Anyone accessing data from this system should have an active case they are assigned to, anything else should be subject to disciplinary action just as with HIPAA. It should have tamper evident audit trails. It should not be on a whim. If emergency access is needed they have to retroactively get reviewed and approved and if it was not in line with any active investigation or assist in an active investigation again it should come under serious scrutiny with actionable consequences.
Regulation of private companies and enforcement of same aren't really the way things work in America. And even the most highly regulated companies struggle with reality practicalities of tamper evident audit trails, for example designating a subset of systems in-scope of SOX or PCI controls where such trails are required.