Shawna works in admissions at Ultimate Medical Hospital. A new hire, Ben, has been assigned to shadow her on the job. Shawna is showing Ben how to access medical records for returning patients that have previously received care. Her phone rings; she lets Ben know that she needs to take the call from her mom. She walks out of the office. As Ben is waiting for Shawna to return, he remembers that his brother just completed full lab imaging at the hospital a few days ago and is awaiting the results. Since he has the electronic health record (EHR) system pulled up on Shawna’s computer, Ben decides to look up his brother’s results. He takes a picture of his brother’s lab reports with his phone and sends them to their mom. A few days later, Ben’s brother calls the hospital and complains that his medical information was disclosed without his permission. He was able to provide the screenshot that his brother sent, with Shawna’s employee number at the top of the screen. Shawna was suspended without pay for violating company policy and the Health Insurance Portability and Accountability Act (HIPAA). Explain one potential reason why Shawna was suspended without pay. Discuss how cybersecurity strategies can protect a patient’s information.

Suggest one recommendation to Shawna about what she could have done differently to prevent this situation.