HIPAA Violation: Employee Snooping in Medical Records

Response and investigation guide for unauthorized employee access to PHI

Immediate Action Required

Response Timeline

First 24 Hours

  • Isolate the employee account and revoke all access
  • Preserve all access logs and system audit trails
  • Interview the employee (with HR/legal present)
  • Document the nature and scope of unauthorized access
  • Determine which patient records were accessed
  • Review the employee's access history for patterns
  • Notify incident response leadership

48 Hours to 1 Week

  • Conduct comprehensive EHR access audit for the employee
  • Prepare detailed breach assessment documentation
  • Determine number of affected patients and dates of access
  • Assess whether this was a pattern or isolated incident
  • Consult with legal counsel regarding employee actions
  • Prepare disciplinary recommendation memo
  • Draft breach notification plan

First 30 Days

  • Conduct formal disciplinary hearing with employee
  • Issue disciplinary action or termination notice
  • Send breach notifications to affected patients
  • Provide required notification to media if applicable
  • File OCR breach report
  • Document investigation findings and recommendations
  • Implement corrective action plan

60+ Days

  • Submit OCR notification if required
  • Monitor for employee appeals or legal action
  • Implement access control and monitoring improvements
  • Provide training updates to all workforce members
  • Retain investigation files for potential subpoena
  • Follow up with affected patients as needed

Investigation Process

A thorough investigation is critical for HIPAA compliance and potential legal proceedings:

Disciplinary Actions

Your sanctions policy should define appropriate discipline for unauthorized access:

Document all decisions with business justification. Maintain consistency with prior similar incidents.

Patient Notification Requirements

Unauthorized access is presumed to be a breach requiring notification:

Prevention Measures

Frequently Asked Questions

Is employee snooping always a breach?
Yes, unauthorized access to patient records is a breach if the employee viewed or acquired PHI without a legitimate treatment, payment, or operational purpose. Even if no information was disclosed to others, the unauthorized access itself constitutes a breach under HIPAA.
What are the penalties for employee snooping?
Civil penalties range from $100 to $50,000 per violation per patient per year. Criminal penalties can include fines and imprisonment. Both the organization and individuals can face civil and criminal liability. OCR may conduct investigations and impose fines.
Do I need to report this to OCR?
Yes, unauthorized access is considered a breach and must be reported to OCR. You must also notify affected patients within 60 days. Reporting requirements depend on the number of affected patients and whether a low probability of compromise exception applies.
What disciplinary action should I take?
Appropriate discipline ranges from termination to suspension depending on severity and intent. Your sanctions policy should define clear expectations. Document all actions and maintain records for regulatory review. Consistency with prior similar incidents is important.

Build a Comprehensive Compliance Program

Prevent unauthorized access with proper security controls and monitoring.

Get Your Security Analysis