HIPAA: Unauthorized EHR Access Detected — Response Steps

Immediate response guide for suspicious access to patient medical records

Immediate Action Required

Response Timeline

First Hours

  • Detect the unauthorized access pattern
  • Preserve all audit logs and access records
  • Export/save the relevant log entries for investigation
  • Immediately restrict or revoke user access to EHR
  • Interview the employee
  • Document the nature and scope of access
  • Identify which patient records were accessed
  • Notify incident response leadership

First 24 Hours

  • Conduct comprehensive review of user's entire access history
  • Determine if this is pattern or isolated incident
  • Generate detailed audit report of all access
  • Assess the employee's job role and authorization scope
  • Determine if access was authorized but unusual
  • Prepare preliminary breach assessment
  • Identify number of patients whose records were accessed
  • Notify legal counsel

First 7 Days

  • Complete detailed investigation of all unauthorized access
  • Conduct formal breach assessment
  • Prepare investigation report with all findings
  • Determine if access was intentional or negligent
  • Assess what information was accessed by the employee
  • Determine notification requirements
  • Prepare disciplinary recommendation

First 30 Days

  • Conduct formal disciplinary meeting with employee
  • Issue appropriate discipline or termination
  • Send breach notifications to affected patients (if required)
  • File OCR breach report if required
  • Provide media notification if required (500+ affected)
  • Implement corrective action plan
  • Document all investigation and disciplinary actions

60+ Days

  • Submit OCR notification if required
  • Implement access control improvements
  • Provide staff training on access policies
  • Conduct regular access audits
  • Monitor for additional violations by other users
  • Retain documentation for investigations

Audit Log Analysis

EHR systems provide detailed audit logs that reveal access patterns:

Breach Assessment

Unauthorized access is presumed to be a breach unless an exception applies:

Access Revocation Procedures

Immediately limit further access:

Patient Notification

If breach assessment determines notification is required:

Disciplinary Actions

Develop consistent sanctions for unauthorized access:

Frequently Asked Questions

Is unauthorized EHR access always a breach?
Yes, unauthorized access to patient records is a breach under HIPAA unless the person had authorization for treatment, payment, or operations purposes. The access must be for a legitimate business purpose aligned with the person's job function. Snooping, curiosity, or access without a work-related reason is always unauthorized.
How do I detect unauthorized access?
EHR systems generate detailed audit logs of all access. Review these logs for access patterns that don't align with job function, such as accessing records for patients they don't treat, access outside normal business hours, access from unusual locations, or access to sensitive records they have no business purpose for.
What should I look for in audit logs?
Look for access to family members' or celebrities' records, large batch downloads, access from unusual locations or departments, after-hours access, access by staff whose job function doesn't require access to those records, or repeated access patterns outside normal treatment scope.
Can I fire someone for unauthorized access?
Yes, unauthorized access is grounds for disciplinary action up to and including termination. Document the audit logs and investigation findings thoroughly. Termination is typically appropriate for intentional or repeated violations. Consult with HR and legal on the specific circumstances before making final decisions.

Strengthen Your Access Controls

Comprehensive security assessment identifies access control gaps and monitoring weaknesses.

Get Your Security Analysis