Back to Resources

When curiosity becomes misconduct

Articles

What a recent case tells health employers about privacy, governance and responding well when things go wrong

At HR in Health, we come across privacy breaches involving employees who really should know better more often than many practices might expect.

Sometimes it is a staff member checking a family member’s results. Sometimes it is a team member accessing information about a patient they know socially, out of curiosity, concern or conflict. Sometimes it is a nurse checking the medical records of a doctor, practice owner or colleague — and believe it or not, we have seen that too. Sometimes it is framed as “just checking” or “trying to help” — but in a healthcare setting, unauthorised access to patient records is a serious breach of trust.

The recent decision in Health Care Complaints Commission v Oliver [2026] NSWCATOD 25 is a particularly serious example of this problem. It involved a registered nurse who, was found guilty of professional misconduct after repeatedly accessing electronic medical records without authorisation.

In this article, we break down what happened, why the Tribunal treated the conduct so seriously, and what the case means for health employers from an HR perspective — particularly when it comes to policies, procedures, training, governance and responding appropriately when things go wrong.

What happened?

Ms Oliver was a RN who worked within NSW Health and had access to electronic medical records as part of her role. As part of her role, she had legitimate access to the electronic health records system; however, over an eight-year period, she accessed the records of a close family member on more than 120 occasions despite the individual not being her patient and there being no clinical or work-related reason connected to her duties to justify the access. She also accessed the records of a third party and her own records.

Importantly, Ms Oliver had received formal warnings, undertaken additional training, and acknowledged her employer’s code of conduct obligations during her employment, yet the conduct continued. The tribunal determined that, had she remained a registered practitioner, cancellation of her registration would have been appropriate. As she was no longer registered at the time of the proceedings, a 12-month disqualification order was imposed instead.

Ms Oliver’s explanation was that she was worried about the relative’s welfare, particularly when he was in hospital or custody, and felt unable to get information from treating teams. The Tribunal accepted that she may have cared about him and been motivated by concern. But it treated that as motive, not justification. That distinction matters. A personal concern, even a genuine one, does not authorise an employee to use their staff login to access health information. The professional obligation remains clear – health records must only be accessed where there is a proper clinical, professional or otherwise authorised reason.

The matter became more serious after a violent incident involving another person connected to the relative. Ms Oliver accessed that person’s records as well, and then passed information from those records back to her relative. That step took the conduct beyond unauthorised access and into disclosure of confidential health information about someone who was not her patient. The Tribunal regarded this as a serious breach of trust, particularly given Ms Oliver’s training, experience and the clear terms of the applicable Code of Conduct.

Why the Tribunal treated the conduct so seriously

The Tribunal focused on several aggravating features.

  • First, the access was not isolated. It occurred repeatedly over many years. This was not a one-off error, accidental click or momentary lapse in judgment. It was a sustained pattern of conduct.
  • Second, there was no clinical reason for the access. Ms Oliver was not involved in providing care to the people whose records she accessed. Her use of the system was personal, not professional.
  • Third, Ms Oliver had received training and reminders about her privacy obligations. The Tribunal considered that she knew, or ought to have known, that the conduct was wrong.
  • Fourth, the disclosure of information from another person’s record significantly increased the seriousness of the breach. Accessing information without authorisation is already serious. Passing that information on to someone else can compound the harm and expose the employer, the employee and the patient to further risk.

The Tribunal found that Ms Oliver had engaged in unsatisfactory professional conduct and that the repeated, deliberate access of electronic health records over many years was serious enough to amount to professional misconduct. It was decided that if she were still registered, her registration would have been cancelled. It also disqualified her from being registered for 12 months.

The HR issue – Privacy compliance is not just a policy document

For health employers, the case is a useful reminder that privacy obligations need to be operational, not theoretical. Most health organisations have privacy policies. Many provide induction training. Many require staff to sign a Code of Conduct. But when something goes wrong, the existence of those documents is only one part of the picture.

