Denver Police Caught Misusing Databases Got Light Punishments, Report Says
nytimes.com
nytimes.com
Do they not maintain proper audit logs? I work for Stack Overflow and I can't look at a user's PII without it being logged in multiple systems, do we have higher internal security than the police department?
Most likely: yes.
The other consideration is that if they were doing so under the threat of HIPAA violations, they may not have abused the information quite so casually. Jealous husband fears a slap on the wrist, he abuses the database. Jealous husband fears jail time, he possibly [hires P.I. / follows his wife / etc.].
I'm not defending them–law enforcement enjoys some protections that are arguably unconstitutional, and as such should be held to a much higher standard–but it's unproductive to examine what would have happened if the penalties were different, while simultaneously assuming that the actors would have made identical decisions based on different criteria.
And the reason that's important brings me back to my first point–built-in constraints are the only way to solve this sort of thing, which is the same reasoning the founders used to try to place constraints on American politicians.
The fact that there may be more of them does not change that they are low-lifes.
Though at a minimum https://en.wikipedia.org/wiki/Transparent_Data_Encryption should be used.
If the situation had been reversed, and that man had driven to a police officer's house to threaten him, I think that man would have been criminally charged or even shot on the spot.
"When a Colorado man thought his wife might be having an affair, he asked a Denver police officer to dig up personal details about the man he suspected. The husband then drove by his house and threatened him, according to a civilian oversight agency’s report."
You are right; I was wrong.