This would be a HIPAA violation. Accessing records without a clinical or operational reason constitutes unauthorized access. EHR access is audited. Use this as a teaching moment about the minimum necessary standard.
This is the correct response. Accessing a patient's medical record without a legitimate clinical or operational reason is a HIPAA violation, regardless of the accessor's role or access level. The PMHNP should clearly explain that EHR access is restricted to legitimate clinical or operational purposes, the minimum necessary standard requires limiting access to what is needed for one's job function, EHR systems maintain audit trails that track who accesses what records and when, unauthorized access can result in disciplinary action, termination, fines, and criminal charges, and curiosity is not a legitimate reason for accessing medical records. This is an important teaching moment for a student learning professional responsibilities.