Know Your Rights

Patient privacy is about far more than medical records — it's about protecting your ability to live freely and safely. Understanding your rights requires examining which specific regulations apply to your particular situation.

The critical gap: Once an organization shares your sensitive health information, you often can't see where it goes next — who received it, how it was used, or how to trace any resulting harm back to its source.

Privacy contexts

Your rights change depending on the setting. Here's where your health data runs the biggest risks.

Healthcare

Your rights when seeking medical treatment, hospital stays, and clinical care.

Employment

How health data can affect hiring, workplace accommodations, and job security.

Finances & Credit

Health information's impact on loans, credit scores, and financial services.

Health Insurance

Coverage decisions, claims data, and pre-existing condition protections.

Education

Student health records, campus health services, and academic accommodations.

Mental Health

Special protections for psychotherapy notes and mental health treatment records.

Genetics

Genetic testing data, GINA protections, and discrimination prevention.

Law Enforcement

When and how law enforcement can access your health information.

Domestic Violence

Protecting health records for survivors of domestic violence and abuse.

Reproductive Care

Privacy protections for abortion care and reproductive health decisions.

Substance Use

Specialized 42 CFR Part 2 protections for substance use treatment records.

Data Breaches

Your rights when your health data is compromised in a security breach.

Understanding HIPAA

HIPAA doesn't protect your medical records the way most people think.

HIPAA was originally written to help workers keep their insurance when changing jobs. In 2003, amendments to the Privacy Rule removed your authority over who can see and share your medical records.

Today, HIPAA lets hospitals, insurers, and data-handling companies share your prescriptions, mental health visits, reproductive care, genetic tests, and addiction records — without asking you.

Who can access your records under HIPAA

Under the Privacy Rule's Treatment, Payment, and Operations (TPO) framework, these organizations can take and use your health records without asking.

Healthcare providers
Employers
Government agencies
Insurance companies
Billing firms
Transcription services
Pharmacy benefit managers
Pharmaceutical companies
Data miners
Creditors

Common HIPAA misconceptions

  • Myth: Doctor conversations stay completely confidential.

    Reality: Under HIPAA's Treatment, Payment, and Operations (TPO) rules, your information can be shared with dozens of third parties without your consent.

  • Myth: The “privacy notice” you sign prevents unauthorized disclosure.

    Reality: Those notices describe how your data can be used — they don’t restrict it. Signing them doesn’t give you additional protection.

  • Myth: Your medical records can’t be accessed without your explicit consent.

    Reality: The 2003 Privacy Rule amendments removed the consent requirement for most disclosures. Routine sharing happens without any notification to you.

Take action

Report an Incident

Help us track systemic patterns by reporting concerning privacy incidents you've experienced.

Report now

Support Our Work

Your donation helps us continue researching, advocating, and educating on patient privacy.

Donate

Stay Informed

Get patient privacy updates on evolving practices and new threats to your health data.

Subscribe

This resource was created by Dr. Latanya Sweeney and is maintained as an independent public-interest initiative.