Skip to main content

Patient privacy

Medical Record Snooping: The Insider Risk Every EHR Carries

Curiosity-driven record access is a HIPAA violation regardless of intent. The patterns snooping follows, and how privacy teams detect it at scale.

August 6, 2026 3 min read By the Clinical Compliance Solutions team

A celebrity is admitted and curiosity gets the better of a dozen employees. Elsewhere in the building, someone looks up a neighbor, an ex, or the parent of their child's classmate. None of these people consider themselves data thieves, and every one of them just committed the same violation: snooping.

Snooping matters because it is a HIPAA violation regardless of intent, and each incident can lead to an OCR investigation, breach notification obligations, and lasting reputational damage. With the average healthcare breach now costing $9.77 million and taking 258 days to identify and contain, "we didn't know" is an expensive posture.

The patterns snooping follows

Snooping is not random. It follows relationships, and relationships leave patterns a monitoring platform can detect:

  • Co-worker access. Same facility, same unit, or known relationships between the user and the patient. A classic trigger for a look that has no clinical justification.
  • Same household or same street. Geographic proximity between user and patient is a snooping signal that mature platforms map directly.
  • VIP and confidential patients. High-profile admissions reliably produce access spikes. Watchlisting these patients ahead of time turns a scramble into a routine review.
  • Patient-is-employee. Records of colleagues attract views, especially after visible events like an injury at work.
  • Family and holiday spikes. Renown Health found snooping seasonal enough to plan for: "If we see a spike in say family snooping around the holidays, we can schedule educational sessions 30 days or 90 days out to avoid that spike."
  • Discharged-employee access. A departing staff member reading records on the way out the door is snooping's uglier cousin and a standard risk type in its own right.

Why it goes unseen

Individually, a snooping event is one row in millions. A large system generates thousands of users touching thousands of records daily, across the EHR, document management, labs, PACS, and more, each with its own audit log. Manual review cannot keep up, and traditional tools that flag every unusual-looking access bury the real cases in false positives.

The consequence: most snooping is discovered reactively, when a patient complains or a story circulates, long after the damage is done.

How detection works at scale

Modern patient privacy monitoring platforms consolidate every system's audit trail into one event list and score each access against the organization's learned patterns. In Haystack iS, the Solomon Engines AI assigns each event a Risk Index built from the specific risk types detected, so a same-street co-worker access to a watchlisted patient scores far above workflow noise.

Investigation then leans on context: every record the user touched that day, every user who touched the patient's record, geographic proximity mapping, watchlist status, and full investigation history, all in one place. Follow-up is automated: AVA contacts the employee with a targeted questionnaire, evaluates the response, re-scores the event, and escalates or closes it by rule.

Deterrence is the quiet payoff

The strongest argument for systematic monitoring is what happens to behavior once staff know it exists. When every PHI interaction is monitored and abnormal access is instantly detectable, casual curiosity stops feeling casual. The monitoring program itself becomes the deterrent, and a culture of compliance replaces a culture of "nobody will notice."

That, plus proactive training timed to predicted spikes, is how privacy teams get ahead of snooping instead of cleaning up after it.

Risk types, capabilities, and quotes in this article come from the Haystack iS whitepaper.