AZ Rivierenland protects patient data with Data Loss Prevention policies
At AZ Rivierenland, a merger of three hospitals in Antwerp, the General Data Protection Regulation (GDPR), and therefore data governance, is a high priority. The hospital handles patients' personal data and wants to store it securely. Therefore, it has implemented Data Loss Prevention policies (DLPs) in its M365 platform. This allows it to further safeguard the privacy and security of patient data and ensures compliance with data protection law.
Store data securely, GDPR-compliant
AZ Rivierenland handles a significant amount of patient data daily: names, addresses, dates of birth, financial information, test results and treatments linked to patients, and so on. It is crucial that this personal data is stored securely and is not shared with external parties or accessible to unauthorized persons.
This is also stated in the General Data Protection Regulation (GDPR), a comprehensive privacy law that regulates the collection, use, storage, and transfer of personal data. The legislation applies to any organization that collects, processes, or stores personal data of EU/EEA residents, regardless of their location. In Belgium, the Data Protection Authority oversees compliance with the legislation and issues fines if organizations fail to do so.
Under the GDPR, individuals have the right to access their personal data, to have it deleted, and to be informed about the use of their data. Companies are also required to obtain consent from individuals before collecting and processing their personal data. Furthermore, companies must implement appropriate security measures to protect personal data from unauthorized access, disclosure, or theft. This last point is where AZ Rivierenland entered into partnership with AXI.
"AZ Rivierenland handles data meticulously," explains Carlo Usala, Presales Consultant Digital Workplace at AXI. "When they had specific questions about data governance, we started a conversation. Implementing Data Loss Prevention policies within their M365 Platform offered a suitable solution for AZ Rivierenland." Having previously relied on AXI for the migration to the M365 Platform, the hospital partnered with AXI again.
AXI Digital Workplace implements DLPs
Data Loss Prevention policies (DLPs) are a set of technologies and processes that can be used to detect data flows and intervene appropriately in the event of potential issues. They can include monitoring and detection systems, encryption, data classification, network control, endpoint security, and more. AXI configured a mix at AZ Rivierenland. The DLPs can be used for the content of attachments, emails, shared files in SharePoint, MS Teams, and OneDrive, etc.
"Each DLP at the hospital has its own function and purpose," explains Frederic Demeyere, Infrastructure Expert at AXI. "Some policies relate to detecting shared patient information. Based on a dictionary that AZ Rivierenland can further expand, data flows are detected using fields that appear in a patient file. Employees can use the various policies to decide for themselves how to intervene." For example, a notification can appear on the screen of a user who is about to share data. This way, the AZ Rivierenland IT team can inform its users to handle sensitive information with care.
A key component of DLP is the use of encryption. Encryption is a process in which data is converted into a code that can only be read with a key. By encrypting sensitive data, an organization can ensure that it is only accessible to those authorized to view it. Specifically, AZ Rivierenland can block emails or provide additional encryption when sensitive data is detected, both during internal and external sharing or sending, adds Carlo Usala, Presales Consultant Digital Workplace at AXI.
Watertight data protection
By implementing DLPs, AZ Rivierenland can guarantee the privacy and security of its patient data and comply with legal requirements for the protection of personal information.
Interestingly, AZ Rivierenland can activate the policies gradually and determine how to intervene when sensitive data is detected. "A first step, for example, could be to initially monitor only sensitive data and display a policy tip, without immediately blocking anything for users. Finally, they can choose to encrypt or block the sharing of sensitive data," says Frederic Demeyere. A successful configuration, concludes Carlo Usala: "With the options offered for handling sensitive data, AZ Rivierenland now has a solid foundation that they can expand in phases."
Curious about AXI's Digital Workplace solutions and services?
The AXI Digital Workplace team helps you with implementation, support, backup and security, modern device management, low-code automation and data insights via the MS Power Platform, and managing your hardware and software licenses.