Skip to content

Science1 publisher3 min readPublished

HIPAA Covers Less Than You Think, And "Anonymized" Is Not A Legal Shield

A health privacy scholar lays out how much patient data sits outside HIPAA entirely, just as federal demands for medical records expand and de-identification gets harder to defend.

The Scientist · Science desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened

  • The article's author is a professor of law at Indiana University who studies health information privacy and medical data regulation, including how sensitive health information moves among clinics, government agencies and law enforcement, and is a co-investigator on a federally funded study about opioid prescribing.
  • HIPAA regulates hospitals, physicians, insurers and their business associates, but not health data generated elsewhere: not a period-tracking application on a phone, an internet search about a diagnosis, DNA mailed to a genealogy company, or a wearable that counts heartbeats.
  • A growing body of research shows that anonymizing data by removing identifying information to make it difficult to trace back to an individual, the safeguard federal data-collection efforts lean on, is far weaker than officials claim.
  • HIPAA gives patients rights to see their health records, demand corrections, and expect that a covered provider will not casually disclose their information.
  • A hospital fully bound by HIPAA may release certain types of records without the patient's authorization and without telling the patient, and there are roughly a dozen such categories.

Compiled by The ScientistSomething wrong?How this is made

Why it matters

Writing in The Conversation, an Indiana University law professor who studies health information privacy argues that HIPAA is narrower than its reputation, and that the gap matters now because the federal government is pushing hard to collect health data at the same time that the safeguard those efforts rely on, anonymization, is looking weaker than officials claim [1][2][3]. For anyone holding patient, wearable, or genomic records, that combination changes the risk calculation: the law you cite in your privacy policy may not apply to most of what you hold.

The scope problem is structural. HIPAA regulates hospitals, physicians, insurers and their business associates, and not the period-tracking app on a phone, the search someone ran about a diagnosis, DNA mailed to a genealogy company, or the wearable counting heartbeats [2].

Inside the covered world, consent is less central than most consent language implies. HIPAA does grant rights to see records, demand corrections, and expect that a covered provider will not casually disclose information [4]. But a hospital fully bound by HIPAA may release certain records without authorization and without telling the patient, across roughly a dozen categories: treatment, payment and routine healthcare logistics, plus public health reporting, law enforcement, judicial and administrative proceedings, health plan oversight, research, and the catchall of essential government functions [5][6]. The statute carries further exceptions, and once data leaves the HIPAA-covered system, the HIPAA limits fall away [7][8].

The prescription drug monitoring programs are the concrete version. Every state now operates one, assembling detailed logs of who filled which controlled substance prescription and when [9]. Federal law enforcement can often reach those logs with a self-issued administrative subpoena, which requires no judge's approval or oversight [10]. According to the author, these programs have expanded beyond opioids into a dragnet that shares health data across state lines, exposing patients who seek reproductive or gender-affirming care to surveillance far from home [11].

Against that backdrop, demand is rising. Since the spring of 2025, Health and Human Services Secretary Robert F. Kennedy, Jr. has sought federal access to Americans' medical records to investigate whether vaccines cause autism, a question the scientific community has studied for decades and answered decisively in the negative [12][13]. KFF Health News reports that HHS has been courting state health information exchanges, the systems that let hospitals and clinics swap detailed, identifiable patient records, and asking how those records might be used for vaccine research [14]. One proposal floated by state organizations would give HHS data on 90% of Americans' medical records by 2028, roughly three years from the start of the push [15][16]. In Nebraska, millions of federal grant dollars have gone to a statewide health information exchange nonprofit that cooperated with the effort [17].

None of this makes large datasets worthless. Pooled records can expose drug side effects, track outbreaks and reveal disparities in care that smaller studies miss, and public health has always depended on some surrender of individual privacy for collective benefit [18][19].

What to watch: whether the 90%-by-2028 proposal moves from floated to funded, which state exchanges follow Nebraska's grant path, and how much of your own data inventory sits outside covered-entity status, where HIPAA constraints do not travel with it [15][17][8]. If your control for that exposure is a vendor's assertion that the data is de-identified, treat it as a claim to be tested rather than a defense already won [3].

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories