News
Aesto Health AWS Breach Hits HHS Portal at 9.54 Million Patients Across 30 Provider Clients, Including Everside Health · Data BreachTheGentlemen Ransomware Group Threatens Nutex Health's 27-Hospital Network; Class Action Filed Days After SEC Disclosure · Data BreachOCR Settles with California Eye Care Provider Azul Vision for Failure to Provide Timely Patient Record Access — 55th Right of Access Enforcement Action · OCR EnforcementShinyHunters Claims Leak of 7.1 Million Baxter International Salesforce Records Including Patient PII · Data BreachCareCloud EHR Vendor Breach Exposes Medical and Financial Data of 345,000 Patients · Data BreachOptalis Management Solutions and Other HIPAA-Regulated Entities Disclose Patient Data Breaches Affecting Thousands · Data BreachFive Small Healthcare Organizations Disclose Patient Data Breaches: Family Medical Associates of Raleigh, Arkansas Oral & Maxillofacial Surgeons, Alpine Agency of the Midlands, Princeton Family Eye Care, and Others · Data BreachAesto Health AWS Breach Hits HHS Portal at 9.54 Million Patients Across 30 Provider Clients, Including Everside Health · Data BreachTheGentlemen Ransomware Group Threatens Nutex Health's 27-Hospital Network; Class Action Filed Days After SEC Disclosure · Data BreachOCR Settles with California Eye Care Provider Azul Vision for Failure to Provide Timely Patient Record Access — 55th Right of Access Enforcement Action · OCR EnforcementShinyHunters Claims Leak of 7.1 Million Baxter International Salesforce Records Including Patient PII · Data BreachCareCloud EHR Vendor Breach Exposes Medical and Financial Data of 345,000 Patients · Data BreachOptalis Management Solutions and Other HIPAA-Regulated Entities Disclose Patient Data Breaches Affecting Thousands · Data BreachFive Small Healthcare Organizations Disclose Patient Data Breaches: Family Medical Associates of Raleigh, Arkansas Oral & Maxillofacial Surgeons, Alpine Agency of the Midlands, Princeton Family Eye Care, and Others · Data Breach

I saw a coworker looking at patient records they shouldn't be

This is an internal HIPAA violation. You have an obligation to report it.

  1. 1

    Do not confront the coworker directly

    This is not your job. Confronting them could create workplace conflict and may compromise any investigation.

  2. 2

    Report it to your privacy officer or manager

    Tell your supervisor or privacy officer what you saw, when it happened, and which patient records were involved if you know. You are protected from retaliation for reporting.

  3. 3

    Write down what you saw while it's fresh

    Note the date, time, what you observed, and any details. Your manager will need this for any investigation.

  4. 4

    Let your privacy officer handle the rest

    They will investigate, determine whether a breach occurred, and decide on appropriate disciplinary action and next steps.

Important

HIPAA prohibits retaliation against employees who report violations in good faith. If you experience retaliation, document it and contact HHS.

Related

Not legal advice. Follow your organization's policies and consult counsel for legal questions.