TL:DR: Never just pull a card at random from HQ when you access
So, recently, I've been experimenting in my local meta when playing as Corp. If a Runner is running on HQ, and I have an Agenda in there, I shuffle that Agenda to the bottom of my hand as I present. So far, after over 25 games, it has been stolen a single time.
In addition to this, I've looked to study my opponent's access patterns. Do they usually go for the middle card, or the top card? When they play Legwork, how do they access cards then? Based on this, I change how I shuffle my HQ to keep it safe. We humans are creatures of patterns, and if you know to look for them, you can exploit them.
Basically, I've been assuming the style of a cheater. Manipulating Agendas, feeding runners Snares, and never getting my Caprices trashed from hand. This to see just how far a skilled cheat can exploit this hole in the rules.
(Context and disclaimer: I have a background in card magic. I know how to manipulate and track cards through shuffles, while making it look entirely normal. I never use these skills in any games. Cheating is deplorable and is what ruins everything I love about games. I attempt to teach people common ways they can be cheated so that we, as a community can get rid of it.)
So I entreat the community, PLEASE use an independent randomizing system such as dice or an RNG on your phone when picking accesses from HQ. I have tested this, and just pulling cards from HQ, even after a shuffle, is dangerously exploitable. Random accesses are supposed to be RANDOM, but if I can feed you my Snares 3 times in a row (this has also happened), it's no longer random.
Also, an entreaty to FFG: please change the rules regarding random HQ accesses. Because as it stands now, I haven't cheated. And that is wrong.