Know Your Rights
Patient privacy is about far more than medical records — it's about protecting your ability to live freely and safely. Understanding your rights requires examining which specific regulations apply to your particular situation.
The critical gap: Once an organization shares your sensitive health information, you often can't see where it goes next — who received it, how it was used, or how to trace any resulting harm back to its source.
Privacy contexts
Your rights change depending on the setting. Here's where your health data runs the biggest risks.
Healthcare
Your rights when seeking medical treatment, hospital stays, and clinical care.
Employment
How health data can affect hiring, workplace accommodations, and job security.
Finances & Credit
Health information's impact on loans, credit scores, and financial services.
Health Insurance
Coverage decisions, claims data, and pre-existing condition protections.
Education
Student health records, campus health services, and academic accommodations.
Mental Health
Special protections for psychotherapy notes and mental health treatment records.
Genetics
Genetic testing data, GINA protections, and discrimination prevention.
Law Enforcement
When and how law enforcement can access your health information.
Domestic Violence
Protecting health records for survivors of domestic violence and abuse.
Reproductive Care
Privacy protections for abortion care and reproductive health decisions.
Substance Use
Specialized 42 CFR Part 2 protections for substance use treatment records.
Data Breaches
Your rights when your health data is compromised in a security breach.
HIPAA doesn't protect your medical records the way most people think.
HIPAA was originally written to help workers keep their insurance when changing jobs. In 2003, amendments to the Privacy Rule removed your authority over who can see and share your medical records.
Today, HIPAA lets hospitals, insurers, and data-handling companies share your prescriptions, mental health visits, reproductive care, genetic tests, and addiction records — without asking you.
Who can access your records under HIPAA
Under the Privacy Rule's Treatment, Payment, and Operations (TPO) framework, these organizations can take and use your health records without asking.
Common HIPAA misconceptions
Myth: Doctor conversations stay completely confidential.
Reality: Under HIPAA's Treatment, Payment, and Operations (TPO) rules, your information can be shared with dozens of third parties without your consent.
Myth: The “privacy notice” you sign prevents unauthorized disclosure.
Reality: Those notices describe how your data can be used — they don’t restrict it. Signing them doesn’t give you additional protection.
Myth: Your medical records can’t be accessed without your explicit consent.
Reality: The 2003 Privacy Rule amendments removed the consent requirement for most disclosures. Routine sharing happens without any notification to you.
Take action
Report an Incident
Help us track systemic patterns by reporting concerning privacy incidents you've experienced.
Report nowSupport Our Work
Your donation helps us continue researching, advocating, and educating on patient privacy.
DonateStay Informed
Get patient privacy updates on evolving practices and new threats to your health data.
SubscribeThis resource was created by Dr. Latanya Sweeney and is maintained as an independent public-interest initiative.