← Back to Compliance Insights

September 5, 2026  ·  Jonah Gobah

What Do I Do If a Staff Member Accessed a Patient's Record Without Authorization?

Short answer: If a staff member accessed a patient's record without a legitimate work reason — looking up a neighbor, a family member, a coworker, or a local public figure out of curiosity — treat it as a genuine HIPAA incident requiring investigation, documentation, and likely breach notification, not as a minor internal matter to handle quietly. This is one of the most common types of HIPAA violation small practices actually face, more common in practice than external hacking incidents for many practices.

Why this happens more than practices expect

Unauthorized internal access doesn't require any malicious intent to be a real violation. It's often simple curiosity: a staff member notices a friend or acquaintance's name come through as a new patient and looks up their chart out of curiosity, with no intention of causing harm. That intent doesn't change the fact that it's an unauthorized access and disclosure under HIPAA — the rule is about whether the access was appropriate for a legitimate work purpose, not about whether harm was intended.

What to do when you discover it

1. Don't dismiss it as harmless. Even without malicious intent, unauthorized access to PHI is a real incident that needs to be treated according to your incident response plan, not handled informally as a one-on-one conversation with the staff member and nothing else.

2. Investigate the scope. Determine what specifically was accessed, how many times, over what period, and whether the information was viewed, copied, or shared further. Your audit logging (a core Security Rule requirement) is what makes this investigation possible — without it, determining scope becomes guesswork.

3. Determine whether it constitutes a reportable breach. This requires a documented risk assessment of the specific incident: was there a low probability the information was compromised, or does it rise to the level requiring notification to the patient and potentially HHS. This determination should be documented, not just assumed either way.

4. Notify the affected patient if required. If the incident meets the threshold of a reportable breach, the patient needs to be notified within the Breach Notification Rule's timelines, the same as any other type of breach.

5. Apply your documented sanctions policy. Every practice should have a written sanctions policy describing consequences for staff who violate security policies. This incident is exactly what that policy exists for, and it needs to be applied consistently, not on a case-by-case basis depending on who's involved.

6. Use it to check for broader gaps. A single instance of unauthorized snooping is also a signal worth checking against your access controls generally — did the staff member have unnecessarily broad access to have been able to view this record at all, and would tighter role-based access have prevented the opportunity in the first place.

Why documentation matters even for a "minor" incident

If this comes up during an OCR investigation or audit later, having documented that you investigated, assessed, and appropriately responded to an insider incident is a meaningful part of demonstrating an actual functioning compliance program — as opposed to a practice that only reacts to external threats and overlooks the more common internal ones.

Preventing this proactively

Beyond responding well when it happens, the better position is reducing the likelihood in the first place: role-based access limiting staff to records they actually need for their work, regular audit log review rather than only checking logs after a complaint, and training that specifically addresses this exact scenario rather than only discussing external threats like phishing.

Run the free HIPAA risk assessment →

FREE DOWNLOAD

HIPAA Security Rule Readiness Checklist

The 9-point checklist every practice needs. Delivered instantly to your inbox.

Truvidence

Ready to get your practice HIPAA compliant?

Truvidence gives you everything you need — risk assessments, policy documentation, staff training, and the Verified™ seal — without hiring a compliance consultant.

Get Started →More Articles