Sep 17, 2026

News

Insider Threats: The Breach That Wasn't a Hacker

When medical practices think about data breaches, the mental image is usually a hacker in another country, a ransomware note on a locked screen, a phishing email that tricked someone into clicking a bad link. What's harder to picture, and easier to miss, is a trusted employee quietly looking at records they have no business seeing, for years, without anyone noticing.


That's exactly what happened at the University of Miami Health System, right here in South Florida.


What happened at UMHS. According to the breach notification, an employee accessed patient medical records between September 2022 and May 2025, a span of roughly two and a half years, when there was no legitimate clinical or business reason to do so. The access wasn't discovered until June 2025. In total, 2,928 patients were affected.


The information involved included patient names, dates of birth, medical record numbers, provider names, diagnosis and condition information, insurance information, and vaccination status. The employee did not have access to financial information or Social Security numbers, which limited the identity theft risk, but the privacy violation itself, someone looking at your child's vaccination record or a family member's diagnosis with no legitimate reason, is exactly the kind of harm HIPAA's access controls exist to prevent.


UMHS engaged a third-party firm to notify affected patients, offered credit monitoring and identity protection, and worked with law enforcement. But the more important number in this story isn't 2,928. It's two and a half years. That's how long unauthorized snooping went on before anyone reviewed the access logs closely enough to catch it.


Why this matters more for small practices, not less. It's tempting to read this and think, "that's a huge hospital system, we're an 8-person office, this doesn't apply to us." It's actually the opposite. Large health systems have compliance departments whose entire job is auditing access logs. Small and mid-sized practices in Palm Beach, Broward, and Miami-Dade counties often have none of that. If a large system with dedicated security staff can miss unauthorized access for 30 months, a small practice running on trust and a shared EMR login has essentially no way of catching it at all.


Insider incidents are also more common than most office managers assume. Unauthorized access and disclosure incidents rose again in 2025 after several years of decline, according to HIPAA Journal's breach statistics, and small practices accounted for the majority of HIPAA enforcement penalties in recent years, in part because they lack the basic access controls larger organizations take for granted.


What actually prevents this. The good news is that preventing insider snooping doesn't require enterprise security software. It requires a few specific habits and controls that most small practices simply haven't set up yet: every staff member should have their own login, since shared usernames and passwords for the EMR feel convenient but make it impossible to know who actually looked at a chart, one of the most common HIPAA gaps in small offices; access should match job function, since a front-desk scheduler doesn't need the same chart access as a clinician, and most EMR platforms, including eClinicalWorks, Athenahealth, and CareCloud, support role-based permissions, so the question is whether your practice has actually configured them that way; someone should actually review the audit logs that most EMRs generate automatically, even a simple monthly spot-check of unusual activity, like a staff member accessing a patient with a different last name and address than any family member on staff; and termination and role-change procedures need to include access removal, since a surprising number of small-practice breaches trace back to a former employee's login that was never deactivated.


The takeaway for your office. You don't need to suspect your staff of wrongdoing to put these controls in place. Most insider incidents aren't malicious, they're curiosity: looking up a neighbor, an ex, a coworker's chart. But under HIPAA, curiosity without a treatment, payment, or operations reason is still a violation, and it's still your practice's liability if it happens on your watch.


If you're not sure whether your current EMR setup has individual logins, role-based access, and any kind of audit log review in place, that's a conversation worth having with your IT provider before it becomes a notification letter you have to send.

Get expert clarity

Frequently asked questions

Can my staff use the free version of ChatGPT or Claude at work?

Yes, for tasks with no patient information at all, like drafting a generic handout or a job posting. Never for anything touching a patient’s chart or PHI, per both companies’ own consumer terms.

What is a BAA and why does it matter for AI tools?

A Business Associate Agreement is a signed contract required under HIPAA before any vendor can touch PHI on your behalf. Anthropic and OpenAI only offer BAAs on business-tier or API plans, and it must be separately executed, not assumed from a paid subscription.

Does paying for ChatGPT Plus or Claude Pro make it HIPAA-compliant?

No. Both companies state that even paid individual consumer accounts (Plus, Pro, Max) are not covered by a BAA and PHI should not be entered into them.

What should our practice do before letting staff use AI with patient information?

Confirm a business-tier account is provisioned with an executed BAA, set a written policy distinguishing PHI from non-PHI use cases, and fold AI access into your existing audit-logging and access-review process.

How does UpsiteGroup help with this?

We confirm which AI tools your staff can access, verify a BAA is actually on file (not just technically available), and manage AI access controls alongside your EHR’s existing security configuration.

Faded abstract map pattern behind the closing call to action

Build smarter systems and grow with confidence

Faded abstract map pattern behind the closing call to action

Build smarter systems and grow with confidence