Policy violation

What would you recommend as a punishment for a policy violation involving removal of confidential records for a “harmless” reason like catching up on reading them at home?

Would your recommended punishment be different if the violator used them for a different purpose, perhaps using them to perform identity theft?

