Article

Data Security Posture Management (DSPM) for Healthcare

Every HIPAA settlement HHS announced in the first five months of 2025 — all ten of them — cited the same root failure: the organization had not completed an accurate, enterprise-wide risk analysis of where its electronic PHI actually lives (National Law Review). One national medical supplier paid $3 million after OCR found it never conducted a "compliant risk analysis," and was then hit by a phishing-driven breach (National Law Review). That pattern — can't protect PHI you can't find — is exactly the gap Data Security Posture Management (DSPM) was built to close, and it's why DSPM has become one of cybersecurity's fastest-growing categories heading into 2026, with market estimates ranging from roughly $1.5–2 billion in 2025 to as high as $10 billion by the early 2030s (Palo Alto Networks).

What DSPM actually is

Data Security Posture Management is a data-centric security discipline that continuously discovers, classifies, and assesses the exposure of sensitive data across cloud, on-premises, and SaaS environments — rather than starting from infrastructure or network perimeters (Microsoft). IBM defines it as technology that identifies sensitive data across cloud environments and services and assesses its vulnerability to security threats and regulatory non-compliance (IBM). Gartner, which coined the category in its 2022 Hype Cycle for Data Security, predicts that more than 20% of organizations will deploy DSPM technology by 2026 specifically to find previously unknown data repositories and mitigate the risk they carry (Cloud Security Alliance, citing Gartner). At its core, DSPM answers four questions: where does sensitive data live, who or what can access it, how is it being used, and what's the security posture of the system holding it (Varonis).

Why DSPM has gained traction through 2025-2026

Adoption has accelerated because data sprawl has outpaced manual inventory methods. A 2025 industry survey found 75% of organizations planned to implement DSPM by the end of 2025, with adoption velocity outpacing both EDR and Cloud Security Posture Management (Palo Alto Networks 2026 DSPM Adoption Report). Frost & Sullivan projects the broader data security market will grow at a 37.4% compound annual rate from 2025 through 2029 (Palo Alto Networks). The driver is simple: security teams can no longer answer "where is our sensitive data" with a spreadsheet, and breach costs are punishing the ones who can't. IBM's 2025 Cost of a Data Breach Report found that breaches involving data spread across multiple environments — exactly the pattern DSPM is designed to map — cost $5.05 million on average, the highest of any category studied (IBM).

Healthcare's shadow-PHI problem, by the numbers

Healthcare has been the single costliest industry for data breaches for 14 consecutive years, averaging $7.42 million per breach in IBM's 2025 report (TechTarget). The volume is climbing too: healthcare data breaches more than doubled in frequency in 2025 compared with the prior year (TechTarget), and over 700 breaches exposed more than 275 million patient records between 2024 and 2025 (BrightDefense). Shadow IT compounds the exposure: 86% of health system IT executives reported instances of shadow IT in a 2025 survey, up from 81% the year before, driven by staff turning to personal cloud storage and unapproved apps that fall outside sanctioned environments while still handling sensitive data (TechTarget). Third parties compound it further — more than 80% of stolen PHI records originate from third-party vendors and software services rather than hospitals directly (Knowi, citing HIPAA Journal/DeepStrike), and the Change Healthcare breach alone ultimately affected roughly 192.7 million individuals (DeepStrike).

How DSPM differs from DLP and CSPM

Traditional Data Loss Prevention watches channels — network egress, email, endpoints — to stop sensitive data from leaving a defined boundary. DSPM instead follows the data itself, wherever it lives, and asks a broader set of questions: what sensitive data exists, where does it live, who can reach it, and is it over-exposed (Securiti). Cloud Security Posture Management (CSPM), meanwhile, is data-agnostic — it evaluates infrastructure misconfigurations without knowing whether the resource in question actually holds sensitive data (Concentric AI). The two are complementary rather than competitive: DSPM focuses on data-access governance and finding data at rest, while DLP protects data in motion, and CSPM secures the infrastructure layer underneath both (Forcepoint). For healthcare specifically, that distinction matters because PHI routinely sits in places CSPM never inspects and DLP never watches — misconfigured storage buckets, orphaned database exports, and SaaS tools nobody remembered to add to the inventory.

Vendor approaches worth knowing

Several vendors have built healthcare-specific DSPM capabilities. Cyera markets PHI discovery across IaaS, PaaS, and SaaS, entitlement right-sizing for over-privileged or duplicate identities touching PHI, and audit-ready evidence for HIPAA and HITRUST reviews (Cyera). BigID positions its platform around finding PHI across EHRs, cloud storage, SaaS apps, databases, file shares, and legacy systems, then generating audit-ready evidence for HIPAA reviews (BigID). Wiz built DSPM directly into its cloud-native platform using agentless, read-only API scanning, so a publicly accessible storage bucket's risk score jumps the moment Wiz detects it holds PHI or PII (Wiz DSPM overview via Techclick). Varonis has documented healthcare deployments that identified hundreds of thousands of files with excessive access — one regional health system case study cites 318,357 folders with global group access and 504,162 HIPAA-relevant "hits" flagged for remediation (Varonis case study). Securiti frames DSPM around automated data discovery that determines where PHI exists and imposes least-privileged access as a direct response to HIPAA's risk analysis and access control requirements (Securiti). The common thread across all of them: discovery and classification come first, because every other control — access governance, encryption, monitoring — depends on actually knowing where the PHI is.

