Go back

Health Benefits Company Ensures Compliance, Reduces ATO Risk, and Protects 1.3M+ Sensitive Messages

See how a leading health benefits company secured PHI in email and sailed through HITRUST R2 and SOC 2 Type II, all with zero employee complaints.

m read
“It's like a security system at your house. You don’t need it until you need it. It’s there, it’s not impactful day-to-day, and that’s exactly the point.”
CIO
CIO
CIO
“Do the POC with Material. The numbers speak loudly and will tell you how much sensitive data is sitting in your mailboxes that you don't know about.”
CIO
CIO
CIO
“I knew there was a problem, but I didn’t know there was a solution. I don’t think there is any other solution in the market today that can do what Material does.”
CIO
CIO
CIO
CIO
industry
Healthcare
Book a Demo
1.3M+ sensitive messages locked and protected over 11 months
570,000 sensitive messages detected across employee inboxes
8,907 health records specifically identified (2% of all sensitive messages)
Key Results

The Challenge: PHI in inboxes

With thousands of employees and a business built around sensitive health data, this company is a prime target for email-based threats. The company handles a significant volume of Protected Health Information (PHI) every day, with much of it flowing through employee inboxes. As a health benefits company, patient data routinely arrives via email before being routed into systems of record, leaving sensitive records sitting in mailboxes across the organization. This information can be radioactive: the average cost of a healthcare breach is $9.8million, including forensic investigation, legal review of every exposed message, individual notification, credit monitoring, and the lengthy litigation process.

The company’s Chief Information Officer was all too aware of the security risk associated with email data at rest. Email was often just a transient vessel (data came in, got downloaded, and was imported elsewhere), but that didn't mean the risk disappeared. The PHI remained accessible in those inboxes.

The challenge was compounded by the company’s history. The company was formed from a merger of several organizations, each with its own Microsoft 365 tenant and email retention policies. Consolidating those environments meant inheriting a sprawling, inconsistent data estate with sensitive content scattered across inboxes at scale.

The Solution: Detect and protect sensitive data

After seeing Material’s CEO Abhishek Agrawal deliver a ten-minute demo at an executive roundtable event, the CIO immediately requested a follow-up call and a proof of concept was quickly underway.

The POC was the turning point. Seeing that one third of employee inboxes contained patient information made the need undeniable. Material was the clear choice to protect this information, ensure compliance, and avoid the costly fines that come when a healthcare company is involved in a breach.

The company deployed Material Security's Account Takeover Resilience (ATOR) product, with the email redaction feature as a centerpiece. The configuration was straightforward: 

  • The security team chose a one-week grace period before sensitive messages are automatically locked, calibrated to match how the company uses email as a pass-through for PHI that gets imported into downstream systems.
  • Step-up verification is required to retrieve any locked message, ensuring that access to sensitive content is always intentional and logged.
  • In addition to redacting sensitive information, Material also provided protection for applications that use email to verify user identity. Messages like password resets and sign-up confirmations are commonly used by attackers as pivot points into other systems. Material automatically redacts these messages, requiring step-up authentication and blocking lateral movement.

Change management was built into the rollout from day one. The security team created a Microsoft Teams channel to support employees during the initial launch, then handed off ongoing education to the IT service desk. Critically, the team made Material part of new hire orientation, using it as an early signal to new employees that the company takes data protection seriously.

The Results: 1.3 million sensitive messages protected

The numbers tell a clear story. Since deployment, Material Security has processed and protected an enormous volume of sensitive data across the company’s environment:

  • 1.3M+ sensitive messages locked and protected over 11 months
  • 570,000 sensitive messages detected across employee inboxes
  • 8,907 health records specifically identified (2% of all sensitive messages)
  • 57,542 password reset and sign-up confirmations surfaced across 77 services
  • 30,000 messages locked in a single week, with just 682 retrieval requests

Beyond the volume metrics, the impact on the company’s compliance posture has been significant. In 2025, the company achieved both HITRUST R2 and SOC 2 Type II certifications. The email protections provided by Material made that process notably smoother. Audit evidence around email security was one of the easiest areas to document.

The operational reality is equally telling. 30,000 messages were locked in a single week. Only 682 were retrieved. That ratio reflects a system working exactly as intended: protecting sensitive content at scale while generating almost no friction for the people who need access to it.

Privacy Preference Center

By clicking “Accept”, you agree to the storing of cookies on your device to enhance site navigation, analyze site usage, and assist in our marketing efforts. View our Privacy Policy for more information.

New