Thanks again for your replies.
I figured out a work around (read hack

) but if I leave the album folder where it is in the html part of the server, then set the full path to it in $conf['album_folder'] and set it as an 'external' path, I can then place a .htaccess file in the album folder that then completely locks out direct URL to the files in it. Something like below which is what I took from the Gallery data folder:
DirectoryIndex .htaccess
SetHandler Gallery_Security_Do_Not_Remove
Options None
<IfModule mod_rewrite.c>
RewriteEngine off
</IfModule>
Order allow,deny
Deny from all
This still leaves the cache folder exposed of course. I'm not quite sure why you say there needs to be access to the cache with direct urls files since this solution works for items in the album folder, wouldn't it work for the cache too? And Gallery seems to use all it's albums and cache data from a folder protected this way.
I could change the name of the cache folder to something random which would effectively hide it I believe.