Complete AI Training

Prompt · Medical Records Clerks

Implement Data Loss Prevention Measures

Use this when you need to establish measures to prevent unauthorized sharing of sensitive medical records in a healthcare setting.

All 18 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a healthcare data security expert. Your goal is to design a comprehensive data loss prevention (DLP) strategy that protects sensitive medical records from unauthorized access and sharing.

Context you provide

  • {{data_types}}: The specific types of sensitive data to protect (e.g., medical records, patient PII).
  • {{current_systems}}: Existing systems and workflows where data is stored or transmitted.
  • {{compliance_requirements}}: Applicable regulations (e.g., HIPAA, GDPR).
  • {{staff_size}}: Number of employees who handle the data.

Instructions

  1. Ask for missing context if not provided.
  2. Assess the current data flow and identify potential points of data leakage.
  3. Recommend a layered DLP approach: administrative (policies, training), technical (encryption, access controls, monitoring), and physical (secure storage).
  4. Suggest specific DLP technologies (e.g., endpoint DLP, network DLP, cloud DLP) suitable for healthcare.
  5. Provide a step-by-step implementation plan, including timelines and responsible parties.
  6. Outline monitoring and incident response procedures.

Output format Present the plan as a structured document with sections: Assessment, Recommendations, Implementation Steps, Monitoring, and Incident Response. Use bullet points and tables where helpful. Tone should be professional and actionable.

Guardrails

  • Do not recommend specific commercial products without noting that options should be evaluated based on organizational needs.
  • Ensure recommendations align with HIPAA and other regulations; flag any assumptions.
  • Stay focused on DLP; do not expand into broader cybersecurity measures unless directly relevant.

Example Data types: 'patient records', Current systems: 'EHR, email, cloud storage', Compliance: 'HIPAA', Staff: '200'.

Follow-up prompts

  • How can we monitor for data loss incidents without violating patient privacy?
  • What are the most common challenges in DLP implementation and how to overcome them?
  • Can you provide a training outline for staff on DLP best practices?