HIPAA doesn't stop at the firewall.
Most breach spending goes toward hacking and ransomware — and should. But a steady share of reportable healthcare breaches every year is simpler than that: someone on staff looked at, took, or mishandled records they had no reason to touch. That's not a technical failure. It's a program gap.
The regulator publishes what goes wrong. Insider misuse is a fixture, not an outlier.
HHS's Office for Civil Rights (OCR) has published every large healthcare breach since 2009. The pattern holds year over year: most incidents are external hacking, but a persistent share is workforce members doing something they shouldn't — and OCR treats that as seriously as an outside attack.
large healthcare data breaches (500+ records) reported to HHS OCR in a typical recent year — each one now part of the public record.
of reported healthcare breaches fall under “Unauthorized Access/Disclosure” — workforce snooping, misuse, and insider misdirection, distinct from outside hacking.
is the maximum window under the HIPAA Breach Notification Rule to report a breach of unsecured PHI to HHS and affected individuals.
It's rarely a hacker. It's usually someone with a badge.
Across the breaches OCR categorizes as unauthorized access or disclosure, the pattern repeats across practices of every size.
Record snooping
A staff member looks up a coworker, an ex-partner, or a public figure's chart out of curiosity — not treatment. The access is technically valid and the log shows nothing wrong until someone asks why.
Access that outlives the job
A departing employee's EHR credentials stay active past their last day, or they export patient lists on the way out. Small practices are the most exposed here — offboarding is rarely formalized.
Shared logins, broad access
Front-desk and clinical staff share a login “just for today,” or everyone has access to the full record instead of what their role requires. Convenience quietly becomes exposure.
A rushed disclosure under pressure
A stressed or overloaded staffer sends records to the wrong recipient, or skips a verification step to move faster. The behavior precedes the mistake — and it's visible beforehand.
Practices with real risk and no one dedicated to watching it.
Medical, dental, mental health, and addiction treatment practices
Independent and small-group practices handling protected health information every day — without a dedicated compliance or security officer. The practice manager already owns scheduling, billing, and HR. Insider risk becomes the thing nobody owns until OCR asks who was supposed to.
Three ways to work together.
Same arc every time: find the gaps, train the eyes, build the program that holds.
Before the Breach
A half-day session for your practice manager, front-desk lead, and clinical staff — the precursor framework adapted to EHR access, patient interactions, and HIPAA's workforce security expectations, plus a one-page escalation plan.
Program Readiness & Gap Assessment
2–3 weeks: access review, offboarding process, documentation review, and interviews — benchmarked against the HIPAA Security Rule's administrative safeguards, with a prioritized roadmap.
Program Advisory
Ongoing advisory as staff and systems change — access reviews, refresher training, and mock-audit prep before OCR or a payer ever asks.
Curious where your practice actually stands?
A 20-minute call, no pitch. Tell me where you're exposed — I'll tell you honestly whether I can help and where I'd start.
Book a 20-minute call