Medical administrator accused of accessing patient records to gain leverage in family dispute

Overview

A lawsuit filed July 23 in Kanawha Circuit Court alleges that Sarah Gross, a medical administrator employed by West Virginia University Medical Corporation, spent years secretly accessing the private health records of a family she knew personally and using that information against them in an ongoing personal dispute. The plaintiffs, identified in court filings only by their initials, describe the conduct as deliberate, repeated, and targeted — not an accidental or incidental access event.

‍‌​‌​‍The complaint frames the alleged conduct as both a HIPAA violation and a civil tort, accusing Gross of "weaponizing" sensitive medical information in ways that caused direct harm to the family. The case is in its early stages and the allegations have not been proven in court.

The lawsuit illustrates a category of insider threat that is distinct from ransomware or external hacking: a credentialed employee using authorized system access for entirely unauthorized purposes, over an extended period, without detection.

‍​​‌‌‍## Key developments

Alleged access was sustained, not isolated. According to the complaint, the unauthorized record review did not happen once — it spanned years. That duration suggests either that audit logging was absent, that alerts were not triggered, or that flagged activity went unreviewed by the employer organization.

The harm alleged is personal, not financial. Unlike breaches where stolen records are sold or used for identity fraud, the plaintiffs allege the information was used to harm them within a private dispute. ‍​​‌‌‍This represents a use-case that technical controls alone cannot anticipate; it requires that access anomalies be reviewed regardless of whether downstream misuse is immediately apparent.

The defendant is named individually alongside the employer entity. The inclusion of WVU Medical Corporation as a named defendant signals that plaintiffs intend to argue the organization bore responsibility for the employee's conduct — whether through inadequate access controls, insufficient auditing, or failure to detect a pattern of suspicious queries.

Civil HIPAA litigation is distinct from OCR enforcement. HIPAA itself does not provide a private right of action, so plaintiffs in cases like this typically pursue state-law tort theories — invasion of privacy, negligence, intentional infliction of emotional distress — alongside statutory claims. ‍​‌​‌‍The success of those theories varies by state, and West Virginia courts will determine whether the facts here support civil liability.

Industry impact

Insider threats account for a substantial share of healthcare data breaches. The HHS Office for Civil Rights breach portal consistently shows workforce members as a recurring breach source category, separate from hacking and IT incidents. ‍​​​‌‍OCR's own enforcement guidance identifies workforce access monitoring as a required addressable specification under the HIPAA Security Rule.

The 2024 IBM Cost of a Data Breach Report found that malicious insider incidents tend to carry higher average costs than many external attack types, in part because they take longer to detect. Extended dwell time — the period between when unauthorized access begins and when it is discovered — is a central factor in both the scope of harm and the eventual liability exposure for covered entities.

‍​​​‌‍For health systems that grant broad EHR access based on job title rather than specific patient-care need, this case is a concrete example of what that access model risks. An employee with legitimate credentials to access any record in a system can, in practice, access records of people they know personally for reasons entirely unrelated to care delivery.

What this means for independent practices

When an employee accesses records for personal reasons, the employing organization typically faces scrutiny regardless of whether it had direct knowledge of the conduct. A well-documented, regularly practiced access-review program is the primary mechanism for demonstrating that a covered entity met its Security Rule obligations — and for detecting misconduct before it becomes multi-year litigation.

What would have prevented this

Role-based access controls (RBAC): Restricting EHR access to records associated with an employee's specific department, care team, or assigned patient panel limits the universe of records any one employee can reach. An administrator with no clinical relationship to a patient should encounter a permission barrier, not an open query.

Automated audit log monitoring with anomaly detection: Systems that flag statistically unusual access patterns — such as repeated queries on the same individual or access to records outside an employee's normal department — create an opportunity to catch insider misuse before it spans years rather than weeks.

Minimum necessary access reviews: Periodic review of which employees hold access to which record categories, and whether that access still reflects their current role, reduces credential creep and ensures that staff who have changed roles or responsibilities do not retain broader access than their function requires.

Privileged access monitoring: Employees in administrative roles who have elevated access to record systems benefit from closer monitoring than clinical staff, whose access patterns tend to follow predictable care-delivery workflows. Monitoring that distinguishes between routine and anomalous administrative queries adds a targeted layer of oversight.

Clear workforce sanctions policy with documented enforcement: A written sanctions policy that specifies consequences for unauthorized record access — and that can be shown to have been communicated to staff — both deters misconduct and provides documented evidence of organizational due diligence if a breach is later alleged.

Read the original at DataBreaches.net