25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Virginia Commonwealth University Health System Discovers 3-Year HIPAA Breach

For the past three years, the electronic medical records of patients of Virginia Commonwealth University Health System have been inappropriately accessed by employees of physician groups.

In total, around 2,700 individuals, many of whom were children, have had their medical records viewed and their privacy violated.

VCU Health System provides access to patients’ medical records to community physician groups and contracted vendors. Community physicians are able to share patients’ medical records with the VCU Health System to ensure continuity of care when referring patients. Contractors that provide medical equipment to patients are similarly given access to medical records.

However, VCU Health System discovered ‘an unusual pattern of accessing medical records’ in January. Further investigation revealed individuals were accessing patients’ medical records without any legitimate business reason for doing so and that records had been accessed for a period of more than three years. The first privacy breach occurred on January 3, 2014 and inappropriate access continued until January 10, 2017, when the privacy breaches were discovered. The records were accessed by a contractor and employees of some community physician groups that were partnered with Virginia Commonwealth University Health System.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The types of information accessed includes names, addresses, medical record numbers, birth dates, visit dates, health care provider names, health insurance details, medical information and some patients’ Social Security numbers.

According to a statement released by VCU Health System, the investigation did not uncover any evidence to suggest that health insurance information had been used inappropriately and no information appears to have been accessed with malicious intent.

VCU Health System determined which individuals had improperly accessed patients’ medical records and employers terminated those employees. In order to prevent similar breaches from occurring in the future, VCU Health System has implemented new safeguards to prevent inappropriate system access. All individuals impacted by the privacy breaches have been offered complimentary credit monitoring services for 12 months without charge.

The incident highlights how important it is for controls to be put in place to prevent the inappropriate accessing of medical records and for regular audits of PHI access logs to be conducted. It may not always be possible to prevent inappropriate accessing of medical records by employees, partners and business associates, but fast identification of privacy violations will allow healthcare organizations to take action to limit the harm caused.

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist