The Feds Are Pushing for Unprecedented Access to Your Medical Records 

By Jennifer Oliva

You might assume that what you tell a doctor stays between you, your physician and perhaps your insurer. But the reality is more complicated.

The Health Insurance Portability and Accountability Act, the federal privacy law that governs health information and is commonly known as HIPAA, is narrower than its reputation suggests. 

It regulates hospitals, physicians, insurers and their business associates, but not the health data you generate everywhere else: not the period-tracking application on your phone, the internet search you ran about a diagnosis, the DNA you mailed to a genealogy company or the wearable that counts your heartbeats.

Even the records HIPAA does cover can be shared, sold or handed to the government in ways that might surprise you.

This gap in protection matters more than ever because the U.S. government is pushing hard to gather health data domestically and abroad. This is happening even as a growing body of research shows that the safeguard which these efforts to collect data lean on – anonymizing data by removing identifying information to make it difficult to trace back to an individual – is far weaker than officials claim.

As a professor of law at Indiana University, I study health information privacy and medical data regulation, which includes tracing how sensitive health information moves among clinics, government agencies and law enforcement. As a co-investigator on a federally funded study about opioid prescribing, I rely on health data in my own research. I appreciate its value for science, and I also see the danger of collecting it without meaningful safeguards.

Limits of Medical Privacy

HIPAA gives you several rights: You can see your health records, demand corrections and expect that a covered provider will not casually disclose your information.

But the law also permits release of some information without your consent. A hospital fully bound by HIPAA may release certain types of records without your authorization and without telling you. 

There are roughly a dozen such categories. Information about treatment, payment and routine healthcare logistics require no sign-off. Neither does information released for public health reporting, law enforcement, judicial and administrative proceedings, health plan oversight, research or the broad catchall of essential government functions.

The statute is also thick with additional exceptions. In practice, much of your health information can be shared through these many open doors. And once data is sent outside the system covered by HIPAA, the HIPAA limits fall away.

For instance, prescription drug monitoring programs, which every state now operates, assemble detailed logs of who filled which controlled substance prescription and when. Federal law enforcement can often access these logs with a self-issued administrative subpoena – an order that doesn’t require a judge’s approval or oversight.

These programs have expanded beyond opioids into a dragnet that shares health data across state lines, exposing patients who seek reproductive or gender-affirming healthcare to surveillance far from home.

Health records can flow to many destinations under different rules. A given disclosure might feel more like a violation depending on who decides where it can go and who can then see it.

RFK Jr.’s Push to Access Health Records

Since the spring of 2025, Health and Human Services Secretary Robert F. Kennedy, Jr. has sought federal access to Americans’ medical records to investigate whether vaccines cause autism. The scientific community has studied this question for decades and has shown decisively that they do not.

According to KFF Health News, HHS has been courting state health information exchanges – the little-known systems that let hospitals and clinics swap detailed, identifiable patient records – and asking how those records might be used for vaccine research. 

One proposal floated by state organizations would give HHS data on 90% of Americans’ medical records by 2028. In Nebraska, millions of federal grant dollars have flowed to a statewide health information exchange nonprofit that has cooperated with the effort.

Large health datasets can be useful. Pooled records can expose drug side effects, track outbreaks and reveal disparities in care that smaller studies miss. Public health has always depended on some surrender of individual privacy for collective benefit.

The concern is not that the government should never collect health data. It is that meaningful safeguards have not kept pace with the scale of collection and capabilities of modern data analytics.

In seeking access to Americans’ medical records for a vaccine and autism study, HHS has declined to say how many states are involved, what data it collects, who can see it or how it will be protected.

University of Maryland school of medicine professor Dr. Omer Awan fact-checks Health and Human Services Secretary Robert F. Kennedy Jr.’s claims about COVID-19, vaccines and autism.

Building a comprehensive repository to chase a question that science has already answered inverts the logic of research. Usually a hypothesis justifies the data collected, rather than the reverse.

