I don't believe them.
We had a similar situation at work... turns out the Compliance Officer found out some of our employees were sharing their passwords. We are all medical professionals who are all within limits to see the information shared, but we were all forced to change our passwords if we were the actual offenders or not.
Here, when an employee leaves their email and all accounts are terminated immediately. (I work for a health care provider with over 500 employees and only 5 are computer admins but they still manage to do all of this)
The way I understand it, no matter who is ALLOWED to view the information isn't the issue... its how you obtain it. Using YOUR sign on information should NOT be allowed...though I'm not sure if my experience is actual HIPPA or my company holds higher standards (I doubt it!

) If they have permission to view/use the info, why don't they have their own sign on? They shouldn't need yours...
google HIPPA - they have a website that may help you get to the bottom of this.