Electronic Health Records (EHRs) improve the quality and efficiency of healthcare but introduce risks of unauthorised access, especially for sensitive conditions such as HIV. In Namibia, limited cybersecurity capacity increases these risks in public hospitals like Grootfontein State Hospital. This study develops a machine learning approach to detect unauthorised access to HIV patient EHRs in a low-resource setting. A mixed-methods design was used, combining healthcare worker insights with a synthetic dataset that replicates realistic access patterns without exposing real patient data. Four models—Logistic Regression, Support Vector Machine, Random Forest and Extreme Gradient Boosting—were evaluated using accuracy, precision, recall and F1-score. The Random Forest model achieved the best performance, with 79% accuracy and 65% recall. The findings show that lightweight, context-aware ML models can improve EHR security monitoring and support data protection in resource-constrained healthcare environments.