Sharing a file with a link is one of the most convenient features of cloud storage. A staff member needs to send a form to a family member, so she clicks "share," copies a link and pastes it into an email. Months later, that link still works for anyone who has it, and possibly for anyone who can guess or discover it. If the file contains resident information, payroll data or contracts, you have an exposure that no firewall will catch.
This post explains how to find overly open sharing links in your cloud storage and fix them.
Cloud platforms generally offer several sharing levels, which may vary by product:
Specific people: only named users can open it.
People in your organization: anyone signed in to your tenant with the link.
Anyone with the link: no sign-in required.
The last option is the dangerous one. Links can be forwarded, posted, indexed or stolen from a compromised mailbox. They rarely expire by default, and the person who created a link may have long forgotten it. If a file contains protected health information, an open link can become a reportable HIPAA incident.
Whether you use Microsoft 365, Google Workspace, Dropbox, Box or something else, learn what administrators can do. Look for:
Tenant-wide settings that restrict or disable anonymous links
Reports showing externally shared files and link types
Options to set expiration dates on links
Per-site or per-folder sharing controls
Alerts for sharing events
Ask your IT provider to confirm which of these your licensing includes.
Generate a report of every file and folder shared externally or through anonymous links. For each item, capture:
The owner and location
The type of link and who it grants access to
When it was created and last accessed
Whether the file likely contains sensitive information, judged by its folder, name or sensitivity labels
Focus first on high-risk locations: resident records, HR and payroll, finance, contracts and anything related to incident response.
Legitimate and current: Keep, but convert to named-person sharing if possible.
Legitimate but stale: Remove the link, since the work is finished.
Unknown or suspicious: Remove immediately, notify the owner and consider whether an incident review is needed.
Contains sensitive data and publicly accessible: Escalate to your compliance officer, check access logs for who opened it and consult counsel if exposure may have occurred.
After cleaning up, make the safe behavior the default.
Disable anonymous links for sites or libraries containing sensitive data, or across the whole organization if your workflows allow.
Set the default link type to specific people or your organization rather than anyone.
Require expiration on any external link that remains allowed, such as 7 to 30 days.
Require sign-in or a verification code for external recipients.
Limit who can share externally to certain roles or groups.
Block external sharing entirely for the most sensitive repositories.
Apply sensitivity labels or data loss prevention rules where available, to warn or block when files with resident identifiers are shared outside.
People use open links because they need to send files. Offer an approved alternative:
A secure portal or encrypted email for resident and family documents
Guest access with verification for partners who need regular collaboration
A simple guide explaining which method to use for which kind of information
Training should be short and concrete: do not use "anyone with the link" for anything containing resident or employee information.
Turn on alerts for new anonymous links or large external shares.
Run the sharing report monthly or quarterly and review exceptions.
Include departures in your process: when someone leaves, review what they shared and transfer or revoke their links.
Add sharing review to your annual security risk analysis.
Keep a record of what you found, what you changed and when. If a regulator, insurer or partner asks how you control data sharing, that record is evidence of an active program.
UnityCare IT helps healthcare organizations audit cloud storage, tighten sharing defaults and set up alerts so a convenient link does not become a breach.
Microsoft 365, cloud storage and tested backups with access controls built in.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172