Auditing Anyone With the Link Cloud Sharing

Sharing a file with a link is one of the most convenient features of cloud storage. A staff member needs to send a form to a family member, so she clicks "share," copies a link and pastes it into an email. Months later, that link still works for anyone who has it, and possibly for anyone who can guess or discover it. If the file contains resident information, payroll data or contracts, you have an exposure that no firewall will catch.

This post explains how to find overly open sharing links in your cloud storage and fix them.

Why open links are risky

Cloud platforms generally offer several sharing levels, which may vary by product:

Specific people: only named users can open it.

People in your organization: anyone signed in to your tenant with the link.

Anyone with the link: no sign-in required.

The last option is the dangerous one. Links can be forwarded, posted, indexed or stolen from a compromised mailbox. They rarely expire by default, and the person who created a link may have long forgotten it. If a file contains protected health information, an open link can become a reportable HIPAA incident.

Step one: understand your platform's controls

Whether you use Microsoft 365, Google Workspace, Dropbox, Box or something else, learn what administrators can do. Look for:

Tenant-wide settings that restrict or disable anonymous links

Reports showing externally shared files and link types

Options to set expiration dates on links

Per-site or per-folder sharing controls

Alerts for sharing events

Ask your IT provider to confirm which of these your licensing includes.

Step two: run an audit

Generate a report of every file and folder shared externally or through anonymous links. For each item, capture:

The owner and location

The type of link and who it grants access to

When it was created and last accessed

Whether the file likely contains sensitive information, judged by its folder, name or sensitivity labels

Focus first on high-risk locations: resident records, HR and payroll, finance, contracts and anything related to incident response.

Triage what you find

Legitimate and current: Keep, but convert to named-person sharing if possible.

Legitimate but stale: Remove the link, since the work is finished.

Unknown or suspicious: Remove immediately, notify the owner and consider whether an incident review is needed.

Contains sensitive data and publicly accessible: Escalate to your compliance officer, check access logs for who opened it and consult counsel if exposure may have occurred.

Step three: fix the settings

After cleaning up, make the safe behavior the default.

Disable anonymous links for sites or libraries containing sensitive data, or across the whole organization if your workflows allow.

Set the default link type to specific people or your organization rather than anyone.

Require expiration on any external link that remains allowed, such as 7 to 30 days.

Require sign-in or a verification code for external recipients.

Limit who can share externally to certain roles or groups.

Block external sharing entirely for the most sensitive repositories.

Apply sensitivity labels or data loss prevention rules where available, to warn or block when files with resident identifiers are shared outside.

Step four: give staff a better way

People use open links because they need to send files. Offer an approved alternative:

A secure portal or encrypted email for resident and family documents

Guest access with verification for partners who need regular collaboration

A simple guide explaining which method to use for which kind of information

Training should be short and concrete: do not use "anyone with the link" for anything containing resident or employee information.

Step five: monitor going forward

Turn on alerts for new anonymous links or large external shares.

Run the sharing report monthly or quarterly and review exceptions.

Include departures in your process: when someone leaves, review what they shared and transfer or revoke their links.

Add sharing review to your annual security risk analysis.

Document the result

Keep a record of what you found, what you changed and when. If a regulator, insurer or partner asks how you control data sharing, that record is evidence of an active program.

UnityCare IT helps healthcare organizations audit cloud storage, tighten sharing defaults and set up alerts so a convenient link does not become a breach.

Related service

Microsoft 365, cloud storage and tested backups with access controls built in.

Related articles

Keep reading

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172