Overview

A civil lawsuit filed July 23 in Kanawha Circuit Court alleges that Sarah Gross, a medical administrator employed by West Virginia University Medical Corporation, repeatedly accessed the health records of a family without authorization and used the information she obtained to gain advantage in a personal dispute with them. The plaintiffs, identified only by their initials, allege the unauthorized access spanned years and constituted a systematic violation of HIPAA's privacy protections.

‍​​​‌‍The complaint frames Gross's conduct not as a single opportunistic intrusion but as a deliberate, sustained pattern — accessing records she had no legitimate clinical or administrative reason to view, then using details drawn from those records in ways the family characterizes as coercive. The lawsuit names both Gross individually and West Virginia University Medical Corporation as defendants.

The filing raises serious questions about how the medical corporation's access controls and audit processes allowed repeated unauthorized record access to go undetected for an extended period.

‍‌​​‌‍## Key developments

Insider access at the center of the claim. The lawsuit alleges Gross used her administrative position — and the system access that came with it — to retrieve records belonging to individuals with whom she had a personal conflict. Insider misuse of this kind is distinct from external hacking: the employee is already credentialed, making detection dependent entirely on internal monitoring disciplines the employer controls.

"Weaponization" allegation elevates the harm claim. The plaintiffs allege the accessed information was not merely viewed but actively deployed against them in the context of a family dispute. ‍‌‌​‌‍That framing, if proven, would likely support claims of willful or intentional HIPAA violation — a threshold that carries higher civil and potential criminal exposure than negligent disclosure.

Institutional liability in focus. Naming West Virginia University Medical Corporation alongside the individual defendant signals that the plaintiffs intend to argue the employer bore responsibility for the conditions that made repeated unauthorized access possible. Under HIPAA, covered entities are expected to maintain access controls and audit logs sufficient to detect and deter exactly this category of insider threat.

‍‌​​​‍Identity protection through initials suggests ongoing harm concern. The plaintiffs' decision to file under initials rather than full names indicates the family regards the threat from disclosure of their health information as continuing, or at minimum that further public exposure of their identities would compound existing harm.

Industry impact

Insider threats represent a persistent and underappreciated source of healthcare data exposure. According to the Verizon Data Breach Investigations Report, insider misuse consistently accounts for a material share of healthcare breach incidents — a sector that also ranks among the most targeted by malicious actors overall. ‍‌‌​​‍HHS Office for Civil Rights enforcement data shows that workforce member access violations, including unauthorized access by employees, are a recurring basis for investigation and penalty.

The IBM Cost of a Data Breach Report has repeatedly found that healthcare breach costs are the highest of any industry, averaging over $10 million per incident in recent years. While most cost analyses focus on external attacks, insider-driven breaches carry their own financial and reputational consequences, including civil litigation exposure of the kind illustrated by this case.

‍‌​‌‌‍OCR guidance has long required covered entities to implement technical safeguards — specifically access controls and audit controls — as addressable or required implementation specifications under the HIPAA Security Rule. A breach sustained over years suggests those controls were either absent, insufficiently configured, or not reviewed with enough regularity to surface anomalous access patterns.

What this means for independent practices

Independent practices typically lack the compliance infrastructure of large health systems, which makes proactive log review and access-rights hygiene even more critical. A long-running unauthorized access pattern like the one alleged in this case is detectable through routine audit activity; the question is whether that activity is actually being performed on a schedule and by someone with the authority to act on what they find.

What would have prevented this

Role-based access controls (RBAC): Limiting each employee's record access to the patient population and functions their role legitimately requires would have reduced or eliminated Gross's ability to retrieve records of individuals unrelated to her work responsibilities.

Automated audit log monitoring with anomaly detection: Systems configured to flag access to records outside a user's normal patient panel — or access to records of individuals with no active care relationship — can surface insider misuse far faster than periodic manual review.

Separation of personal and professional relationships in system access: Covered entities should have policies requiring staff to recuse themselves from accessing records of individuals with whom they have a personal relationship, and technical controls should reinforce that policy where feasible.

Regular access-rights recertification: Periodic review — at least annually — of which employees hold access to which record sets, with supervisors attesting that access remains appropriate to current job function, reduces the accumulation of excessive or outdated permissions over time.

Clear whistleblower and patient-concern intake channels: Patients and family members who suspect their records have been accessed without cause should have a direct, documented way to report that concern. A functioning intake process creates an early-warning mechanism that audit logs alone may not provide.

Read the original at DataBreaches.net