25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Doctor to Plead Guilty to HIPAA Privacy Violation

A former physician of Fletcher Allen Health Care in Burlington, Vermont, is due to appear before a federal judge where he is expected to plead guilty to violating patient privacy by using his position and access rights to view the medical information of a patient he was not treating.

The incident occurred in 2008, and the doctor, named as Joshua A. Welch, allegedly accessed the records of a female patient in September which whom he was having a “personal relationship”. That was until the woman discovered that he had accessed her medical records.

A complaint was filed with the hospital and an investigation was launched into the matter, with the case being referred to the State Medical Board. It was discovered that she was not the only woman the doctor had checked out. The healthcare provider discovered that Welch had accessed the medical records of 8 separate women without authorization and for no work reason for doing so.

According to a statement issued by FAHC, “The board’s investigation determined, and respondent admitted, that respondent over the course of two years accessed female patients’ medical records while working at FAHC.” The doctor received a six month suspension on his license and is no longer working for the hospital.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Instead of returning to work after the investigation was completed, the doctor decided to resign and change location, and has now moved to the Rural South West and is providing medical services to a “traditionally underserved population.”

However, that may at least temporarily come to an end. The doctor has entered into a plea deal with the U.S. Attorney’s Office and has agreed to plead guilty to the charge in exchange for a “low end sentence.” A guilty verdict can see the accused sentenced to up to a year in prison and receive a $50,000 fine.

Under the Health Insurance Portability and Accountability Act’s Privacy Rule, patients are afforded certain rights and their records must not be viewed by unauthorized individuals. Just because a physician has access to EHRs, does not mean that the person is permitted to view any patient record. Records may only be accessed by physicians involved in the treatment of their own patients, and only ever for work purposes.

The penalties for unauthorized access can be severe, especially if records are viewed and information obtained for personal gain. It is essential that the penalties for snooping are explained to all staff required to access PHI as part of their work. Ignorance of the law is not a valid defense, and training on HIPAA Rules may be enough to make some individuals think twice about accessing records that they are not authorized to view.

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist