Compliance rules in Google Apps: Prevent employees from emailing PII
Are you concerned about HIPAA compliance standards & preventing employees from sharing sensitive information over email? Do you need to implement a data loss prevention policy within your organization? Even with clear communication to your employees that PII such as social security numbers should not be sent over email, mistakes happen.
You can configure the DLP policy so that Gmail automatically scans all mail automatically (including attachments), and take immediate action to quarantine the message. Here’s a quick guide for doing so, courtesy of Google:
Set up a compliance rule
Click Apps > Google Apps > Gmail > Advanced settings.
In the Compliance section, hover over Content compliance, and click Compliance (appears on the right).
In the Add setting popup, enter a short description, such as Social Security Number detected.
In the Email messages to affect field, check the Outbound box to prevent emails containing SSNs from being shared outside your organization. You can also check the Internal – sending box to apply the same rule to messages sent within your organization.
In the Add expressions field, click the Down arrowand select If ANY of the following match the message.
In the Expressions category, click Add.
Click the Down arrowand select Predefined content match.
Click Predefined content match, and select United States – Social Security Number.
(Optional) Enter a Minimum match count, which is the number of SSNs that must appear in an email before an action is triggered. If you leave this as 1, then messages containing a single SSN will be detected.
(Optional) Click Confidence threshold and select High or Medium.
This indicates the likelihood that the content of the detected email meets your criteria. Some data, such as a SSN, can be detected with a high level of confidence because it has a well-defined pattern.
Click If the above expressions match..., and select Quarantine message, which allows you to check emails that have been detected.
Click Add setting > Save.
Review the Content compliance field for a summary of the new settings.
Check quarantined emails
From the Quarantine Manager, click All quarantines. This displays the list of all quarantined emails.
Click an email message to check the content.
Check the box for one or more messages and click Allow or Deny to approve or reject the message.
If you click Allow, the email is sent.
If you click Deny, the sender receives a notification by email that the message was not delivered.