Despite the intense training and constant warnings, it happens constantly. And that’s just the cases they know about and address.
You have to be able to trust your staff, but you also have to be realistic that any organization at scale will have people who either don’t care or don’t think and it happens frequently.
1) Prevent the patients from suing after a data breach or intentional sale of their medical records, regardless of negligence.
2) Transfer as much money as possible from health care to privately owned businesses in the compliance industry.
Very few computer security lessons from that industry generalize to other parts of the economy.
This isn't the same as leaving a tool in someone; making and misplacing a screencap take active doing. If your meeting participants actively want to put data where it doesn't belong, the solution isn't accident prevention
It's essentially a guardrail. It can be easily circumvented if someone was being actively malicious.
Many people are babies.