The more important questions are:

  • Were staff trained in a way they understood?
    It is not enough to record that an employee has completed a module or signed an acknowledgement. Training needs to make the practical boundaries clear. Staff need to understand that accessing a record without authorisation is itself a breach, even if they do not print, download, screenshot or widely share the information.
  • Were access rules clear in practical terms?
    Policies should not assume that staff will automatically translate broad privacy principles into day-to-day decisions. A good policy should say, plainly, that employees must not access records because they are curious, concerned, related to the patient, in conflict with the patient, trying to save time, or trying to help someone outside their clinical role.
  • Were contractual obligations clear and able to be relied upon?
  • Employment contracts are also part of the governance framework. HR in Health employment contract templates already contain an expanded patient records clause that addresses the type of conduct raised in this case. That clause can be referred to when setting expectations with employees, and may also be relied on during performance management, disciplinary discussions or investigations where inappropriate access to patient records is alleged.
  • Were warnings and audits followed through?
    Where an employer identifies unusual access or suspected inappropriate conduct, it needs to respond in a way that is documented, timely and proportionate. If inappropriate conduct continues, there should be a clear escalation pathway.
  • Was the organisation prepared to manage the employment, regulatory and privacy dimensions together?
    A privacy breach in healthcare may trigger multiple processes at once – an internal investigation, disciplinary action, patient or consumer communication, privacy breach assessment, regulator notification, and support for affected staff or patients. That is why privacy governance should sit across HR, practice management, clinical leadership, IT and risk — not in a silo.

Policies, procedures and training – What good governance looks like

A good privacy framework should make the expected behaviour easy to understand and the wrong behaviour difficult to rationalise. At a minimum, health employers should ensure that privacy and patient records-access policies clearly address:

  • access to family members’ records;
  • access to colleagues’ records;
  • access to doctors’, owners’ or senior leaders’ records;
  • access to records of patients known socially or personally to the employee;
  • access motivated by concern, curiosity, conflict or convenience;
  • disclosure of information to family members, friends, police, lawyers or other third parties;
  • how staff can lawfully seek information when they are also a family member, carer or patient;
  • how staff should raise concerns about another patient’s care without misusing their employee access.

Employers should also ensure these obligations are reflected consistently across employment contracts, privacy policies, codes of conduct, onboarding documents, training materials and disciplinary processes. The message to staff should be consistent: access to patient records is granted for work purposes only, and misuse of that access may result in disciplinary action, regulatory notification and professional consequences.

Training should not be treated as a one-off induction exercise. It should be repeated, scenario-based and role-specific.

Staff should be asked to apply the rules to realistic situations such as:

  • “Can I look up my mother’s results?”
  • “Can I check whether my neighbour has been admitted?”
  • “Can I look at and print out a patient’s file to prove my point about a colleague not taking good clinical notes?”
  • “Can I confirm whether a former patient has returned to the practice?”
  • “Can I look at a record of a family member that I’m estranged from to make sure they’re OK?”
  • “Can I look at a record if I am worried about someone’s safety?”
  • “Can I tell a family member what I saw in a patient’s file if I think it will help?”

These examples matter because privacy breaches often occur in ordinary human moments. The employee may not set out to cause harm. They may be worried, curious, frustrated or trying to assist. But the privacy obligation does not disappear because the motive feels understandable.

A practical way to keep this front of mind is to build patient privacy into regular team discussions. If practices do not already do this, patient privacy should be included as a standing agenda item at least quarterly. This does not need to be lengthy or complicated. It may involve discussing a short scenario, asking staff what they would do in a difficult situation, or reminding staff about their privacy obligations. Regular, practical discussion helps move privacy from an annual compliance task to part of the everyday culture of the practice.

Managing the human factor

One of the difficult features of this case is that Ms Oliver did not present as an individual trying to exploit the health system. She said she was worried about someone close to her. She felt shut out. She believed she was helping. Those motivations did not make the access lawful or professional.

That is precisely why HR, managers and clinical leaders need to be alert to the human-factor risks in healthcare privacy. Staff are often also patients, family members, carers, neighbours and community members. They may work in the same health service that treats people they know. They may feel pressure to help, to check, to reassure or to intervene.

Good governance acknowledges that these situations will arise and gives staff a safe alternative.