Collecting identifiable records for tens of millions of people in a single database also creates a target for breaches, secondary uses that no one consented to and abuses by current or future administrations with different priorities.

‘Anonymized’ Health Data Doesn’t Protect Your Privacy

Officials have offered reassurances that data will be aggregated and stripped of identifiers so no individual can be singled out.

Decades of computer science research undercuts that promise. A study published in Nature in June 2026 sharpened the point, showing that in this age of artificial intelligence, stripping identifiers from patient records to protect identity does not protect all patients equally.

The researchers audited AI diagnostic models trained on clinical data, including chest X-rays, electrocardiograms and electronic health records. They asked whether an outsider could tell if a particular person’s data had been used to build the model. 

For instance, confirming that someone’s record helped train a cancer-prediction tool can reveal that that person has cancer. This exploit is known as a membership inference attack.

The research team found that while the average risk of being identified from data stripped of identifying information often looked reassuringly low, some patients faced near-certain reidentification 

The burden fell unevenly: Underrepresented groups, sorted by race, insurance status or diagnosis, were most at risk. Those most exposed were frequently already most vulnerable to discrimination.

Researchers have long established that removing identifiers from rich datasets does not reliably protect the people in them, and that identification gets easier the more information you have. Today’s AI technology makes it possible to carry out these attacks remotely and quickly.

The U.S. government’s appetite for health data does not stop at the border. As ProPublica reported in June 2026, the State Department has been conditioning lifesaving aid to African nations on access to their citizens’ health data.

Under the Trump administration’s global health plan, Uganda agreed to give the United States real-time access to nine of its health data systems for seven years, including the central repository of the nation’s health information and the system managing individual electronic medical records, in exchange for up to US$1.7 billion over five years, a sum that shrinks each year and falls below prior U.S. support. 

Kenya struck a similar deal; Zambia, Zimbabwe and Ghana walked away from the initial terms.

The U.S. government has promised that the data will be aggregated and anonymized, but privacy experts warn that the agreements are vague and omit standard limits on how much data is taken and how it can be used. A Ugandan digital rights lawyer called the choice his country faced the essence of digital colonialism: Accept the deal and risk exploitation, or refuse it and watch people die.

Domestic records collection and foreign data-for-aid deals rest on the same faith that anonymization neutralizes the risk of pooling sensitive health data.

The evidence says otherwise. This does not mean health data should never be gathered or studied, but I believe that the reassurances deserve skepticism, the safeguards deserve scrutiny, and the people whose bodies generated the data deserve a say. To safeguard privacy, a government seeking sensitive medical records should have to show why it needs them and how the safeguards it relies on hold up.

Privacy law was built for a world where data resided in filing cabinets. Governments from Kalamazoo to Kampala now operate in a world where even an anonymized digital record can point back to you.

Jennifer Oliva, JD, is a Professor of Law at Indiana University.

Oliva’s research and teaching interests include health law and policy, privacy law, evidence, torts, and complex litigation. She also serves on the Science & Policy Advisory Council of the National Pain Advocacy Center (NPAC).

This article originally appeared in The Conversation and is republished with permission.  

Is Your Personal Health Data For Sale?

By Pat Anson, PNN Editor

Many U.S. consumers believe their personal health information is protected under the Health Insurance Portability and Accountability Act (HIPPA), a federal law that requires healthcare providers and insurers not to share a patient’s sensitive health information without their consent or knowledge.

A new study on consumer data brokers and a federal complaint against a popular drug discount service show otherwise, with patient names, social security numbers, email addresses, prescription drug use and other personal information routinely being sold to third parties.

The Duke University study on data brokers focused only on mental health records, but gives you a good idea of what’s available on the open market. When researcher Joanne Kim contacted 37 data brokers asking to buy mental health data on millions of patients, 11 of them offered to sell her the requested data, which included information about whether an individual was being treated for depression, anxiety or insomnia, and if they were prescribed drugs such as Prozac or Zoloft.

