Case Scenarios: Accessing records for the right reason

The following scenarios are designed to help nurses better understand the principle of access in the Confidentiality and Privacy – Personal Health Information practice standard. They highlight common situations where nurses may question whether it is appropriate to view a client’s health record and reinforce that access must be authorized, connected to the nurse’s role and limited to the information needed to provide care or fulfill an authorized purpose.


Scenario 1: Accessing a client’s health record for educational purposes

Accessing a client's record because a condition is of interest, uncommon or educational is not an authorized reason for access. Unauthorized viewing of personal health information ("snooping") is considered a privacy breach and may result in a report being sent to CNO and/or the Office of the Information and Privacy Commissioner (IPC) of Ontario. Nurses should seek educational opportunities that do not require accessing identifiable client records when they are not involved in the client's care.

Scenario 2: Accessing records before the client is transferred

It is appropriate to access a client’s record only when there is an authorized, care-related purpose connected to the nurse’s role. If a transfer is only possible and the client has not yet been assigned to the nurse, access may not be appropriate. Once the nurse is assigned to provide or assist with the client’s care, they may only access the information needed to prepare for and provide safe nursing care.

Scenario 3: Accessing records for personal relationships 

Scenario 4: Accessing a record without a care-related purpose

Even if information is easy to access in an electronic record system, nurses should only access information that is necessary for providing care or carrying out authorized duties. Curiosity, personal interest or familiarity with the client do not constitute an authorized purpose. Access should be limited to the minimum amount of information required to provide nursing care.

Scenario 5: Accessing records for a chart audit

A nurse may access client records for a chart audit when the access is authorized by the organization and connected to a permitted purpose, such as quality improvement or auditing. Access should be limited to the least amount of personal health information needed to complete the audit, and only information relevant to the audit should be reviewed. If unrelated clinical details are not needed for the audit purpose, the nurse should not continue reviewing them out of curiosity or for general learning. Nurses should also follow employer policies for audits, documentation, shared systems and privacy safeguards, and report any suspected or known privacy breach according to organizational processes.