Health Record Rights Index data API and MCP server

curl https://healthrecordrights.com/api/v1/countries/FIN

JSON, no key. MCP server: https://healthrecordrights.com/mcp (Streamable HTTP, read-only). License: CC BY 4.0, credit "SuperTruth, Inc., Health Record Rights Index".

A developer at her desk, coffee mug in hand, builds an app on her laptop next to a second screen showing a world map.

The 2026 Health Record Rights Index as open JSON: 198 countries and territories scored from 0 to 100 on eight rights, with every source, and 463 published real cases. For the United States, it also records what each of the 50 states and DC adds to federal law, question by question. Data as of October 2, 2026.

Not a developer? Start with our guides for students, teachers, patients and caregivers, healthcare professionals, and researchers and journalists.

It is free to use under CC BY 4.0, with credit. There is no sign-up and no key. The same answers are open to AI assistants through an MCP server. Every answer gives the page on this site that shows the same thing, so you can check it.

Quick start

Ask for one country by its three-letter code. This is the real answer from this API, shortened: the full answer also holds the other seven rights, every source, the laws, the news and the real cases.

curl https://healthrecordrights.com/api/v1/countries/IND
{
  "api": "v1",
  "version": "1.0",
  "asOf": "2026-10-02",
  "dataSha256": "7d9d4873c5fcc598c966c1e0b55dbc9544884e80a4530cefe0af297db25027e5",
  "license": {
    "id": "CC-BY-4.0",
    "url": "https://creativecommons.org/licenses/by/4.0/",
    "credit": "SuperTruth, Inc., Health Record Rights Index"
  },
  "citation": "Snyder, J. A., Hill, R. P., IV, Raney, D., & Sims, L. (2026). Health Record Rights Index (version 1.0). SuperTruth Inc. https://healthrecordrights.com/ https://doi.org/10.5281/zenodo.23120174",
  "pageUrl": "https://healthrecordrights.com/brief/IND/",
  "data": {
    "iso3": "IND",
    "name": "India",
    "overall": 45,
    "band": "Mixed",
    "rank": 71,
    "rankTied": true,
    "leadGroup": false,
    "likelyRank": {
      "low": 52,
      "high": 95
    },
    "likelyRankText": "52 to 95",
    "confidence": "low",
    "categories": {
      "access": {
        "name": "Getting your full record",
        "weight": 20,
        "score": 55
      }
    }
  }
}

Compare two states. This shows the first of 10 rows. Each row says whether the answers differ; there is never a total or a winner.

curl "https://healthrecordrights.com/api/v1/states/compare?s=CA,TX"
{
  "pageUrl": "https://healthrecordrights.com/us/states/compare/CA-TX/",
  "data": {
    "rule": "Columns are in the order given. Each row says differs, same or cannot_compare (an answer was not checked; not checked is not a no). There is no total, no rank and no winner: the questions are on different scales, and some have no best answer.",
    "rows": [
      {
        "id": "consumer_health_data",
        "name": "Health data outside HIPAA",
        "question": "Do apps and wearables need your OK before sharing health data?",
        "comparison": "same",
        "answers": [
          {
            "usps": "CA",
            "checked": true,
            "short": "Opt-in, for some businesses",
            "citations": [
              "Cal. Civ. Code § 56.06(d)",
              "Cal. Civ. Code § 56.10(a)"
            ]
          },
          {
            "usps": "TX",
            "checked": true,
            "short": "Opt-in, for some businesses",
            "citations": [
              "Tex. Bus. & Com. Code § 541.101(b)(4)",
              "Tex. Bus. & Com. Code § 541.001(29)"
            ]
          }
        ]
      }
    ]
  }
}

Use a name instead of a code, and the answer tells you the code. Ask for a place we do not rate, and it says why.

