When people think about healthcare data breaches, they picture hackers. Yet some of the most common privacy violations come from inside: an employee looks up a neighbor's chart out of curiosity, checks a coworker's records, or searches for a relative admitted to the facility. Most of the time there is no malice, but it is still an impermissible access under HIPAA, and it can harm residents, damage trust and lead to penalties and discipline.
Preventing and detecting snooping requires three things: clear expectations, access that matches roles and audit logs that someone actually reviews.
Curiosity: looking at records of coworkers, family, friends or public figures
Personal motives: checking on an ex-partner, a neighbor in a dispute or a person in the news
Financial motives: selling information or using it for identity theft
Carelessness: sending information to the wrong person or leaving screens open
Departing employees: taking contact lists, reports or files on the way out
Most incidents fall in the first and fourth categories, which is why education and visibility are so effective.
Start with a plain statement that every access to a resident's record is logged, and that staff may access only the information required for their jobs. Include this in:
New hire orientation and annual training
Confidentiality agreements
A login banner on key systems
Sanctions policy, which the HIPAA Security Rule requires you to apply to workforce members who violate policies
Use real-world, anonymized examples, and make clear that looking up a friend is not harmless.
As discussed in the minimum necessary standard, access should align with role and unit. Where your EHR allows, consider:
Restricting access to the staff assigned to a resident or unit
Requiring a reason when staff open a record outside their normal assignment, often called break-the-glass
Extra protection for employee records and those of high-profile individuals
Most EHRs and file systems log who viewed or changed what, and when. The logs only help when reviewed. Build a routine:
Access to employees' own records and those of other staff
Access to the records of residents outside a user's assigned unit
Users with unusually high numbers of chart views
Access after hours or when the user was not scheduled to work
Records opened for a very short time across many residents, which can indicate browsing
Record exports and printing
Periodically select a sample of users and review their activity for plausibility. Predictable review schedules are easy to avoid, so vary them.
Where supported, set automatic alerts for high-risk patterns, such as access to a flagged record.
When a review reveals suspicious access:
Preserve the logs and any related evidence
Involve the privacy officer and HR
Interview the employee fairly and document their explanation
Determine whether the access was permissible
If not, perform the breach risk assessment and notify as required
Apply sanctions consistently, regardless of seniority
Remind the workforce of expectations without naming the individual
Inconsistent discipline damages the credibility of the whole program.
When an employee gives notice, consider reviewing their recent access and downloads, limiting access to what is needed for the remaining time and disabling accounts on their last day. Collect devices and remove access to shared files and cloud storage.
Staff should know that logs exist and are reviewed. Monitoring is not about distrust; it protects residents and also protects honest employees from false accusations by providing facts.
Audit programs work best when employees understand that they protect everyone. Honest employees benefit when logs can show that they did not access a record they are accused of viewing. Frame the program as part of caring for residents and respecting their privacy, not as a search for wrongdoing, and invite questions at training sessions.
A small facility can start with a monthly review of two or three reports, taking an hour or so. UnityCare IT can help configure audit reports in your systems, set up alerts and create a review routine that your privacy officer can run without becoming a full-time analyst.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034