A patient books a visit. A clinician reads the chart. A payer gets the claim, a lab returns a result, a pharmacy gets the script, an analytics partner gets a de-identified extract. Before one appointment closes, that PHI has crossed a dozen systems and three or four organizations. You granted every one of those moves on purpose. The platform was built to make them happen.
That is what makes telehealth security harder than it looks. The breach does not show up as an unauthorized move. It shows up as a permitted move that fits a dangerous shape.
The controls you bought check permission, not pattern
Your security budget went to proving each access is allowed. Role-based access control decides who can open a chart. Encryption protects PHI in transit and at rest. Audit logs record who touched what. A Business Associate Agreement papers the boundary with every partner. HIPAA expects all of it, and it is the right spending. It answers one question well: was this person allowed to do this thing.
It does not answer the question that matters once the platform is doing its job. Is this pattern of movement normal for this identity.
A clinician opens forty charts in a shift. A billing service pushes claims to a payer overnight. An interoperability connection ships records to a referring practice through an approved API. A data team exports a cohort for a quality measure. Every one is allowed. Every one touches PHI. None violates a policy. The audit log stamps each as a clean, authorized event, and that is the trap. The log proves the move was permitted. It never asks whether the move belonged.
The danger is the credential that already has a key
The breach in telehealth is rarely the kicked-in door.
A clinician account, taken over through a phished session, starts reading charts for patients it never treated, in a specialty it does not practice, at a volume no single shift produces. Every chart open is authorized. The pattern is the breach.
A third-party integration, granted access through a real BAA for a real reason, starts pulling more than its job needs, on a schedule it never kept, toward a destination that is new. The permission was right. Only the behavior changed.
A departing employee with legitimate access copies a patient cohort in small, off-hours increments through an approved export path. No policy breaks. No alert fires. Each action looks like the job. The danger lives across the moves, and no single move carries it.
None of this is exotic. It is the ordinary shape of a PHI breach on a platform that works exactly as designed. It sits in a blind spot because every tool you own was built to check permission, not to read the pattern of movement across permitted actions.
Before and after both miss
Predictive tools try to catch it before. Data loss prevention writes rules in advance about what should not move. It guesses, it is wrong often, it buries the team in false alarms, and it still waves the permitted move through, because the move was permitted. You cannot write a rule against your own platform doing its job.
Forensics tries to catch it after. Logging, breach investigation, the eventual disclosure letter all reconstruct what happened once the PHI is already gone. By then the question is not whether to act. It is how many patients to notify and what to tell the Office for Civil Rights.
The pattern only resolves in the middle: at runtime, while the data is moving, on the move itself.
What a runtime view adds
This layer sits underneath the controls you already run. It does not replace them.
Hilt watches data movement at the kernel, the one vantage low enough to see a move no matter which application or integration made it. It runs metadata only by default, which counts for more in healthcare than almost anywhere. It can tell a pattern is wrong without reading the chart. Content-aware inspection is there when you want it, but it is never the cost of entry, so your most sensitive data stays exactly as private as it was.
The collector stays off the path. It watches movement instead of standing in it, on the order of 0.1% of one core and 4 to 8 MB of memory per host, single-tenant inside your own cloud. It never sits inline. It never blocks, drops, or alters traffic. PHI events never leave your account.
Each move resolves to a probabilistic, source-dependent identity. Which clinician or service. Which job behind the access. Which destination. Whether this fits what that identity normally does. When the compromised account starts reading charts outside its practice, the deviation shows up across layers at once. The job is wrong for that identity. The access is a broad read across patients with no treatment relationship. The volume does not fit a single session. Any one signal is noise. Together they are a pattern, and a pattern is a case, not an alert.
When the pattern crosses the line, Hilt responds with host-level network isolation, quarantine from the control plane, not by filtering packets inline. You get a written case in time to act, before the export finishes, in place of a disclosure letter after it does.
What it does not replace
Hilt is additive and honest about its edges. Your access controls still decide who gets in. Your encryption still protects PHI in transit and at rest. Your audit logging still satisfies the HIPAA accounting requirements, and Hilt does not stand in for it. Your BAAs still govern the legal boundary with every partner.
None of those was built to judge the behavior of movement across permitted actions, in real time, by an identity that is allowed to be there. That is the gap. It is the gap that produces most of the PHI breaches telehealth platforms actually suffer. A runtime view closes it without asking you to rip anything out.
One question to run against your stack
Ask whether your current tools can tell you what a given clinician account's data access actually did over the last four hours: resolved to the job behind it, scored against how that identity normally moves, across charts, exports, and integrations at once. If the answer is no, the permitted-move blind spot is open on your platform right now.
Telehealth lives or dies on moving PHI fast across many parties. The model that lets you do that is the same one that hides the dangerous pattern in plain sight. Seeing it is a different layer, and a quiet one to add.
If you want to see how this maps to your own data flows, the fastest path is a 30-minute technical call, engineer to engineer, walking through where PHI moves on your platform and what a runtime view of it would surface.