The physician had accessed the hospital’s EHR system and viewed patient records without a valid clinical reasoning, according to a Feb. 28 breach notification from Asante.
An investigation found that he had accessed records from June 12, 2014, and Jan. 3, 2023.
Asante did not say how many patients were affected, but said the files included patients’ names, demographic information, and diagnostic and treatment information.
Asante does not believe any of the information accessed by the physician has been misused as he accessed the records “out of curiosity.” However, Asante said it has terminated his access to the EHR system and reported him to the Oregon Medical Board.
The hospital said it is working on implementing additional security measures to detect when there is inappropriate access to medical information by authorized users.
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.