By QuanMed AI Research Team · Reviewed by Dr. James Harker, MD, Medical Director
Published August 26, 2026 · Updated August 26, 2026
Quick Answer
In the United States, your healthcare provider owns your medical records, but HIPAA gives you the right to access, copy, and amend them. Fitness apps, genetic testing kits, and health data brokers fall outside HIPAA entirely, meaning hundreds of companies can legally buy and sell your health information with little restriction. The EU offers much stronger rights under GDPR, including the right to erasure and data portability. A handful of US states, led by Washington and California, are beginning to close the federal gap. Protecting yourself requires proactive steps: requesting your records regularly, reviewing app privacy policies, and monitoring the HHS breach portal.
One of the most common misconceptions in healthcare is that patients own their medical records. In the United States, the physical or electronic record is the legal property of the entity that created it: the hospital, clinic, physician practice, or health system. This is a firmly established principle under state property law, and no federal statute changes it. What HIPAA does, under 45 CFR 164.524, is carve out a patient right to access, inspect, and obtain copies of the information within those records. Ownership and access are legally distinct, and conflating them can lead patients to misunderstand what remedies they actually have.
The consequences of this distinction are significant. A provider can, for example, retain your records indefinitely after your care ends, use de-identified versions of your data for research, or share information with business associates under HIPAA-compliant agreements without your active consent. You cannot demand that a hospital delete your record the way you might delete an account on a social media platform. For a deeper look at the legal mechanics of record ownership, the QuanMed guide on medical record ownership walks through the state-by-state variations and what providers are actually permitted to do with the records they hold.
The picture shifts considerably in the European Union. Under GDPR, health data is classified as a "special category" of personal data and the data subject, meaning the patient, holds substantial control rights. The regulation imposes stricter obligations on processors and controllers of health data and gives individuals tools to restrict processing in ways that have no US federal equivalent. Understanding which framework applies to your situation is the starting point for knowing what you can actually demand.
HIPAA's Privacy Rule establishes five foundational rights for patients dealing with covered entities, which include hospitals, most physician practices, health insurers, and their contracted business associates. The first and most actionable is the right to access: you can request a copy of your designated record set, and the provider must respond within 30 days. They may take one additional 30-day extension if they notify you in writing of the reason. Fees must be cost-based, meaning they cannot charge more than the actual labor, supply, and postage cost to fulfill the request.
Beyond access, patients hold the right to request amendments to records they believe are inaccurate or incomplete. The provider is not obligated to agree; they may deny the amendment if they believe the record is accurate. However, they must accept and file your written statement of disagreement alongside the original record. The right to an accounting of disclosures is a tool many patients never use: you can request a list of instances where your records were shared outside of treatment, payment, and healthcare operations for up to six years prior to your request. This accounting can surface unexpected third-party disclosures. For a thorough breakdown of each right, the HIPAA patient rights guide covers the procedural details and common provider violations to watch for.
Two additional rights are worth noting. The right to request restrictions lets you ask a provider not to share certain information with your insurer if you paid out of pocket in full for a service. The provider must honor this specific scenario, even if they can deny other restriction requests. The right to confidential communications allows you to ask that correspondence be sent to a specific address or by a specific method, which matters for survivors of domestic abuse or individuals in shared-housing situations. Filing a complaint with the HHS Office for Civil Rights is the enforcement mechanism when providers fail to honor these rights; the OCR investigates complaints and can impose civil monetary penalties.
The General Data Protection Regulation, which applies to organizations processing the data of EU residents regardless of where the organization is based, sets a markedly different standard for health data. Three articles are especially relevant for patients. Article 17 establishes the right to erasure, commonly called the right to be forgotten, allowing individuals to request deletion of their data under specific conditions, such as when the data is no longer necessary for the purpose it was collected. Article 20 provides data portability, meaning you can request your data in a structured, machine-readable format and transmit it to another controller. Article 22 prohibits purely automated decision-making with legal or similarly significant effects without explicit human review, a provision relevant as insurers and providers adopt AI-driven clinical decision tools.
For US patients, the practical relevance of GDPR is limited but growing. If you use health-related apps or platforms headquartered in the EU, or if a US company has operations serving EU customers, GDPR obligations may extend to you. More importantly, GDPR has set a global benchmark that is influencing US state legislatures. The GDPR health data rights guide explains how to exercise each right in practice, including the template requests and response timelines regulators require organizations to honor.
The contrast between HIPAA and GDPR reveals a fundamental philosophical difference. HIPAA was designed primarily to enable the flow of health information for treatment and payment while establishing a floor of privacy protections. GDPR was designed primarily to protect individual privacy and places the burden of justification on the organization that wants to process data, not on the individual who wants to protect it. Neither framework is perfect, but patients who understand both are far better positioned to navigate the international landscape of health data.
