HIPAA Violation: Employee Snooping in Medical Records
Response and investigation guide for unauthorized employee access to PHI
Immediate Action Required
- Secure all evidence of the unauthorized access immediately
- Suspend or revoke the employee's system access
- Preserve EHR audit logs and access records
- Interview the employee and request written statement
- Identify all patients whose records were accessed
- Notify your legal and compliance teams
- Begin formal investigation within 24 hours
Response Timeline
First 24 Hours
- Isolate the employee account and revoke all access
- Preserve all access logs and system audit trails
- Interview the employee (with HR/legal present)
- Document the nature and scope of unauthorized access
- Determine which patient records were accessed
- Review the employee's access history for patterns
- Notify incident response leadership
48 Hours to 1 Week
- Conduct comprehensive EHR access audit for the employee
- Prepare detailed breach assessment documentation
- Determine number of affected patients and dates of access
- Assess whether this was a pattern or isolated incident
- Consult with legal counsel regarding employee actions
- Prepare disciplinary recommendation memo
- Draft breach notification plan
First 30 Days
- Conduct formal disciplinary hearing with employee
- Issue disciplinary action or termination notice
- Send breach notifications to affected patients
- Provide required notification to media if applicable
- File OCR breach report
- Document investigation findings and recommendations
- Implement corrective action plan
60+ Days
- Submit OCR notification if required
- Monitor for employee appeals or legal action
- Implement access control and monitoring improvements
- Provide training updates to all workforce members
- Retain investigation files for potential subpoena
- Follow up with affected patients as needed
Investigation Process
A thorough investigation is critical for HIPAA compliance and potential legal proceedings:
- Audit trail analysis: Determine dates, times, and specific records accessed
- Intent assessment: Evaluate whether access was for treatment purposes or purely curiosity
- Pattern identification: Check if this is a one-time incident or repeat behavior
- Documentation: Create detailed written record of all findings
- Witness interviews: Talk to colleagues who may have knowledge of behavior
- Professional conduct review: Assess against your sanctions policy
Disciplinary Actions
Your sanctions policy should define appropriate discipline for unauthorized access:
- First offense (one record): Written warning, mandatory retraining
- First offense (multiple records): Suspension or termination
- Pattern of snooping: Termination is typically appropriate
- Accessing sensitive information: Termination recommended
- Intent to harm or disclose: Termination and potential criminal referral
Document all decisions with business justification. Maintain consistency with prior similar incidents.
Patient Notification Requirements
Unauthorized access is presumed to be a breach requiring notification:
- Notification must be sent without unreasonable delay (no later than 60 days)
- Include details of what information was accessed
- Describe the circumstances of the unauthorized access
- Provide identity of the employee (optional but often done)
- Offer credit monitoring or identity protection services if appropriate
- Explain steps you're taking to prevent recurrence
Prevention Measures
- Role-based access: Limit access to only records needed for job function
- Audit monitoring: Regularly review access logs for suspicious patterns
- Alerts: Implement system alerts for unusual access patterns
- Training: Mandatory annual HIPAA training covering privacy rules
- Sanctions policy: Clear written policy on discipline for violations
- Background checks: Screen employees for trustworthiness
- Culture of compliance: Foster reporting of violations by colleagues
- Access reviews: Regular audits of who has access to what data
Frequently Asked Questions
Is employee snooping always a breach?
Yes, unauthorized access to patient records is a breach if the employee viewed or acquired PHI without a legitimate treatment, payment, or operational purpose. Even if no information was disclosed to others, the unauthorized access itself constitutes a breach under HIPAA.
What are the penalties for employee snooping?
Civil penalties range from $100 to $50,000 per violation per patient per year. Criminal penalties can include fines and imprisonment. Both the organization and individuals can face civil and criminal liability. OCR may conduct investigations and impose fines.
Do I need to report this to OCR?
Yes, unauthorized access is considered a breach and must be reported to OCR. You must also notify affected patients within 60 days. Reporting requirements depend on the number of affected patients and whether a low probability of compromise exception applies.
What disciplinary action should I take?
Appropriate discipline ranges from termination to suspension depending on severity and intent. Your sanctions policy should define clear expectations. Document all actions and maintain records for regulatory review. Consistency with prior similar incidents is important.
Build a Comprehensive Compliance Program
Prevent unauthorized access with proper security controls and monitoring.
Get Your Security Analysis