Montefiore Medical Center learned in 2015 that a specific patient's medical information had been stolen. The investigation that followed found an employee had been taking and selling patient records for six months, and the OCR announced a $4.75 million settlement in February 2024 after finding the hospital system had no clear way to determine if something like that was taking place.
Then OCR Director Melanie Fontes Rainer framed the case as part of a category the sector underweights, saying that "cyber-attacks from malicious insiders are not uncommon." The Verizon 2025 Data Breach Investigations Report analyzed 1,710 healthcare incidents and attributed 30% of confirmed breaches to insiders rather than external actors.
What the OCR found at Montefiore
The findings had nothing to do with how the employee got access, because the access was legitimate. OCR cited failures to analyze and identify risks to protected health information, to monitor and safeguard activity across health information systems, and to implement policies that record and examine activity in systems containing PHI.
Without those controls the theft ran unnoticed, and Healthcare Dive reported that Montefiore could not detect the attack until years after it happened. The employee was terminated and prosecuted, the health system expanded staff training and monitoring, and the settlement carried a corrective action plan with two years of OCR oversight.
Threats involving no theft
Yakima Valley Memorial Hospital, a not-for-profit community hospital in Washington, reported a breach involving 23 security guards in its emergency department. Each used their own login credentials to access the medical records of 419 individuals, and the OCR settled the matter for $240,000 in June 2023.
Nothing was sold and nothing left the building. The finding was that the guards had no job-related reason to reach electronic protected health information at all, and that the hospital had not implemented policies preventing them from doing so. Curiosity carries the same regulatory weight as theft, because HIPAA measures whether access was permitted rather than what the person did afterward.
Sentencing follows in some cases regardless of motive. A behavioral analyst in Tennessee received 30 days in jail for accessing and taking records belonging to 300 patients.
Why detection is the recurring failure
Both settlements turned on the same gap. Neither organization had monitoring capable of distinguishing legitimate record access from illegitimate record access by someone whose credentials worked correctly.
Audit controls are a Security Rule requirement rather than a best practice, and the difficulty is volume. A hospital generates millions of access events, most of them appropriate, and identifying the handful that are not means having baselines for what normal looks like by role and department. Repeated access to VIP charts, bulk record printing, after-hours queries, and lookups of records belonging to people sharing a surname with the employee are the patterns that surface in investigations after the fact.
Paubox research on small practices found 20% keeping no email archiving or audit trail whatsoever, which removes the possibility of ever answering the question.
Where email sits in the pattern
Records reached through an EHR still have to travel somewhere to be useful to the person taking them. Personal email accounts, removable media, and personal cloud storage are the common routes, and outbound email is the one a covered entity can inspect directly.
Paubox DLP monitors outgoing messages for protected health information and can alert an administrator or hold delivery when PHI is heading somewhere it should not. The same control operates whether the sender is an employee acting deliberately, an employee making an error, or an attacker using credentials taken from someone else, because it evaluates what is leaving rather than who appears to be sending it.
Misdirected email belongs in the same category. It produces reportable breaches with no malicious intent involved, and it sits outside what access controls and training reliably prevent.
New motives for attackers
Verizon added ideology as a category to its list of insider motivations, and the timing points at the Supreme Court's decision in Dobbs v. Jackson Women's Health Organization. Records relating to reproductive health now carry potential legal consequences in some states, which creates a reason for an employee to access or disclose them that has nothing to do with money.
Financial gain still dominates, covering sale of records on criminal markets, prescription fraud, and identity theft schemes. Curiosity accounts for a substantial share of what OCR actually investigates, and it is the one most organizations underestimate because it produces no obvious loss.
What reduces the exposure
Role-based access limits what any single credential can reach, and the Yakima case turned on security guards holding access to clinical records they had no reason to open. Reviewing permissions after role changes and department transfers closes the accumulation problem, where staff keep access from previous positions indefinitely.
Logging every access to PHI and reviewing those logs is the control OCR cited in both settlements. Automated alerting on unusual patterns matters more than the logs themselves, because retrospective review finds nothing until somebody already knows to look.
Outbound inspection covers the exit. Paubox Email Suite encrypts every outbound message by default, and Paubox Archiving keeps the searchable record that an OCR investigation asks for.
Why insider cases take years to surface
Montefiore was alerted to the theft of one patient's information in 2015, and the full picture emerged only once investigators worked backward from that single report. Cybersecurity Dive noted that the health system had no capability to detect the activity while it was happening.
External attacks announce themselves through encrypted systems, ransom demands, or data appearing on a leak site. An employee opening records they are technically permitted to open generates no alert, no outage, and no external notification, which means these cases typically begin with a patient complaint, a tip, or an unrelated investigation that happens to surface the pattern. The detection window is measured in years rather than days, and the volume of records involved grows for every month the activity continues.
FAQs
Does an employee viewing records without taking them count as a breach?
Yes. HIPAA measures whether the access was permitted, so an employee opening records without a job-related reason creates a reportable breach regardless of what happens next. The Yakima settlement involved no theft or disclosure.
Why was the Montefiore settlement so much larger?
OCR cited multiple Security Rule failures covering risk analysis, system activity monitoring, and policies for recording and examining access. The employee stole and sold records over six months, and the hospital could not detect it until years afterward.
What proportion of healthcare breaches involve insiders?
The Verizon 2025 Data Breach Investigations Report attributed 30% of confirmed healthcare breaches to insiders, with 67% to external actors and 4% to partners.
How do organizations detect this kind of access?
Through audit logs combined with automated alerting on unusual patterns, covering repeated access to high-profile records, bulk printing, after-hours queries, and lookups of records belonging to people connected to the employee.
Can email security help with an insider problem?
It covers the route data takes to leave. Outbound scanning for PHI catches records heading to personal email or external addresses, whether the sender is acting deliberately, making a mistake, or using stolen credentials.
Learn more: HIPAA Compliant Email: The Definitive Guide (2026 Update) | Paubox
