Ok, I can see how you would consider this off topic. And I have not ever seen the journals until you brought it up.
So I will explain.
She was using the computer to do something that didn't directly relate to her job function. I assume that the hospital didn't give employees outside web mail addresses. People pass around emails all the time, "Check out this cool screensaver." It is done everywhere and IT is what keeps me busy. Now, this doesn't make her at fault on her own. Who knows she probably could not read her email at home for the same reason. But the major post above argue points about reading running programs and such and having administrator rights.. By the way you can run a program from a website without admin rights and it runs right out of the temp folder. Then it is a matter of time before the program infects other users. But you can't get some stupid web portal or remote SSL desktop connection to work correctly without it. And there are a lot of database client programs running around that require administrator rights, because they must have read/write access to the systemroot or systemprograms folders. Where does MYSQL and MSSQL install the database by default? C:\Programs files\.... it is hard to get IE settings to work for every user without manually doing it as that user.
Quote from the article "That points to a security failing at that hospital, but then they aren't that different from 99 percent of companies out there,"
Sorry: very frustrating. As an admin you are expected to provide security. But if you block to much or won't give out passwords you are an over protective administrator. You run a risk of being locked up, fired, sued, etc.. I could bitch for hours and hours. I could say something supportive of MS VISTA but then I know I would be a troll. Which would be funny as I refused to use it, and refuse to use IE unless I have too.
Personally $33,000.00 is light, the medical professional could loose her job and the hospital is at risk. "3 Wrongs"