Skip to main content
All playbooks
Playbook

A staff member viewed a chart they had no business viewing

Curiosity is the most common motive, and curiosity is still a HIPAA violation. There is no attacker, the staff member meant no harm, and the patient may never find out unless you tell them — which is exactly the problem.

Last reviewed: May 2026

The first hour

  1. 1Export the per-record access log for the affected chart for the last 12 months. Do not screenshot — export the underlying data (CSV with timestamps, ideally with a vendor-provided integrity hash) so chain of custody holds up.
  2. 2Confirm the user ID maps to a single named person, not a shared account. A shared account in 2026 is an OCR finding in its own right.
  3. 3Pull the staff member's full access pattern across all records for the last 30 days. One unauthorized view is a problem; a pattern is a different problem with a heavier sanction and higher reportability risk.
  4. 4Loop in the privacy officer and the staff member's direct supervisor. No one else, yet.
  5. 5Do not confront the staff member without the audit log in hand. The conversation that starts with 'we have 14 views over six weeks' produces real evidence.
  6. 6Suspend the staff member's access to the affected record (or all records, depending on scope) while the investigation runs.

Evidence to preserve

What not to delete, what to screenshot, what to log. Do this before recovery starts — most of it disappears as soon as systems are rebuilt.

  • Vendor-exported access log for the affected chart, with timestamps and integrity hash if available.
  • 30-day access pattern export for the staff member across all records.
  • Written, verbatim record of the sanction conversation, including the staff member's explanation.
  • Written four-factor breach risk assessment with the conclusion and the reasoning.
  • Copy of the practice's sanction policy, with the applied sanction documented against it.

The HIPAA breach clock

The breach-notification clock starts at discovery. Federal HHS deadline is 60 days; many states are faster.
HHS / patient (federal)
October 27, 2026
60 days from discovery
CA / FL / others
September 27, 2026
30-day state floor
NY / others
October 12, 2026
45-day state floor

Breaches affecting 500+ patients in a single state are reported to HHS and media immediately, not within 60 days. Confirm state-specific timelines with counsel.

Regulator contacts

Frequently asked

Is curiosity-driven snooping really a breach?+

Often, yes. The HHS definition of breach is access or use of PHI not permitted under the Privacy Rule, unless the four-factor risk assessment concludes a low probability that PHI was compromised. Document the four-factor analysis. If you cannot defensibly conclude 'low probability,' notify the patient within 60 days.

Do we have to fire the staff member?+

Not automatically. Low-volume curiosity often results in a written warning and re-training; repeated snooping, snooping with a personal or commercial motive, or snooping with disclosure to a third party usually results in termination. The decision is yours; the documented sanction is what protects the practice from an OCR enforcement-record finding.

Should we have break-the-glass alerts?+

Yes. Modern EHRs can alert when a staff member opens a flagged record (VIP, coworker, family, outside their care team's panel). Many small practices have the feature and have never turned it on. Detection by tipoff is luck, not strategy.

Need to walk through this with someone?

Free first call. If we're the right fit, we'll tell you. If we're not, we'll tell you that too.

This page is general guidance, not legal advice. Reading it does not create a Business Associate relationship with HackFirstAid. See scope of use.

Built by

Travis R. Barlow.

25+ years in incident response. 580+ engagements. Founder of AtlSecCon, one of Canada's longest-running security conferences. No SDR, no junior associate — you talk to the person who has run this incident before.

25+
years IR
580+
engagements
1–25
provider ICP
Scenarios we have walked practices through

Illustrative composites drawn from practitioner conversations. No patient or practice identifiers.

  • Ransomware · Friday afternoon

    Walked the office manager of an 8-provider primary-care clinic through the first three hours — who to call, what not to touch, and what the 60-day HIPAA clock meant.

  • Cyber-insurer renewal

    A 3-provider dermatology clinic pulled the playbooks, customized two pages, and the underwriter accepted the plan — instead of a $9,000 consulting engagement.

  • BEC wire-fraud attempt

    A 5-provider OB/GYN group had read the Front-Desk Email Compromise playbook the week before. Their dual-approval rule caught the wire and prevented the loss.

  • MSP handoff to physician-owner

    The HIPAA self-check produced a one-page gap list an MSP could hand to a physician-owner — no jargon translation required.

Upgrade — vCISO

Your MIPS-ready SRA — and a named owner for the 60-day clock.

Training gets your people ready and advisory is there when something breaks. When you need someone to own the program — the HIPAA Security Rule, your annual SRA, and 405(d) “reasonable security” — and be the name your OCR, cyber insurer, EHR/clearinghouse business associates, and (in Canada) your provincial health privacy commissioner can point to, that’s the HackFirstAid vCISO: a security leader on retainer. Built for the EHR/vendor ransomware event mid-clinic-day, where the breach clock starts before the schedule clears.

We own your program

Strategy, risk register, roadmap, governance, cadenced reviews, and the OCR, cyber-insurer, EHR/clearinghouse BA, and provincial privacy commissioner conversations.

Independent partners execute

DFIR, SOC, pen-testing, tooling, legal, brokerage — coordinated by your vCISO, never sold by us.

Small Practice
CA$1,800/mo
Solo & the smallest offices — quarterly cadence
Foundations
CA$3,000/mo
Managed
CA$6,500/mo
Most chosen
Embedded
CA$12,000/mo

Billed annually. Every tier includes a named vCISO, a 90-day on-ramp, and household coverage.