Sep 17, 2026
News
The Breach That Wasn't a Hacker: What the University of Miami Health System Incident Teaches About Insider Threats


When medical practices think about data breaches, the mental image is usually a hacker in another country, a ransomware note on a locked screen, a phishing email that tricked someone into clicking a bad link. What's harder to picture, and easier to miss, is a trusted employee quietly looking at records they have no business seeing, for years, without anyone noticing.
That's exactly what happened at the University of Miami Health System, right here in South Florida.
What happened at UMHS. According to the breach notification, an employee accessed patient medical records between September 2022 and May 2025, a span of roughly two and a half years, when there was no legitimate clinical or business reason to do so. The access wasn't discovered until June 2025. In total, 2,928 patients were affected.
The information involved included patient names, dates of birth, medical record numbers, provider names, diagnosis and condition information, insurance information, and vaccination status. The employee did not have access to financial information or Social Security numbers, which limited the identity theft risk, but the privacy violation itself, someone looking at your child's vaccination record or a family member's diagnosis with no legitimate reason, is exactly the kind of harm HIPAA's access controls exist to prevent.
UMHS engaged a third-party firm to notify affected patients, offered credit monitoring and identity protection, and worked with law enforcement. But the more important number in this story isn't 2,928. It's two and a half years. That's how long unauthorized snooping went on before anyone reviewed the access logs closely enough to catch it.
Why this matters more for small practices, not less. It's tempting to read this and think, "that's a huge hospital system, we're an 8-person office, this doesn't apply to us." It's actually the opposite. Large health systems have compliance departments whose entire job is auditing access logs. Small and mid-sized practices in Palm Beach, Broward, and Miami-Dade counties often have none of that. If a large system with dedicated security staff can miss unauthorized access for 30 months, a small practice running on trust and a shared EMR login has essentially no way of catching it at all.
Insider incidents are also more common than most office managers assume. Unauthorized access and disclosure incidents rose again in 2025 after several years of decline, according to HIPAA Journal's breach statistics, and small practices accounted for the majority of HIPAA enforcement penalties in recent years, in part because they lack the basic access controls larger organizations take for granted.
What actually prevents this. The good news is that preventing insider snooping doesn't require enterprise security software. It requires a few specific habits and controls that most small practices simply haven't set up yet: every staff member should have their own login, since shared usernames and passwords for the EMR feel convenient but make it impossible to know who actually looked at a chart, one of the most common HIPAA gaps in small offices; access should match job function, since a front-desk scheduler doesn't need the same chart access as a clinician, and most EMR platforms, including eClinicalWorks, Athenahealth, and CareCloud, support role-based permissions, so the question is whether your practice has actually configured them that way; someone should actually review the audit logs that most EMRs generate automatically, even a simple monthly spot-check of unusual activity, like a staff member accessing a patient with a different last name and address than any family member on staff; and termination and role-change procedures need to include access removal, since a surprising number of small-practice breaches trace back to a former employee's login that was never deactivated.
The takeaway for your office. You don't need to suspect your staff of wrongdoing to put these controls in place. Most insider incidents aren't malicious, they're curiosity: looking up a neighbor, an ex, a coworker's chart. But under HIPAA, curiosity without a treatment, payment, or operations reason is still a violation, and it's still your practice's liability if it happens on your watch.
If you're not sure whether your current EMR setup has individual logins, role-based access, and any kind of audit log review in place, that's a conversation worth having with your IT provider before it becomes a notification letter you have to send.

