When we talk about cybersecurity, attention usually goes to outside attackers. Yet a significant share of privacy incidents in healthcare involve people who already have legitimate access. Sometimes the cause is curiosity, such as looking up a neighbor or a coworker. Sometimes it is a mistake, such as sending a document to the wrong recipient. Occasionally it is deliberate misuse, or a departing employee taking information along.
Insider risk is manageable, and the controls are mostly about clarity, visibility and fairness. Here is how to approach it.
Looking at records of residents, patients, family members or colleagues without a work reason is a violation of the minimum necessary standard and facility policy, even if nothing is done with the information. Small communities make this temptation stronger, since staff often know the people in their care.
Typing the wrong fax number, emailing a spreadsheet to the wrong person, leaving a chart open on a shared screen or losing a device. These are the most common incidents and the easiest to reduce with better workflows.
Taking resident information for identity theft, billing fraud or selling it. This is rare, but the damage can be severe.
People who leave, particularly under strained circumstances, may copy files, forward email to a personal account, or retain access that was never removed.
An attacker who steals a legitimate employee's credentials looks like an insider in your logs.
Give each role only the access needed. Review role templates periodically, and require manager approval for exceptions. The less access an account has, the less harm it can cause, whether through misuse or compromise.
Individual logins make audit logs meaningful. Shared credentials make it impossible to know who did what.
Turn on logging in your EHR and other systems that hold ePHI, and review it. The Security Rule requires audit controls and information system activity review. Practical review approaches include:
Alerts for access to records of staff members or their relatives
Reports of users who open unusually large numbers of records
Review of after-hours or off-site access
Flagging of access to high-profile or sensitive records
Tell staff that access is monitored. Awareness alone deters most snooping.
Publish a short statement of what is and is not allowed, have staff sign it at hire, and refresh it annually. The Security Rule requires a sanction policy, and consistent enforcement matters. Apply it fairly across roles.
Control where information can go. Options include blocking USB storage on workstations, restricting personal email and cloud storage on work devices, and alerts for large file transfers or auto-forwarding rules in email.
Use address book entries and confirmation steps for fax and eFax destinations
Enable warnings when emailing outside the organization
Use secure portals for sharing documents
Lock screens automatically after a short idle period
Coordinate HR and IT so access ends when employment ends:
Disable accounts at the time of departure, or before for sensitive terminations
Review recent activity for unusual downloads or forwarding rules
Retrieve devices, badges and keys
Remove the employee from shared mailboxes, vendor portals and group chats
Remind departing staff of their continuing confidentiality obligations
When a possible violation appears, involve your privacy officer and HR early. Preserve logs, interview fairly, and determine whether a breach assessment under HIPAA is required. Document the decision, the sanction and the corrective steps. Treat honest reporters well, and consider retraining for mistakes rather than automatic discipline.
People who feel respected and who understand the reasons behind the rules are far less likely to cause harm, and more likely to report problems. Leaders can reinforce this by talking openly about incidents in aggregate, without naming individuals.
UnityCare IT helps healthcare organizations enable audit logging, set up alerts and tighten access, and we can assist with reviews after an incident. If you are unsure whether anyone is looking at your access logs, we can help you build a manageable review routine.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172