Skip to main content

Patient privacy

The HIPAA Privacy Rule and PHI Access Monitoring

Policies satisfy the paperwork half of the HIPAA Privacy Rule. Knowing who actually accessed PHI, and why, is the operational half most programs are missing.

August 6, 2026 3 min read By the Clinical Compliance Solutions team

The HIPAA Privacy Rule sets the terms under which protected health information may be used and disclosed: for treatment, payment, and healthcare operations, under a minimum-necessary standard, with everything else requiring authorization. Every covered entity has the policy binder to match. The harder question is operational: how do you know your workforce is actually following it?

An employee who opens a record without a work reason has made an impermissible use of PHI whether or not any policy was signed. The Privacy Rule problem most health systems actually have is not missing policies. It is missing visibility.

This article is general information, not legal advice.

The enforcement reality

When an incident surfaces, the Office for Civil Rights (OCR) does not only ask what your policy said. An investigation examines what happened, when you knew, what you did about it, and what documentation exists. Breach notification obligations run on the same clock: the longer detection takes, the worse every downstream obligation gets.

The financial math is unforgiving. The average healthcare data breach costs $9.77 million and takes 258 days to identify and contain; containing one inside 200 days saves an average of $1.39 million. Detection speed is the variable you control.

Policy tools and monitoring tools solve different halves

Healthcare compliance software, the policy-and-training category, manages the documented half: policies, attestations, workforce training, risk assessments. It is necessary but not sufficient, because none of it observes behavior.

The operational half is PHI access monitoring: a continuous audit of every access across every clinical system, scored for risk, with a documented investigation trail. That is the half that answers OCR's actual questions:

  • Who accessed this patient's record, across every system? Not just the EHR. Document management, labs, PACS, and HR systems all log PHI access, and a credible answer covers all of them. WVU Medicine consolidated exactly this: one audit across all applications instead of separate reports per system.
  • Was the access appropriate? Risk-type analysis (co-worker, self-access, household proximity, VIP, discharged employee) plus AI trained on your organization's normal patterns separates workflow from violation.
  • What did you do when it was not? Investigation records with risk summaries, breach determinations, affected demographics, safeguards, corrective actions, and notification documentation, exportable as PDF for a regulator.

That last list is the documentation Haystack iS produces on every investigation, structured so the record is audit-ready the day it is created rather than reconstructed under deadline.

Continuous beats periodic, here too

A quarterly audit of a sample of accesses satisfies almost nothing. It cannot detect an incident in progress, cannot support timely breach determination, and confirms only that on one day, one sample looked fine. Continuous monitoring inverts the posture: every access is evaluated as it happens, suspicious events surface in near real time, and the low-level violations that consume audit teams, like employees viewing their own records, get resolved automatically. At Renown Health, automating self-access follow-up through AVA freed the compliance team to focus on "preventing what could be a true OCR breach."

A practical readiness test

If OCR asked tomorrow about one patient's record, could you produce, within a day: every access to that record across all systems, the risk evaluation of each, and the documented outcome of any follow-up? If yes, your Privacy Rule program has an operational half. If no, that is the gap to close, and it closes with tooling rather than more audit hours.

Breach statistics, capabilities, and customer quotes in this article come from the Haystack iS whitepaper. Regulatory descriptions are general summaries of the HIPAA Privacy Rule and OCR enforcement practice.