The company I work has a large database of medical records that don't belong to them meaning they do not have permission from the patient or the facility to maintain these records. Is this a HIPAA violation? When I asked them about it they told me that because the records were sent to them in error they needed to hang on to the records. I would think they need to destroy the records not keep them in a database accessible to employees.