Desafios
This dental insurance provider is a leading dental benefits organization serving millions of members. Operating as an association of member companies, the organization manages a complex flow of Protected Health Information (PHI),including data collected from all its member companies. The Chief Information Security Officer (CISO) is tasked with protecting this sensitive data while navigating a landscape of strict and complex regulatory requirements.
“LegacyDLP just wasn’t working for us. It was noisy, expensive, and didn’t give usconfidence that we were actually protecting member data. With Cyera and OmniDLP, we’re finally moving toward a model that’s practical and cloud-aligned. Wehave clearer visibility into where our PHI lives and how it moves, which putsus much closer to realizing a truly functional data loss prevention program.” -CISO at a dentalInsurance Provider
TheCISO describes the company as a "complicated beast." The primarychallenges are (1) maintaining regulatory compliance and (2) managingdata across different states and member companies. PHI flows through anintricate end-to-end lifecycle: from a dental claim at the provider level,through ingestion at the association, and back to regional members for claimsmanagement. Protecting this data throughout its journey is a massiveundertaking, further complicated by an environment where data grows at a"ridiculous rate," as the CISO put it.
Thecompany relied heavily on AWS but initially struggled to see where its datalived. This visibility gap was worsened by legacy Data Loss Prevention (DLP)tools that failed to meet the team's expectations. The CISO characterizedlegacy DLP as "completely ineffective" - costly, noisy, andlow-return, delivering too many false positives and requiring so much manualreview that teams spent more time investigating alerts than protecting trulysensitive data. This "noise" left the team vulnerable, especially asthe rise of agentic AI introduced new risks regarding how non-human identitiesaccess member information. The organization had to move beyond theoreticalcontrols to a system capable of handling the scale of its member footprint.
Solução
The team partnered with Cyera to design and begin early implementation of a modern data security program, with Cyera Omni DLP as a central part of the approach. The initial focus was not on immediate large-scale remediation, but on gaining accurate visibility into sensitive data and setting a clear direction for how DLP should function across the organization's cloud-centric environment. They began working toward:
- End-to-end Visibility: Better visibility into how sensitive data flows through cloud services and across its lifecycle
- Accurate Classification: More reliable identification and classification of regulated data, including PHI.
- Noise Reduction: Advancing a more effective approach to DLP, addressing historical challenges with false positives and limited efficacy
- Identity Integration: Aligning data security considerations with both human and non-human access patterns.
- AI Access Control: Treating AI as an identity so that, in the CISO's words, it "only has access to the data that it is allowed to," and monitoring those interactions accurately.
- Gaining visibility into how data moves through AWS services: The CISO explained that "by implementing this with that cloud-centric model in mind, we can use more natural AWS services to help give us visibility through our data security program into where that data ends up."
- DataWatcher Implementation: Cyera's DataWatcher team has begun engaging directly with end users to help establish the cultural and operational foundations for the mature data security program that this Dental Insurance Provider is building.
Resultados
This Dental Insurance Provider's partnership with Cyera has established the strategic foundation for a comprehensive data security program. Key achievements include:
- Better visibility into data flows across AWS cloud infrastructure, enabling security teams to understand where sensitive member information resides and how it moves through their systems.
- Strategic framework for modern DLP that overcomes the limitations of legacy DLP tools, positioning the company to prevent data exfiltration without the false positive burden that plagued previous approaches.
- Identity-centric approach to data governance that extends to AI systems, enabling the team to prepare for AI-driven workflows while maintaining appropriate controls over member data.
- Active engagement between Cyera's DataWatcher team and the organization's end users, building awareness and establishing operational practices for ongoing data security management.
- Structured approach to data security program maturity, with clear pathways for implementing remediation controls as the program evolves.
"Ithink now we're a lot closer, technology-wise, to really realizing morethorough and functional data loss prevention capability, and that's one of ourbig goals. Part of a mature data security program has to include data lossprevention." - CISO at a Dental Insurance Provider
Whether you’re modernizing DLP, preparing for agentic AI, or trying to regain control of regulated data in the cloud, Cyera provides the visibility and identity-aware controls to protect what matters. Explore Cyera’s Omni DLP
Book a Demo
.png)