Skip Navigation
Protecting Patient Privacy When Health Systems Merge

Blog Post

Protecting Patient Privacy When Health Systems Merge

By Adam Rosenberg

Health systems announced 72 M&A transactions in 2024, the highest volume since 2020. That same year, breaches compromised more than 305 million patient records, a 26% increase over the prior year. Healthcare merger data privacy sits at the intersection of those two trends, and the patient privacy monitoring programs most organizations rely on weren’t designed to manage both at once.

The Privacy Exposure That Opens During a Merger

OCR complaint data spanning more than two decades consistently shows impermissible uses and disclosures of protected health information as the most frequently alleged HIPAA violation. Mergers generate the conditions that produce that violation across all three phases of a transaction:

PhasePrimary Exposure
Pre-closePHI reviewed during due diligence by parties without appropriate Business Associate Agreements (BAAs) in place
IntegrationTemporary interfaces, parallel systems, and shared service accounts multiply access paths without proportional monitoring coverage
Post-closeTransition-era permissions persist long after the systems and roles that created them are retired

None of these exposures trigger an alert on their own. A staff member carrying over-scoped permissions from a prior facility registers as an authorized user doing authorized work to any monitoring tool calibrated to the old baseline. The system has no frame of reference to recognize the access as wrong.

That gap compounds fast. 

Healthcare organizations take 279 days on average to identify and contain a breach, five weeks longer than the global cross-industry average. During those months, unauthorized users operate inside live systems, watch records update in real time, and reach progressively deeper into data as the merged organization consolidates. Once compliance teams surface the anomaly, the monitoring baseline has already absorbed the behavior as normal, which means the investigation has to work backward through a trail the system stopped questioning long ago.

What Happens to Effective PHI Access Governance When Two User Populations Combine

Effective PHI access governance requires a stable definition of normal.

Every monitoring system works by comparing current access behavior against an established baseline, which is what surfaces a staff member pulling data at unusual hours, accessing records outside their role, or looking up patients with no treatment relationship. A merger eliminates that baseline for both organizations at once.

Audit logs build a behavioral fingerprint per employee over time, capturing:

  • Which patients they typically access
  • How frequently and at what hours
  • Which record types they pull

That fingerprint is what separates routine access from abuse or credential misuse. When two organizations merge, neither fingerprint applies to the combined population. Staff from the acquired facility reach a new patient population, and their prior patterns give monitoring tools no signal about whether that new access fits their role.

The system-level problem reinforces the behavioral one. Many EHR platforms lack the granularity to restrict PHI access by role, which pushes organizations toward blanket access approvals during the transition. Reconciling incompatible EHR systems with different record structures, patient identifiers, and access hierarchies takes months, so the underdefined access state persists long after close.

During that period:

  • Staff carry permissions scoped to a patient population they no longer primarily serve
  • Monitoring tools have no reference point to flag access that doesn’t fit the new organizational reality
  • The gap between what access staff hold and what their role requires widens precisely when the ability to detect misuse narrows

Closing that gap requires reestablishing a monitoring baseline that reflects the combined organization before the two populations fully merge, not after. That reestablishment is the foundational step on which effective PHI access governance during a healthcare merger depends on.

Why Legacy Permissions Are the Hardest Blind Spot to Close

Access that someone once authorized, but that no longer reflects what the role requires, generates no alerts. It moves through the system as normal traffic. Finding it requires actively looking for it, which demands a patient privacy monitoring program calibrated to the post-merger organizational state rather than the one that existed when the permissions were granted.

This is the category of healthcare merger data privacy risk that most organizations discover late, if at all, because permissions don’t expire when a merger closes. Without automated offboarding tied to role changes, access granted under a prior organizational structure persists indefinitely.

The three categories with the highest residual risk are:

  • Transition-era access. Shared service accounts, temporary system bridges, and cross-facility access are granted to manage the integration. No one intended these to be permanent, and few organizations track them with an expiration date.
  • Inherited vendor access. BAAs must be updated to reflect the new data flows, subcontractors, and system integrations migration introduces. Existing agreements are scoped to prior organizational structures and don’t extend automatically, which leaves vendors reaching PHI in the new environment with no governing agreement covering it.
  • Acquired org gaps. Compliance failures the acquired org hadn’t addressed before close carry forward as the combined entity’s liability. The acquiring organization inherits the acquired facility’s entire access control history, including everything that no one was reviewing.