How DSPM connects to HIPAA risk analysis

The HIPAA Security Rule requires covered entities and business associates to conduct "an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability" of all e-PHI they hold, "regardless of the particular electronic medium" or location (HHS). OCR has been explicit that this is not optional: its 2025 enforcement actions repeatedly stated that "performing a HIPAA risk analysis is not an optional or 'check-the-box' exercise" and that a comprehensive risk analysis is "one of the simplest and most effective tools to protect against data breaches" (National Law Review). The proposed HIPAA Security Rule update, issued December 27, 2024, would go further — requiring technology asset inventories, network mapping to track ePHI movement, and more rigorous, detailed risk analysis than the current rule mandates (HHS fact sheet). DSPM maps directly onto this requirement: continuous discovery and classification produce the up-to-date data inventory a risk analysis depends on, while access and exposure monitoring generate the audit trail OCR investigators actually ask for when a breach happens.

A practical framework: putting DSPM to work in healthcare

  1. Discover everywhere PHI can hide. Scan structured databases, unstructured file shares, cloud storage, SaaS apps, and backups — not just the systems already known to hold patient data. Shadow copies created during "quick" analytics or AI projects are one of the most common exposure patterns healthcare teams find once they look (Cyera Research Labs).

  2. Classify by sensitivity and regulatory category. Distinguish PHI from general PII and payment data so remediation can be prioritized by actual regulatory exposure, not just by data volume.

  3. Map access and flag over-permissioning. Identify which users, service accounts, and third-party integrations can reach PHI, and right-size entitlements — a step Cyera specifically calls out for minimizing "blast radius" from compromised or duplicate identities (Cyera).

  4. Feed findings directly into your HIPAA risk analysis. Use the DSPM inventory as the evidentiary backbone of your Security Rule risk analysis, since OCR settlements consistently trace back to analyses that didn't cover all e-PHI locations (National Law Review).

  5. Automate remediation, not just alerts. Static visibility reports go stale fast; the more effective deployments pair discovery with automated policy enforcement — revoking excess access, flagging plaintext exposure, and quarantining risky shares (Forcepoint).

  6. Re-scan continuously. New EHR modules, research datasets, and AI pilots create new PHI locations constantly; treat DSPM as a running process, not a one-time audit.

Healthcare-specific considerations

Healthcare's regulatory exposure is layered: HIPAA's Security Rule requires the risk analysis and technical safeguards above, but breach notification timing (60-day requirement), Business Associate Agreement obligations, and state-level health data laws all sit on top of it (Securiti). Business associates and third-party software are a disproportionate source of exposure — the 192.7-million-record Change Healthcare breach is the starkest recent example of how concentrated third-party risk in healthcare has become (DeepStrike). Clinical and research environments also generate PHI outside typical EHR boundaries — imaging systems, lab platforms, and research data lakes — which is why DSPM tools built for healthcare specifically emphasize coverage of PACS, EHR exports, and SaaS collaboration tools alongside the core patient record systems (Cyera datasheet).

A quick checklist

  • Do you know every system — cloud, database, SaaS, research environment — where PHI currently lives, including copies created for analytics or AI projects?

  • Could your current data inventory serve as evidence in a HIPAA Security Rule risk analysis today, without weeks of manual reconciliation?

  • Have you identified which users, service accounts, and third-party vendors are over-permissioned to access PHI?

  • Is PHI discovery continuous, or does it rely on a periodic manual audit that goes stale between reviews?

  • If OCR opened an investigation tomorrow, could you produce a current, defensible map of where e-PHI resides and who can reach it?

The bottom line

Healthcare's breach costs, breach volume, and OCR enforcement actions all point to the same root cause: organizations don't have a current, accurate picture of where their PHI actually lives, and HIPAA's Security Rule explicitly requires that picture as the foundation of a compliant risk analysis. DSPM exists to close exactly that gap — continuous discovery and classification across cloud, database, and SaaS environments, feeding directly into access governance and audit-ready compliance evidence.

C² Data Privacy Platform discovers sensitive and shadow PHI across cloud, database, and SaaS environments, and masks or de-identifies it automatically before it reaches test, analytics, or AI workflows. Book a demo to see it run against your own schema.

Sources: National Law Review — "OCR Targets Risk Analysis Gaps in 2025 HIPAA Settlements", Palo Alto Networks — DSPM Market Size: 2026 Guide, Microsoft — What Is Data Security Posture Management (DSPM)?, IBM — What is Data Security Posture Management (DSPM)?, Cloud Security Alliance — Top Takeaways from the Gartner Report: DSPM, Varonis — What is Data Security Posture Management (DSPM)?, Palo Alto Networks — 2026 DSPM Adoption Report, IBM — Hidden Risk: Shadow Data and AI Drive Higher Breach Costs, TechTarget — Healthcare remains costliest industry for breaches at $7.42M, TechTarget — 2025: Double the breaches, but less patient data compromised, BrightDefense — 60+ Healthcare Data Breach Statistics for 2026, TechTarget — Shadow AI in healthcare: The hidden risk to data security, Knowi — Healthcare Analytics Statistics 2026, DeepStrike — Healthcare Cybersecurity Statistics 2026, Securiti — Why DSPM is Critical: Key Differences from DLP & CNAPP, Concentric AI — What Is DSPM?, Forcepoint — Best DSPM Solutions in 2026, Cyera — Data Security Solutions for Healthcare Services, BigID — HIPAA Compliance, Techclick — Wiz DSPM: Sensitive-Data Discovery, Classification, Varonis — Regional Healthcare System Case Study, Securiti — How DSPM Streamlines Compliance with GDPR, CCPA/CPRA, HIPAA, HHS — Guidance on Risk Analysis, HHS — HIPAA Security Rule NPRM Fact Sheet, Cyera Research Labs — Top Tactics to Reduce Data Risk in Healthcare, Cyera — Healthcare Industry Datasheet, C² Data Technology.