Could a near death experience lead to a HIPAA violation?
The short answer: In theory, yes. This is an extreme edge case though.
How did we think this up?
Well, it started with a YouTube video.
Some Background
One of Bsquared Intel’s supporters sent us an episode of Dr. Mayim Bialik’s podcast titled “#1 Afterlife Researcher. What NDEs Reveal About Heaven | Bruce Grayson”
In the episode, Dr Bruce Grayson and Mayim Bialik talk about near death experiences/events.
What inspired the scenario we’re going to share with you in a bit was something Dr. Grayson experienced when he was in residence at a hospital when he first started out as a doctor.
Grayson was asked to see a patient in the E.R. who overdosed.
He was in the cafeteria having dinner when his beeper went off.
He dropped his fork and splashed some spaghetti on his tie. He tried to blot it off, but it only made a bigger red stain. So, Dr. Grayson decided to put on his doctor coat and rush to the E.R.
In the Emergency Room, his patient was unresponsive. He then went to talk to the roommate who brought her into the E.R., who was in the waiting room about 50 yards away, to see if he could learn about anything his patient might have taken that could have caused the overdose.
Long story short, Dr. Grayson admitted her to the ICU overnight and visited her the next day.
In that visit, the patient told him that she saw him the previous night talking to her roommate down the hall. She told him everything he asked her roommate, what they were wearing, and even brought up Dr. Grayson’s red stain on his tie.
This story is the inspiration for our scenario.
Scenario: Violating HIPAA by Near Death Experience
Let’s say Bob is sent to the E.R. and as he is admitted. He’s moved into a room there and his condition worsens. He soon becomes unresponsive.
During the time Bob is unresponsive he has an NDE. He finds himself walking behind the nurses’ station and entering peoples’ rooms looking for a doctor. While in the other rooms he can see and hear things like the patients’ names, their dates of birth, who their attending physician is, their diagnosis/prognosis, what medications they’re on, and medical history.
Bob is then successfully resuscitated and admitted to the hospital when his condition is stable.
The following day the doctor comes for a visit to see how Bob is doing.
Bob is conscious and alert. He asked the doctor what happened. He also tells the doctor that he walked behind the nurses’ station and gives him all of the medical information in detail that he remembers about the patients.
The doctors and nurses confirm the medical info and therefore Bob might have technically violated HIPAA through the unauthorized access, and disclosure, of PHI (Protected Health Information).
The questions we have:
How do you protect PHI in the event of an NDE?
How would you detect an NDE? Would this be the SOC’s or I.T. team’s responsibility? Additionally, if you’re operating on a zero trust model, is any patient that’s unresponsive considered a threat to other patient’s PHI?
How does Governance, Risk and Compliance assess risk, write policies (and enforce them) around the issues of NDEs.
How does the hospital’s cyber liability insurance carrier deal with this?
How would this be reported to the Department of Health and Human Services. And if we want to get even weirder, let’s say an NDE happens where the unresponsive patient is able to see, memorize, and recall 500+ patient records. How is that recorded in the OCR portal for breaches?
For the patient who has the NDE, and discloses the PHI to the healthcare provider, could they be criminally charged under the CFAA (or a state law) for unauthorized access of sensitive data?
What does a table top exercise or live simulation look like for this scenario?
How would this be litigated in court?
If you have answers to these questions, we’re all ears. What other questions are we missing?
Let us know in the contact form below.
If you’re unresponsive and reading this, once you’re revived tells us where you read this and what happened. You may also use the contact form below.
How Bsquared Intel Helps
Unfortunately we haven’t perfected protecting businesses that deal with sensitive info from NDEs, but in the land of the living we do have various services to protect your organization.
Your next steps:
Contact us using the form below.
And while you’re still here sign up for our newsletters. You’ll get cybersecurity/OSINT news, tips, tricks, tools, scenarios, in depth articles, our thoughts on various topics, and where appropriate, alerts/notifications on breaches or vulnerabilities.
Contact Us | Bsquared Intel
Please fill out the form below, or call 203.828.0012, to learn how Bsquared Intel can assist you.


