Cite the index, download the data and reproduce a result
The 2026 index covers 198 countries and territories, with data as of October 2, 2026, and what the 50 US states and DC add to federal law. It is free to reuse under CC BY 4.0, and every release has a data hash, so you can show which data you used.
For researchers and journalists: cite, check and reproduce
Cite the index with the DOI that covers all versions of the working paper, 10.5281/zenodo.23120174. It always resolves to the latest version. Each version of the paper also has its own DOI; cite that one if you need the exact text you read. The data have their own DOI, 10.5281/zenodo.23120172 (data version 1.0).
The file CITATION.cff in the open repository carries the citation for reference managers. In BibTeX:
@techreport{snyder2026hrri,
author = {Snyder, Jason Alan and Hill, IV, Robert P. and Raney, Dustin and Sims, Leann},
title = {The Health Record Rights Index: Who Holds the Record in 198 Countries?},
institution = {SuperTruth Inc.},
type = {Working paper},
year = {2026},
doi = {10.5281/zenodo.23120174},
url = {https://doi.org/10.5281/zenodo.23120174}
}
@misc{snyder2026hrridata,
author = {Snyder, Jason Alan and Hill, IV, Robert P. and Raney, Dustin and Sims, Leann},
title = {The Health Record Rights Index: Scores, Sources and Rubric for 198 Countries and Territories (data, version 1.0)},
publisher = {Zenodo},
year = {2026},
doi = {10.5281/zenodo.23120172},
url = {https://doi.org/10.5281/zenodo.23120172},
note = {CC BY 4.0}
}
Get the data
Downloads: the scores (CSV, one row per country or territory), the sources (CSV, one row per cited source) and everything in one JSON file, with scores, category summaries, sources, laws and evidence grades.
The data API at /api/v1/: read-only JSON, no key and no sign-up. It lists every route, and openapi.json describes every field. Each address may make 60 requests a minute, with bursts up to 120, shared with the MCP server. For the whole index at once, use the downloads instead.
The MCP server at /mcp gives an AI assistant the same answers as the API.
Make your work reproducible
Every API answer carries version, asOf and dataSha256. Record all three with your analysis. Today they are version 1.0, data as of October 2, 2026, and dataSha256 7d9d4873c5fcc598c966c1e0b55dbc9544884e80a4530cefe0af297db25027e5.
dataSha256 is a SHA-256 hash of the country files the scores come from. The paper records the same hash, so a match means you used the same data. State answers carry their own hash, statesSha256.
In version 1 of the API, no field is removed or renamed. A change that would break your code would get a new address, /api/v2/, and version 1 would keep working.
When we publish a new data release, dataSha256 changes. Every score change we approve is logged with its evidence.
What the paper reports on reliability
The working paper is not peer reviewed. It sets out the method, the checks and the limits of the scores.
Two blind re-scores: agents that could not see our scores re-scored random samples of single category scores. In the first study, 51 of 58 scores came within 10 points of ours; in the second, 94 of 108 scores did. Agreement was 0.82 and 0.84 (intraclass correlation, where 1 means full agreement). The plans for both studies were written and locked before any scoring.
The limits: the re-scoring agents are the same model family as ours, and no person has re-scored the index. Getting your full record (access) agreed least in both studies. The paper says a single category score should not be read as exact to the point.
Sources: every cited page is listed beside the score it supports, and the agents had to open each one before citing it. A page that opens shows it exists, not that it says what our summary says.
For the 95% intervals, the blind studies and the second full scoring of the first 43 countries, read the part of Section 3 headed "How far a second reading agrees". For the stability analysis behind each likely rank range, read Section 4.2.
Join the scores to other country data. Join the scores, by ISO 3166-1 alpha-3 code, to measures such as health spending or internet use, and test whether record rights track them. Treat gaps under 5 points as ties, use the likely rank ranges rather than single ranks, and report the confidence label of each country.
Study one right across regions. Take one category, such as Rules for AI in your care (ai) or Protection from sale and ads (commercial), and read its scores, summaries and sources across regions. Check the paper's reliability results for that category first. Agreement differs by category: Getting your full record (access) agreed least in both blind studies, and Your say over research use (research) and Rules for AI in your care (ai) were weak in the second full scoring of the first 43 countries.
