policy — behavior the organization can demonstrate rather than describe.

05
Governance policies written

We wrote the governance policies the auditors asked to see: who may share what, how access is requested and reviewed, and how exceptions are handled.

Results

The review came and went. Quietly.

The fire drill leadership was bracing for never happened. The numbers below are the whole story.

200+ open links closed

Every anonymous link surfaced by the sharing audit was revoked and replaced with governed, sign-in-required access.

0 audit findings

The compliance review returned zero findings — the auditors got direct answers, and the policies they asked to see.

3 wks to compliant

From the start of the engagement to a compliant tenant in three weeks, without disrupting clinic operations.

SharePoint Online Microsoft 365 Groups Microsoft Purview SharePoint Admin Center Microsoft Entra ID

Facing your own compliance review?

Book a free 30-minute audit — we'll look at how your documents are actually shared and show you where the exposure sits before an auditor does.