How This Looks in Practice

In February 2025, unauthorized users accessed patient data on legacy Cerner migration servers that Oracle Health hadn’t yet brought inside Oracle Cloud’s security controls. Because the new environment wasn’t monitoring those servers, no alert fired.

By the time the breach surfaced, it had reached more than 2.6 million individuals across dozens of health systems.

How Patient Privacy Monitoring Has to Change at Each Phase

Each phase of a transaction creates a distinct blind spot. The monitoring posture that protects a stable organization doesn’t address any of them.

Before the Close, Establish a Baseline While You Still Can

Due diligence examines policies and documentation, not actual access behavior. Compliance gaps in the acquired organization stay invisible until monitoring begins, and once the organizations merge, no clean separation exists between inherited exposure and what the new structure produces.

Pre-close is the only window to establish an access baseline for the acquired org before integration absorbs it. Priorities during this phase:

  • Request access logs and incident records alongside policy documents. Validate stated controls against what the logs actually show.
  • Map the acquired org’s access patterns by role and facility before combining user populations.
  • Identify which BAAs cover the data flows that will change at close, and begin updating them before PHI starts moving across organizational boundaries.
  • Document the access control gaps identified. They become the remediation roadmap for the integration period.

During Integration, Monitor Both Environments Not Just the Destination

Monitoring tools scoped to one organization have no baseline for the combined population and no visibility into the legacy environment running alongside the new one. Sequential coverage, monitoring the old system until cutover, then switching to the new one, gives the highest-risk window the least oversight.

Patient privacy monitoring must cover both environments simultaneously. During integration, the access patterns most likely to signal a problem include:

  • Staff accessing records at a prior facility with no treatment relationship in the new org
  • Legacy credentials active and in use within the new system
  • Cross-facility record lookups outside any documented care context
  • Access volume spikes during system transitions as staff navigate unfamiliar workflows

Centralizing logs across both environments before temporary systems retire is a prerequisite for detecting any of these. Access history from a legacy system that goes offline without log capture is gone permanently, and that window is the one most likely to contain the anomalies that matter.

In May 2025, OCR settled with BayCare Health System for $800,000 after a former employee’s credentials accessed patient records because BayCare never restricted or monitored that access after the employment relationship ended. Integration produces that failure mode across an entire acquired workforce at once.

After Go-Live, Treat Residual Access as a Sustained Risk

Once integration is declared complete, monitoring focus shifts to the new system while transition-era permissions from the old organizational state go unreviewed, even though the healthcare merger data privacy risk doesn’t end at go-live. 

The combined organization operates as a unified entity. However, the access structure still reflects the merger period, with permissions that no one has retired and role definitions that haven’t caught up with organizational reality.

Roughly 93% of healthcare breaches involve unauthorized access. In a recently merged organization, a significant share of that unauthorized access originates from permissions that survived the transition, access that is technically authorized but no longer appropriate for what the role requires.

The average hospital generates 60 million audit events per year. A merged organization produces more, across more systems, with no shared baseline. Post-go-live patient privacy monitoring should include:

  • Periodic access recertifications to retire permissions scoped to an organizational state that no longer exists
  • Risk assessments tied to each merger milestone and EHR upgrade, not a single post-close audit
  • Monitoring scope that explicitly covers both the legacy and destination environments until full decommissioning
  • A defined timeline for role harmonization with access reviews triggered at each milestone

PrivacyPro effectively audits system accesses, giving a merged organization the coverage it needs when anomalies can surface from either environment at any point in the post-close timeline. The integration period ends operationally before it ends from a privacy risk standpoint, and monitoring posture needs to account for that gap.

See What PrivacyPro Surfaces During an Active Integration

When an organization manages a merger, evaluates an acquisition, or consolidates EHR platforms, the healthcare merger data privacy exposure is already in motion. The PHI access governance gaps, legacy permissions, and patient privacy monitoring blind spots described here produce real breaches, OCR settlements, and notification obligations that compliance teams manage long after the deal closes.

PrivacyPro catches what standard monitoring misses during organizational change, including the access anomalies that only appear when two populations start operating as one. 

Schedule a demo to see how it works during an active integration.