Study what US states add to federal law. Use the answers for the 50 states and DC to study one question at a time, such as whether apps and wearables need your OK before sharing health data, with each law quoted, dated and linked. There is no state score, total or rank. Not checked is never a no, and DC is not a state.
Journalists, clinicians and patients
Check a claim
Ask: A post says "Finland is the best country in the world for health records." Is that what the index says? Cite the method and the sources.
The assistant calls get_method with {}, then get_country with {"country":"FIN"}.
What the tool sends back, shortened:
The rule: No country is called first or best. Every country whose likely rank range includes first is in the lead group, and the group is always named together, in A to Z order.
The lead group: Denmark, Estonia, Finland, Hungary and Sweden.
Finland: 71 out of 100, one of five countries that lead the 198 countries and territories we rated; likely rank range 1 to 6. Page: /brief/FIN/
Check it: The index never calls one country first or best. Look for the lead group, named together, and each rank's likely range.
Journalists and fact checkers
Check a claim across countries
Ask: A story says Estonia gives people more say over who sees their health record than Germany. Give both countries' scores out of 100 for each of the eight rights, and say where the gap is under 5 points.
The assistant calls get_country with {"country":"DEU"}, then get_country with {"country":"EST"}.
What the tools send back, shortened to the scores:
Check it: Open both country pages and match the scores. Where the gap is under 5 points, the index treats the two as the same, so a claim that one gives more does not hold for that right.
Policy staff in the US
A US policy brief with citations
Ask: Write a one-page brief for a state legislator: can people in Ohio and in Pennsylvania say no to sharing their records through a health information exchange? Cite each law with its link and date.
The assistant calls compare_states with {"states":["OH","PA"]}.
What the tool sends back, the row on the health information exchange:
Health information exchange (Can you say no to sharing through a health information exchange (a network that passes records between doctors)?): the answers are the same.
OH: Opt-out. Your records go through the exchange unless you say no, and there is a published way to say no. Law: Ohio Rev. Code 3798.07(A)(3).
PA: Opt-out. Your records go through the exchange unless you say no, and there is a published way to say no. Law: Human Services Code (Act of June 13, 1967, P.L.31, No.21) § 1407-C(c)(1), added by Act 76 of 2016; Human Services Code § 1407-C(b).
Check it: Every claim in the brief should trace to a quoted law with a link. Credit the index in the brief: SuperTruth, Inc., Health Record Rights Index.
Developers
Build a map
Ask: Give me every country's ISO3 code, overall score out of 100 and band, as CSV I can join to a world map.
The assistant calls list_countries with {}.
What the tool sends back, the first 5 of 198 countries and territories, as CSV:
AI assistants can make mistakes, even when they read from our data. Each answer from the index carries a link to the page on this site that shows the same thing. Country scores carry their sources, and US state answers carry the laws they cite. Check them before you quote a score, a law or a date.
Scores are out of 100. Treat two scores less than 5 points apart as the same. The countries in the lead group are always named together. Any of them could rank first, so we never call one of them first.
This is a research tool, not legal advice. It records what laws and official pages said on the dates we read them, and it does not rate any hospital, doctor or company.
We check our data, which makes errors less likely but does not rule them out. We cannot check what an assistant writes from it. If you find one, tell us. Please leave out anyone's medical details.
Our scores, summaries, ratings and labels, and the way the data is put together, are licensed under Creative Commons Attribution 4.0 (CC BY 4.0). You may copy, change and build on them, for any purpose, if you give credit.
Credit this way: SuperTruth, Inc., Health Record Rights Index, with a link to healthrecordrights.com. The same applies to anything an AI assistant writes for you from our data.
Some things are not ours to license, and CC BY 4.0 does not cover them: the words of laws and other sources we quote, the titles of other people's pages, and the pages our links point to. Their owners' terms apply.
Built by SuperTruth, which checks whether a record can be trusted before an AI acts on it. About SuperTruth · How we used AI
Health Record Rights Index, by SuperTruth. Not legal or medical advice. Our data and our own words are CC BY 4.0, credit SuperTruth, Inc., Health Record Rights Index; quoted law and source titles stay with their owners. This page last changed on .