This case highlights that a privacy policy should not simply say “do not access records”. It should also say what to do instead. For example, staff should be directed to:

  • speak to the treating team through ordinary family communication channels;
  • ask the patient to provide consent for information sharing;
  • use formal patient enquiries or complaints pathways;
  • access personal health information through the same patient access process available to the public;
  • speak to a manager, privacy officer or HR before taking any action;
  • step away from clinical involvement where there is a personal conflict or relationship.

When things go wrong – Respond early, fairly and firmly

The Tribunal’s decision also provides lessons about response.

  • Where an employer identifies suspected unauthorised access, the response should be prompt and structured. That means preserving audit logs, identifying the scope of the access, speaking with the employee, considering whether any patients or affected individuals need to be notified, assessing whether there are privacy reporting obligations, and deciding whether disciplinary or regulatory action is required.
  • A response should also be procedurally fair. Employees should be told the concerns, given the evidence in an appropriate form, and provided an opportunity to respond. But fairness does not mean minimising the seriousness of the issue.

Repeated unauthorised access to health records is not a minor administrative error. It goes to trust, professional standards and patient confidence in the health system.

Employers should also consider whether the conduct may require notification to AHPRA or another regulator. In some cases, a privacy breach may be purely an internal disciplinary matter. In others, particularly where the conduct is repeated, deliberate, dishonest or involves disclosure of confidential information, regulatory notification may need to be considered.

The importance of documentation

From an HR perspective, documentation is critical. If a privacy concern arises, employers should document:

  • what triggered the concern;
  • what audit or system evidence was reviewed;
  • what records were accessed;
  • whether there was any clinical or operational reason for access;
  • what explanation the employee provided;
  • what policies, procedures, contract terms or training applied;
  • whether the employee had previously been warned or retrained;
  • what outcome was reached and why.

This documentation is important not only for disciplinary purposes, but also for privacy reporting, regulator engagement, insurance, patient communication and organisational learning. In many matters, the issue is not simply whether the employee breached privacy. It is whether the organisation can demonstrate that it had appropriate systems in place and responded appropriately once it became aware of the concern.

Practical steps for health employers

This case is a timely prompt to review whether privacy governance is working in practice. We encourage HR in Health members to consider:

  1. Reviewing privacy and records-access policies
    Make sure they clearly deal with family members, colleagues, doctors, owners, socially known patients, and access motivated by concern, curiosity or convenience.
  2. Checking employment contracts
    HR in Health employment contract templates already contain an expanded patient records clause that addresses the types of issues raised in this case. Members should be familiar with this clause and refer to it when setting expectations, managing concerns, or conducting performance and disciplinary discussions involving inappropriate access to patient records.
  3. Adding patient privacy to regular meeting agendas
    If patient privacy is not already a standing agenda item, include it at least quarterly. Use the opportunity to discuss short scenarios, remind staff about their obligations, and reinforce what employees should do if they are unsure whether access is appropriate.
  4. Refreshing training
    Use practical, healthcare-specific examples and test understanding. Do not rely only on annual tick-box modules.
  5. Making the “why” clear
    Staff should understand that patient trust depends on records being accessed only by those who need the information for authorised purposes.
  6. Using audit logs proactively
    Audit capability is only useful if someone reviews patterns, escalates concerns and acts on red flags.
  7. Creating clear escalation pathways
    Managers should know who to contact when they suspect inappropriate access and what immediate steps to take.
  8. Documenting warnings and follow-up action
    If an employee is warned, the employer should clearly document what they were told, what they acknowledged, and what will happen if concerns continue.
  9. Separating support from accountability
    Personal stress, family concerns, mental health issues or carer responsibilities may be relevant to support and mitigation, but they do not remove the obligation to protect patient privacy.
  10. Making lawful alternatives visible
    Staff should know how to seek information as a family member, carer or patient without misusing their work access.

The takeaway

A staff member does not need to print, screenshot, gossip or widely disclose information for a privacy breach to be serious. Opening a record without a proper reason can itself be misconduct. For HR and practice leaders, the case reinforces the importance of having the right foundations in place –  clear employment contract obligations, clear policies, practical procedures, regular and fit-for-purpose training, active audit processes, strong documentation and a response plan.

Health information is some of the most sensitive information an organisation holds. Patients trust health services not only to treat them, but to protect the story their records tell. When staff access those records for personal reasons, even caring ones, that trust is put at risk.