That's your classic case for rbac or uac isn't it? If they have the right to browse records then they should be able to, if they don't then they should be locked out. At its most granular would be general user, with the right to browse their own record, up to your equivalent of root with the right to browse all.