Science1 distinct publisher3 min readUpdated
A health privacy scholar lays out how much patient data sits outside HIPAA entirely, just as federal demands for medical records expand and de-identification gets harder to defend.
The Scientist · Science desk
Compiled by The ScientistSomething wrong?How this is made
Writing in The Conversation, an Indiana University law professor who studies health information privacy argues that HIPAA is narrower than its reputation, and that the gap matters now because the federal government is pushing hard to collect health data at the same time that the safeguard those efforts rely on, anonymization, is looking weaker than officials claim [1][2][3]. For anyone holding patient, wearable, or genomic records, that combination changes the risk calculation: the law you cite in your privacy policy may not apply to most of what you hold.
The scope problem is structural. HIPAA regulates hospitals, physicians, insurers and their business associates, and not the period-tracking app on a phone, the search someone ran about a diagnosis, DNA mailed to a genealogy company, or the wearable counting heartbeats [2].
Inside the covered world, consent is less central than most consent language implies. HIPAA does grant rights to see records, demand corrections, and expect that a covered provider will not casually disclose information [4]. But a hospital fully bound by HIPAA may release certain records without authorization and without telling the patient, across roughly a dozen categories: treatment, payment and routine healthcare logistics, plus public health reporting, law enforcement, judicial and administrative proceedings, health plan oversight, research, and the catchall of essential government functions [5][6]. The statute carries further exceptions, and once data leaves the HIPAA-covered system, the HIPAA limits fall away [7][8].
The prescription drug monitoring programs are the concrete version. Every state now operates one, assembling detailed logs of who filled which controlled substance prescription and when [9]. Federal law enforcement can often reach those logs with a self-issued administrative subpoena, which requires no judge's approval or oversight [10]. According to the author, these programs have expanded beyond opioids into a dragnet that shares health data across state lines, exposing patients who seek reproductive or gender-affirming care to surveillance far from home [11].
Against that backdrop, demand is rising. Since the spring of 2025, Health and Human Services Secretary Robert F. Kennedy, Jr. has sought federal access to Americans' medical records to investigate whether vaccines cause autism, a question the scientific community has studied for decades and answered decisively in the negative [12][13]. KFF Health News reports that HHS has been courting state health information exchanges, the systems that let hospitals and clinics swap detailed, identifiable patient records, and asking how those records might be used for vaccine research [14]. One proposal floated by state organizations would give HHS data on 90% of Americans' medical records by 2028, roughly three years from the start of the push [15][16]. In Nebraska, millions of federal grant dollars have gone to a statewide health information exchange nonprofit that cooperated with the effort [17].
None of this makes large datasets worthless. Pooled records can expose drug side effects, track outbreaks and reveal disparities in care that smaller studies miss, and public health has always depended on some surrender of individual privacy for collective benefit [18][19].
What to watch: whether the 90%-by-2028 proposal moves from floated to funded, which state exchanges follow Nebraska's grant path, and how much of your own data inventory sits outside covered-entity status, where HIPAA constraints do not travel with it [15][17][8]. If your control for that exposure is a vendor's assertion that the data is de-identified, treat it as a claim to be tested rather than a defense already won [3].
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
A growing body of research shows that anonymizing data by removing identifying information to make it difficult to trace back to an individual, the safeguard federal data-collection efforts lean on, is far weaker than officials claim.
Since the spring of 2025, Health and Human Services Secretary Robert F. Kennedy, Jr. has sought federal access to Americans' medical records to investigate whether vaccines cause autism.
According to KFF Health News, HHS has been courting state health information exchanges, the systems that let hospitals and clinics swap detailed, identifiable patient records, and asking how those records might be used for vaccine research.
The article's author is a professor of law at Indiana University who studies health information privacy and medical data regulation, including how sensitive health information moves among clinics, government agencies and law enforcement, and is a co-investigator on a federally funded study about opioid prescribing.
HIPAA regulates hospitals, physicians, insurers and their business associates, but not health data generated elsewhere: not a period-tracking application on a phone, an internet search about a diagnosis, DNA mailed to a genealogy company, or a wearable that counts heartbeats.
HIPAA gives patients rights to see their health records, demand corrections, and expect that a covered provider will not casually disclose their information.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Solid on law, thin on the news claims
The statutory material — which entities HIPAA binds, the roughly dozen no-authorization disclosure categories, loss of protection once data exits covered systems, PDMP logs reachable by administrative subpoena — is stated by a named health-privacy law professor and is checkable against the statute. The newer and more consequential assertions are relayed second-hand: HHS courting state health information exchanges, a 'floated' 90%-by-2028 coverage proposal from unnamed state organizations, unquantified federal grants to an unnamed Nebraska nonprofit, and a June 2026 Nature membership-inference study summarized without methods or results. One publisher, one article, no primary documents and no HHS response hold the score near the middle.
Sharing plumbing already live; federal repository still a proposal
The infrastructure that makes the argument concrete is demonstrably in production: PDMPs run in every state and health information exchanges already move identifiable records between hospitals and clinics. Federal money is described as reaching at least one state exchange nonprofit. What is not yet built is the thing the story is about — HHS has been asking questions and a coverage target has been floated, but no operating federal medical-records repository, participating-state list or executed agreement is evidenced.
Framing runs slightly ahead of the documented specifics
The headline's 'unprecedented access' and the body's 'dragnet' language sit above what the article actually documents: a floated proposal from unnamed organizations, unquantified grants, and an HHS inquiry whose scope the agency will not describe. The gap is modest rather than severe, because the durable core — HIPAA's narrow perimeter, its many no-consent disclosure doors, and warrantless federal access to PDMP logs — is accurately stated and the author explicitly credits the public-health value of pooled data instead of arguing collection is always illegitimate.
Disclosed academic interest, advocacy-shaped explainer
The author discloses being an Indiana University law professor and a co-investigator on a federally funded opioid prescribing study that itself relies on health data — an interest that cuts both ways, since he benefits from research access while arguing for tighter safeguards. The publisher is an academic explainer outlet with no product, vendor or investment stake in the outcome, and no company is promoted anywhere in the piece. The residual incentive is professional and argumentative: this is a scholar making a policy case, which favors framing that heightens the protection gap, and no opposing party is given space to answer.
Confident on the law, uncertain on the program
Confidence is split. Assertions about HIPAA's scope, exceptions and PDMP access mechanics are stable, expert-stated and independently checkable, so they can be relied on. Everything about the HHS records program — its scale, participating states, data types and the 90%-by-2028 trajectory — comes through a single publisher relaying another outlet, with the agency silent and no documents supplied, so those elements should be treated as reported-but-unverified pending corroboration.
product
Enhanced Games' $62M quarter puts a price on buying legitimacy1 distinct publisher
science
A phage kinase with no target list: EMBL finds one enzyme that breaks several bacterial defences1 distinct publisher
science
Claude's watermark is a compliance artefact, not a cheating detector1 distinct publisher
product
LLNL closes a 20 percent gap in diamond melting, and stakes a fusion gain claim on it1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.