HIPAA's scope is narrower than most patients assume. The law applies to covered entities and their business associates. It does not apply to the growing ecosystem of companies that collect health-related data outside of clinical contexts. This includes consumer fitness apps, nutrition trackers, period and fertility apps, mental health platforms that are not clinical providers, genetic testing services such as 23andMe and AncestryDNA, and the data brokers who aggregate and resell data from all of these sources. The International Association of Privacy Professionals estimated in 2023 that more than 700 health data brokers operate in the United States with no specific federal oversight of their health data practices.
The consequences for patients can be severe. Research published in the BMJ in 2019 found that 19 of the top 24 health-related apps on Android shared user data with third parties, often without explicit disclosure. A 2021 study in JAMA Network Open examined 36 mental health apps and found that 33 shared data with advertisers, analytics firms, or data brokers. This information is not protected by HIPAA, so companies can use it to make inferences about insurance risk, employment fitness, or creditworthiness. The guide on apps selling your health data documents specific platforms, the types of data shared, and what disclosures, if any, appeared in their terms of service.
Wearable devices occupy a particularly ambiguous position. Data generated by Apple Watch, Fitbit, Garmin, and Oura is stored in proprietary platforms that are not covered entities. If you share data from Apple Health with a research app or a third-party service, HIPAA does not govern what that service does with it. Apple and Google have platform-level policies restricting certain uses of health data on their respective stores, but these are contractual terms between Apple or Google and the developer, not enforceable rights you hold as a user. Reviewing each app's privacy policy, not just the platform's, is essential. For context on what these brokers do with the data they acquire, see the detailed analysis in the health data selling guide.
In the absence of comprehensive federal legislation addressing consumer health data outside of HIPAA, several states have stepped in with their own frameworks. Washington State's My Health MY Data Act, signed in 2023, is the most significant. It was the first US law specifically designed to regulate consumer health data that falls outside HIPAA's scope. The law applies to entities that collect, share, or sell health data about Washington residents, and it grants consumers the right to access, correct, and delete their health data held by these entities. It also prohibits geofencing around healthcare facilities for advertising purposes, a direct response to the documented practice of serving abortion-related ads near reproductive health clinics.
California's Confidentiality of Medical Information Act predates HIPAA and, in certain respects, offers stronger protections for medical information. California also amended its Consumer Privacy Act (CCPA) via the California Privacy Rights Act (CPRA), which gives residents opt-out rights over the sale or sharing of personal information including health data collected by non-HIPAA entities. Texas passed the Texas Health Privacy Act in 2023, extending certain protections to health data held outside of clinical settings. The guide to US state-level health data rights maps the current landscape state by state, including enforcement mechanisms and pending legislation in additional states.
State laws create a patchwork that is difficult for both businesses and consumers to navigate. A company operating nationally may be subject to Washington's My Health MY Data Act for one subset of users, California's CCPA for another, and no state-specific health data law for the majority of the remaining states. For patients, practical protection requires knowing which state you reside in, which companies hold your data, and whether those companies are subject to your state's laws.
The healthcare sector is the most frequently breached industry in the United States by a significant margin. The HHS Office for Civil Rights breach notification portal, which tracks breaches affecting 500 or more individuals, recorded 725 healthcare data breaches in 2023, affecting approximately 133 million patient records. These breaches spanned hospital systems, health insurance companies, billing contractors, and health IT vendors. The Change Healthcare breach in early 2024, affecting the UnitedHealth Group subsidiary, alone disrupted claims processing for thousands of providers and potentially exposed data for tens of millions of Americans.
The IBM Security Cost of a Data Breach Report 2023 found that the average cost of a healthcare data breach was $10.93 million, the highest of any industry and more than double the cross-industry average of $4.45 million. This cost includes regulatory fines, litigation, remediation, notification expenses, and reputational damage. The underlying driver of healthcare's outsized breach costs is the sensitivity of the data: a stolen medical record contains insurance information, prescription history, diagnoses, Social Security numbers, and dates of birth, making it far more valuable on criminal markets than a compromised credit card. The guide to the healthcare data breach epidemic breaks down which types of organizations are most frequently breached and what remediation looks like for affected patients.
Patients affected by healthcare breaches face a specific risk that credit card fraud does not: medical identity theft. When a criminal uses your health information to obtain care, prescriptions, or durable medical equipment under your identity, your medical records can become contaminated with another person's diagnoses and treatment history. This can lead to dangerous clinical errors if a treating physician relies on the corrupted record. The medical identity theft guide covers how to detect contaminated records, how to request corrections, and what to document for law enforcement and your insurer.
The most direct protective step is to exercise your HIPAA access rights proactively. Request a copy of your records from each major provider annually, review them for errors or unfamiliar entries, and compare your Explanation of Benefits statements against your actual care received. Discrepancies, particularly for services you did not receive, are early warning signs of medical identity theft. You can check whether your provider has reported a breach involving your data through the HHS OCR breach portal at hhs.gov/hipaa/for-professionals/breach-notification, which lists all reported breaches affecting 500 or more individuals going back to 2009.
