HIPAA: Unauthorized EHR Access Detected — Response Steps
Immediate response guide for suspicious access to patient medical records
Immediate Action Required
- Preserve all audit log evidence of the unauthorized access
- Immediately revoke or restrict the user's EHR access
- Isolate the user account to prevent further access
- Document the access incidents with timestamps and details
- Identify which patient records were accessed
- Interview the employee and request written statement
- Notify compliance, IT security, and legal teams
Response Timeline
First Hours
- Detect the unauthorized access pattern
- Preserve all audit logs and access records
- Export/save the relevant log entries for investigation
- Immediately restrict or revoke user access to EHR
- Interview the employee
- Document the nature and scope of access
- Identify which patient records were accessed
- Notify incident response leadership
First 24 Hours
- Conduct comprehensive review of user's entire access history
- Determine if this is pattern or isolated incident
- Generate detailed audit report of all access
- Assess the employee's job role and authorization scope
- Determine if access was authorized but unusual
- Prepare preliminary breach assessment
- Identify number of patients whose records were accessed
- Notify legal counsel
First 7 Days
- Complete detailed investigation of all unauthorized access
- Conduct formal breach assessment
- Prepare investigation report with all findings
- Determine if access was intentional or negligent
- Assess what information was accessed by the employee
- Determine notification requirements
- Prepare disciplinary recommendation
First 30 Days
- Conduct formal disciplinary meeting with employee
- Issue appropriate discipline or termination
- Send breach notifications to affected patients (if required)
- File OCR breach report if required
- Provide media notification if required (500+ affected)
- Implement corrective action plan
- Document all investigation and disciplinary actions
60+ Days
- Submit OCR notification if required
- Implement access control improvements
- Provide staff training on access policies
- Conduct regular access audits
- Monitor for additional violations by other users
- Retain documentation for investigations
Audit Log Analysis
EHR systems provide detailed audit logs that reveal access patterns:
- Review user history: Pull complete access history for the user during the relevant timeframe
- Access patterns: Look for access outside their normal job function or treatment team
- Batch access: Note if user accessed multiple unrelated records
- Timing: Flag access outside normal business hours or shift times
- Location: Identify access from unusual locations or departments
- Record types: Look for access to sensitive information (mental health, substance abuse, etc.)
- Related parties: Check if access patterns show accessing family members' or celebrities' records
Breach Assessment
Unauthorized access is presumed to be a breach unless an exception applies:
- Presumption: Assume data was accessed if logs show access occurred
- Authorization determination: Did the person have a business purpose (treatment, payment, operations)?
- Scope of access: What information was actually viewed or extracted?
- Intent: Was this accidental or intentional unauthorized access?
- Disclosure: Did the information get disclosed to unauthorized parties?
- Low probability exception: Rare - only if you can show data was not actually accessed despite log entries
Access Revocation Procedures
Immediately limit further access:
- Disable user's EHR credentials immediately
- Revoke all system access and credentials
- Disable VPN access if applicable
- Change any shared credentials the user may have access to
- Review and restrict third-party integrations using their credentials
- Notify all systems where the user had access
- Document the time and method of access revocation
Patient Notification
If breach assessment determines notification is required:
- Notify affected patients within 60 days of discovery
- Include explanation of what happened and when
- Describe what information was accessed
- Provide information about the disciplinary action taken
- Offer credit monitoring if applicable
- Provide steps for patients to protect themselves
- Include your contact information for questions
Disciplinary Actions
Develop consistent sanctions for unauthorized access:
- Accidental/minor: Written warning, mandatory retraining, increased monitoring
- Intentional snooping: Suspension or termination
- Pattern of violations: Termination required
- Intent to disclose: Termination and potential criminal referral
- Access to sensitive information: Termination appropriate
- Document decisions: Keep detailed record of investigation and discipline
Frequently Asked Questions
Is unauthorized EHR access always a breach?
Yes, unauthorized access to patient records is a breach under HIPAA unless the person had authorization for treatment, payment, or operations purposes. The access must be for a legitimate business purpose aligned with the person's job function. Snooping, curiosity, or access without a work-related reason is always unauthorized.
How do I detect unauthorized access?
EHR systems generate detailed audit logs of all access. Review these logs for access patterns that don't align with job function, such as accessing records for patients they don't treat, access outside normal business hours, access from unusual locations, or access to sensitive records they have no business purpose for.
What should I look for in audit logs?
Look for access to family members' or celebrities' records, large batch downloads, access from unusual locations or departments, after-hours access, access by staff whose job function doesn't require access to those records, or repeated access patterns outside normal treatment scope.
Can I fire someone for unauthorized access?
Yes, unauthorized access is grounds for disciplinary action up to and including termination. Document the audit logs and investigation findings thoroughly. Termination is typically appropriate for intentional or repeated violations. Consult with HR and legal on the specific circumstances before making final decisions.
Strengthen Your Access Controls
Comprehensive security assessment identifies access control gaps and monitoring weaknesses.
Get Your Security Analysis