Skip to content

The Effectiveness of Email Alerting on Reducing Employees' Unauthorized Access to Protected Health Information

Effectiveness of Email Alerting on Reducing Hospital Employees' Unauthorized Access to Protected Health Information: A Nonrandomized Controlled Trial

Status
Completed
Phases
NA
Study type
Interventional
Source
ClinicalTrials.gov
Registry ID
NCT05251844
Enrollment
444
Registered
2022-02-23
Start date
2018-01-01
Completion date
2021-09-30
Last updated
2022-02-23

For informational purposes only — not medical advice. Sourced from public registries and may not reflect the latest updates. Terms

Conditions

Unauthorized Data Access

Brief summary

To assess the effectiveness of email warnings on reducing repeated unauthorized access to Protected Health Information (PHI), a randomized trial was conducted in a large academic medical center to understand the effectiveness of email warning on reducing repeated unauthorized access to PHI.

Detailed description

From January 1, 2018, to July 31, 2018, a large academic medical center's PHI access monitoring system flagged all unauthorized accesses to patient electronic medical records from 444 employees (all professional medical staff), who were not part of the patient's intervention team and did not have access permission. 219 employees (49%) were randomly selected to receive an email warning on the night of their access, while the remaining employees (225, 51%) served as controls. The email informed that the employee has had been identified as having accessed a patient's electronic medical record without a known work-related purpose and that unauthorized access is a privacy violation. A sample email was attached at the end of the protocol. The system tracked all these individuals' violations within the sample period. Later on, all cases with the violators' ID and patients' ID fully de-identified (see the following excerpt as examples) were shared with researchers at John Hopkins and Michigan State for data analyses. Because researchers do not have the ability to link the data with an identifier, the study was exempted from Michigan State University's IRB review. Violator ID Patient ID Date Intervention 01B1NSYX3CEXZ86UZXU7R9JQ4VEK R7Z8RTZQL4B9IAC13F6EXQJVWAI7 1/2/2018 No Email 01B1NSYX3CEXZ86UZXU7R9JQ4VEK R7Z8RTZQL4B9IAC13F6EXQJVWAI7 1/3/2018 No Email

Interventions

OTHERreceiving an email

The email informed that the employee has had been identified as having accessed a patient's electronic medical record without a known work-related purpose and that unauthorized access is a privacy violation.

Sponsors

Protenus, Inc.
Lead SponsorINDUSTRY

Study design

Allocation
RANDOMIZED
Intervention model
PARALLEL
Primary purpose
OTHER
Masking
QUADRUPLE (Subject, Caregiver, Investigator, Outcomes Assessor)

Masking description

all violators' identities are masked to Protenus.

Intervention model description

one group received email notice while the group didn't

Eligibility

Sex/Gender
ALL
Healthy volunteers
No

Inclusion criteria

* violators of patients' privacy rights

Exclusion criteria

\-

Design outcomes

Primary

MeasureTime frameDescription
the number of subsequent unauthorizated access violations12 weeks starting from the first time a violation was flaggedThe investigators monitored and collected all the subsequent unauthorized access violations for both the experiment and the control group

Countries

United States

Outcome results

None listed

Source: ClinicalTrials.gov · Data processed: Feb 4, 2026