The asking price for the information was relatively cheap, with one broker offering data on 10,000 aggregated patient records for $2,000 – or 20 cents per record. The cost was even cheaper if the data was ordered in volume; 435,780 records were available for 6 cents each.

Many of the brokers did not provide Kim with a full explanation about their data or where it came from, making it difficult to determine whether the company was offering “deidentified” information. Some firms openly advertised data that included individual names, addresses, phone numbers and emails. One broker even offered to sell her the IP addresses and browser history of patients.

“This research highlights a largely unregulated data brokerage ecosystem that sells sensitive mental health data in large quantities, with either vague or entirely nonexistent privacy protections,” Kim wrote in her report. “Data brokers are collecting, aggregating, analyzing, circulating, and selling sensitive mental health data on individuals. This comes as a great concern, especially since the firms seem either unaware of or loosely concerned about providing comprehensive privacy protections.”

Due to the stigma associated with mental health problems, Kim says the easy availability of personal health data puts millions of patients at risk of discrimination from employers and insurers, or even theft from scammers who prey on vulnerable populations.

“The nation is in dire need of a comprehensive federal privacy law, and this report recommends that the federal government should also consider generally banning the sale of mental health data on the open market,” she wrote. “Such a law should include provisions that allow consumers to opt out of the collection of their data, gain access to their information, and correct any discrepancies. Furthermore, data brokers should be obligated to be more transparent about their use and exchange of data, as well as have more controls in place for client management.”

One potential “client” that Kim doesn’t mention is law enforcement. In 2020, the Drug Enforcement Administration asked data brokers to submit bids on a potential contract for a surveillance program that would track at least 85% of U.S. prescriptions for opioids and other controlled substances. The DEA was seeking “unlimited access” to this prescription data, including the names of prescribers and pharmacists, types of medication, quantity, dose, refills and forms of payment.

While the contract was never awarded, it remains unclear what the DEA planned to do with the information or if it has found other ways to collect the data.

GoodRx Settlement

Where and how is personal health data collected? It could be as simple as a consumer trying to save money on medications.

The Federal Trade Commission recently reached a $1.5 million settlement with prescription drug discount provider GoodRx for failing to notify consumers that it was selling their information to Facebook, Google and other third parties for advertising purposes.

GoodRx offers considerable savings to patients who enroll in its free drug discount program, and makes money by selling their health and contact information to third parties. For example, according to the FTC complaint, GoodRx shared patient health data with Facebook, which then targeted them with advertisements for specific drugs to treat their health conditions.

“GoodRx’s sharing of personal and health information has revealed highly sensitive and private details about its users, most of whom suffer from chronic health conditions. This has led to the unauthorized disclosure of facts about individuals’ chronic physical or mental health conditions, medical treatments and treatment choices, life expectancy, disability status, parental status, substance addiction, sexual and reproductive health, and sexual orientation, as well as other information,” the FTC said.

“Disclosure of this information without authorization is likely to cause GoodRx users stigma, embarrassment, or emotional distress, and may also affect their ability to obtain or retain employment, housing, health insurance, disability insurance, or other services.”

In a press release, GoodRx said the FTC was focusing on an “old issue” that it addressed and corrected three years ago. “Millions of Americans use GoodRx to save on their healthcare, and we take strong measures to ensure they can trust us with their information,” the company said.

Data mining isn’t limited to healthcare providers, advertisers, internet companies or law enforcement. Medical researchers also use it, to track and evaluate patient conditions and the effectiveness of treatments. Some would also like to use data to predict patient outcomes.

In a new study, researchers at the University of Alberta said they had devised a form of artificial intelligence -- based on patient health data -- that can predict with 90% accuracy whether a patient is at risk of an adverse outcome from opioid prescriptions. Researchers say their model could be used someday to warn doctors about high-risk patients, so they can prescribe another drug or give smaller doses.