The audit trail showed that my credentials had been used from a workstation on the other side of the hospital. I asked IT whether they could tell me who had been logged into that computer at 4:41 that Sunday, and they said they could. The workstation belonged to a supervisor who had been promoted into my department the previous year. I hadn’t worked that Sunday, and my timecard proved I was at home. Then IT found something even stranger: my password had been reset twice without a request from me. Someone had clearly been accessing my account.
I requested the full login history for the previous six months. It showed dozens of entries under my credentials during shifts when I was either off duty or working at another station. The reports created under my name were then being used to criticize my performance. My attorney asked the hospital to preserve the audit logs before anything could be deleted. Within days, the supervisor admitted that she had been using my account because she said it was “easier” than requesting access to certain reports. But she couldn’t explain why several of those reports had been altered afterward or why they were later cited in my disciplinary file.
The hospital opened a formal investigation and removed the false documentation from my record. They also restored the shifts and opportunities I had lost because of the disciplinary write-ups. I stayed at the hospital, but I changed every credential and stopped allowing anyone to use my workstation. The birthday board still doesn’t have my name on it, and after everything that happened, I don’t think I want it there anymore. For two years I thought they had forgotten my name—I finally discovered they had remembered it well enough to use it whenever they needed someone to blame.
