Your electronic health record (EHR) system logs every access event, but who's actually reviewing them? After 11 NHS staff were dismissed for unlawfully accessing records of knife attack victims, and 40 staff at a Cambridgeshire hospital accessed a seriously injured child's file without legitimate reason, the question isn't whether your organization has access controls. It's whether you're enforcing them.
This checklist guides you through the technical and procedural controls needed to prevent, detect, and respond to unauthorized internal data access. Each item is designed to move you from "we have a policy" to "we can prove compliance."
Prerequisites
Before starting this checklist, confirm you have:
- Access to your EHR audit logs with at least 90 days of retention
- Current role definitions for all staff with system access
- Authority to enforce technical restrictions without needing approval from clinical leadership for every change
- A designated person responsible for reviewing access anomalies (this cannot be "everyone's job")
Access Control Checklist
1. Role-Based Access Is Enforced, Not Suggested
☐ Every user account is mapped to a specific role with defined data access scope
☐ Default access is "none" until a role is assigned
☐ Roles reflect actual job functions, not seniority
☐ You can produce a current list of who has access to what within 24 hours
What good looks like: A ward nurse can view records for patients on their ward during their shift. They cannot view records for patients in other departments, former patients, or anyone outside their current care team assignment.
2. Least-Privilege Policies Are Technically Enforced
☐ Users cannot access records outside their assigned department/ward/specialty without explicit override
☐ Override requests require documented justification before access is granted
☐ System administrators cannot view patient data as a function of their technical role
☐ Access is automatically revoked when staff move roles or leave
What good looks like: When a staff member transfers from cardiology to orthopedics, their access to cardiology records ends the day they leave, without requiring manual intervention.
3. Multi-Factor Authentication Protects All Access Points
☐ MFA is required for all remote access to patient records
☐ MFA is required for access from unmanaged devices
☐ MFA cannot be bypassed by claiming "clinical emergency" without post-access review
☐ Shared accounts do not exist (every login traces to one person)
What good looks like: A clinician accessing records from home must authenticate with password plus mobile device confirmation. If they claim they've lost their phone, temporary access requires supervisor approval and flags for audit review.
4. Real-Time Monitoring Flags Suspicious Access
☐ Your system alerts when a user accesses more than [X] records in [Y] timeframe (set thresholds based on role norms)
☐ Access to VIP, celebrity, or high-profile patient records triggers immediate review
☐ After-hours access by administrative staff generates alerts
☐ Someone receives these alerts within 24 hours and has authority to act
What good looks like: When a receptionist accesses 50 patient records in one hour (far above the normal 5-10 for appointment scheduling), the system flags it and your data governance lead investigates before the shift ends.
5. Regular Access Audits Happen on a Schedule
☐ You conduct monthly random sampling of access logs (minimum 1% of all access events)
☐ Quarterly reviews cover all access to records of staff members, their families, and local public figures
☐ Annual comprehensive audits verify role assignments still match job functions
☐ Audit findings are documented with follow-up actions assigned and tracked
What good looks like: Every quarter, you pull all instances where staff accessed records containing their own surname or address. You review each one, confirm legitimate clinical need, and document your findings. The three cases that lack justification result in immediate investigation.
6. Break-The-Glass Procedures Are Documented and Monitored
☐ Emergency access overrides are possible
☐ Every override is logged with timestamp, user, and record accessed
☐ All overrides are reviewed within 48 hours
☐ Users know that "I was curious" or "they're my neighbor" will result in disciplinary action
What good looks like: A surgeon uses emergency override to access a patient's allergy information during an urgent procedure. Within 48 hours, your audit confirms the patient was admitted to that surgeon's service that day. The override was legitimate and requires no follow-up.
7. Staff Training Includes Specific Consequences
☐ Onboarding covers what constitutes unauthorized access with concrete examples
☐ Annual refresher training includes recent cases (anonymized or public)
☐ Staff acknowledge in writing that they understand unauthorized access can result in termination, referral to the Information Commissioner's Office, and criminal prosecution
☐ Managers know how to escalate suspected violations immediately
What good looks like: New hires complete a scenario-based module where they identify which access requests are legitimate ("Can I check my daughter's vaccination record?", No. "Can I view the chart for the patient I'm about to see in clinic?", Yes). They score 100% before getting system credentials.
Common Mistakes
Treating audit logs as insurance, not intelligence. You collect them because you must, but no one reviews them until after an incident. By then, the unauthorized access has been happening for months.
Assuming clinical necessity justifies any access. A doctor's curiosity about a colleague's diagnosis is not clinical necessity. Access must be tied to direct care provision or explicit operational need.
Relying on "culture" instead of controls. Your staff may be trustworthy, but the NHS cases demonstrate that curiosity and poor judgment cross all organizations. Technical controls prevent well-meaning people from making career-ending mistakes.
Configuring alerts you can't action. If your system generates 500 alerts per day and no one has time to review them, you've built security theater, not security.
Next Steps
Start with item 4 (real-time monitoring). If you're not flagging suspicious access patterns now, you're learning about violations from the ICO instead of preventing them internally.
Then move to item 5 (regular audits). Pick one high-risk category (staff accessing their own records, after-hours administrative access, or VIP patient files) and audit it this month. Document what you find.
The technical controls in items 1-3 and 6 require IT implementation, but your data governance lead should define the requirements. Don't wait for IT to propose a solution; tell them what access model you need enforced.
Every item on this checklist has a clear done/not-done state. If you can't check the box, you have a gap. Close it before the next headline features your organization.