For apps and wearables, the primary defense is selective disclosure. Before enabling any health-related app, read its privacy policy specifically for language about data sharing with third parties, data brokers, or advertisers. Look for opt-out mechanisms and use them. On iOS, review the App Privacy section in the App Store listing for each health app, and use the Health app's privacy settings to control which apps can read or write specific data types. On Android, review permissions in settings and revoke health data access for apps that do not require it for core functionality. Deleting an account is not the same as requesting data deletion; submit a formal deletion request and ask for written confirmation.
If your data has been part of a breach, the steps are sequential: notify your insurer so they can flag your account for fraudulent claims, place a fraud alert with Equifax, Experian, and TransUnion (a fraud alert is free and lasts one year, while a credit freeze is permanent until lifted), and request copies of your medical records from any provider listed in the breach notification to check for contamination. If you believe a HIPAA-covered entity violated your rights, file a complaint with HHS OCR within 180 days of the violation. The OCR accepts complaints online and does not charge a fee. Keep copies of all correspondence, breach notifications, and requests submitted to providers or regulators.
Federal legislative activity in the health data privacy space has accelerated since 2022. The American Data Privacy and Protection Act (ADPPA), though not enacted as of this writing, would establish a national baseline for data privacy that would encompass health data outside of HIPAA's reach for the first time. Meanwhile, the FTC has increased its enforcement activity under Section 5 of the FTC Act, pursuing companies that share sensitive health data with advertisers without adequate disclosure. In 2023, the FTC took action against GoodRx for sharing prescription data with Facebook and Google without user consent, marking a significant expansion of FTC health data enforcement.
Emerging technologies complicate the regulatory picture further. Blockchain-based health record systems promise patients greater control over who accesses their data and when, with tamper-evident audit trails that outperform current EHR systems in transparency. The practical implementation of these systems, including questions of interoperability, key management, and regulatory compliance, remains at an early stage. The guide to blockchain in healthcare EHR covers the current state of these projects and what realistic timelines for mainstream adoption might look like.
AI-driven clinical tools also raise new questions about health data rights. When a predictive model trained on your historical records flags you as high risk for a condition, recommends a care pathway, or influences an insurer's coverage decision, Article 22 of GDPR provides EU residents with the right to human review of that decision. US law currently offers no equivalent protection outside of specific anti-discrimination statutes. As AI becomes embedded in clinical workflows, the gap between GDPR protections and US law will become increasingly consequential for patient outcomes and data rights alike.
In the United States, your healthcare provider legally owns the physical or digital medical record. Hospitals, clinics, and physicians retain ownership of the records they create. However, HIPAA (45 CFR 164.524) gives you a robust right to access, inspect, and obtain copies of those records. Ownership and access rights are separate legal concepts, and most patients conflate the two. The EU takes a different approach under GDPR, treating health data as belonging to the data subject with far stronger control rights including the right to erasure and data portability.
HIPAA gives patients five core rights: (1) the right to access your records, with covered entities required to respond within 30 days; (2) the right to amend records you believe are incorrect; (3) the right to an accounting of disclosures, meaning a list of who your records were shared with; (4) the right to request restrictions on how your information is used; and (5) the right to confidential communications, such as receiving correspondence at a specific address. These rights apply to covered entities including hospitals, insurers, and most providers. They do not extend to fitness apps, genetic testing services, or health data brokers.
Yes, in most US states, health apps can legally sell or share your health data. HIPAA only covers covered entities (hospitals, insurers, most clinical providers) and their business associates. Apps like period trackers, fitness platforms, nutrition diaries, and mental health tools that are not clinical providers are generally not covered entities and fall outside HIPAA. The IAPP estimated in 2023 that over 700 health data brokers operate in the US with no federal regulation. California's CMIA and Washington's My Health MY Data Act (2023) offer some state-level protection, but most Americans have limited recourse once they agree to an app's terms of service.
Submit a written request directly to your provider's medical records or health information management department. Under HIPAA, the provider must respond within 30 days (with one 30-day extension if they notify you in writing of the reason). They can charge a reasonable, cost-based fee for copies. You are entitled to receive records in the format you request, including electronic copies, if the provider maintains them electronically. If a provider refuses or delays unreasonably, file a complaint with the HHS Office for Civil Rights at hhs.gov/hipaa. Review the step-by-step QuanMed guide on requesting your records for template language and escalation paths.
Review the breach notification carefully. Covered entities are legally required to notify affected individuals within 60 days of discovering a breach. Determine whether the breached data includes your Social Security number, insurance ID, or financial details, as these enable medical identity theft. Place a fraud alert or credit freeze with the three major credit bureaus. Review your Explanation of Benefits statements for unfamiliar claims. Verify whether your provider reported the breach via the HHS OCR breach portal. If you believe your HIPAA rights were violated, file a complaint with HHS OCR. Document all correspondence in writing and keep copies.
QuanMed AI
Questions about your specific health data rights?
QuanBot draws on verified medical and legal sources to help you understand your rights under HIPAA, GDPR, and applicable state laws. Ask about how to request your records, what to do after a breach, or how specific apps handle your health data.
Ask QuanBot© 2026 QuanMed - All rights reserved