curl https://healthrecordrights.com/api/v1/countries/England
{
  "error": {
    "status": 404,
    "code": "use_code",
    "message": "\"England\" is not an ISO 3166-1 alpha-3 code. The index has it as United Kingdom: use GBR.",
    "suggestions": [
      {
        "code": "GBR",
        "name": "United Kingdom",
        "url": "https://healthrecordrights.com/api/v1/countries/GBR"
      }
    ]
  }
}
curl https://healthrecordrights.com/api/v1/countries/Bermuda
{
  "error": {
    "status": 404,
    "code": "not_rated",
    "message": "Bermuda is not rated. We rate the 193 UN member states plus Greenland, Kosovo, Palestine, Taiwan and Vatican City. Bermuda is a territory of another country, and is not on that list. Which places we rate: https://healthrecordrights.com/#which-places"
  }
}

Routes

Every route answers GET and HEAD with JSON. Codes are upper case: ISO 3166-1 alpha-3 for countries (FIN), two letters for states (CA, or DC).

RouteWhat it returns
/api/v1/The version, the data date and hash, the license, how to cite, and every route.
/api/v1/countriesAll 198 countries and territories: overall score out of 100, band, rank (or lead group), likely rank range, confidence.
/api/v1/countries/{ISO3}One country: each of the eight rights with its score, summary, detail and sources, then key laws, recent news and real cases.
/api/v1/statesThe 50 states and DC. DC is marked as not a state.
/api/v1/states/{USPS}One state, or DC: the answer to each question, with the laws quoted, dated and linked, and laws signed but not yet in force.
/api/v1/states/compare?s=CA,TXTwo or three states side by side, in your order. Each row says differs, same or cannot_compare. No total, no rank, no winner.
/api/v1/cases?country={ISO3}Real cases for one country, or all of them without the country.
/api/v1/methodHow we score: the rights and their weights, the bands, ties, the lead group and confidence.
/api/v1/openapi.jsonThe OpenAPI 3.1 description of all of the above.

Every answer carries the same fields around its data: version (the index version), asOf (the data date), dataSha256 (a hash of the country data, the same one recorded in our working paper), license, citation and pageUrl. State answers also carry statesSha256.

The headers allow use from any website (Access-Control-Allow-Origin: *). Each answer has an ETag, so you can send If-None-Match and get a short 304 when nothing changed. Answers may be cached for five minutes. A code we do not know gets a 404 with a plain message. Any method other than GET, HEAD or OPTIONS gets a 405.

Connect an AI assistant (MCP)

The MCP server is at https://healthrecordrights.com/mcp. It uses the Streamable HTTP transport, needs no sign-in, and only reads. Its answers are the API's answers, each with the citation, the license, the data date, the page link and a reminder to cite the index and its sources.

Claude Code

claude mcp add --transport http health-record-rights https://healthrecordrights.com/mcp

Claude Desktop and claude.ai

Open Customize, then Connectors, press Add and choose Add custom connector. Name it, paste https://healthrecordrights.com/mcp and choose no sign-in. Every Claude plan can add custom connectors; the free plan allows one.

ChatGPT

On the web, open Settings, then Security and login, and turn on Developer mode. Then open ChatGPT Plugins (chatgpt.com/plugins), press the plus button, name the app, paste https://healthrecordrights.com/mcp as the server address and choose no authentication. OpenAI offers this on Plus, Pro, Business, Enterprise and Education accounts. All the tools are marked read-only, so ChatGPT does not ask you to confirm each call. The search and fetch tools follow the shape OpenAI's deep research reads.

To build a custom GPT instead, add an action, choose no authentication and import https://healthrecordrights.com/api/v1/openapi.json. Every route has an operation ID, and every answer an action would ask for is under OpenAI's limit of 100,000 characters. For all real cases at once, use the download instead.

We tested the MCP server with the official MCP client library and with Claude Code. The Claude Desktop, claude.ai and ChatGPT steps follow each company's own instructions, read on October 4, 2026; we have not tested those screens ourselves.

Other MCP clients

Most clients take a server entry like this one. Some name the type streamable-http.

{
  "mcpServers": {
    "health-record-rights": {
      "type": "http",
      "url": "https://healthrecordrights.com/mcp"
    }
  }
}

Tools

Every tool wraps text from other sources in [quoted] and [/quoted], and tells the assistant to treat it as data, never as instructions.

License, and how to credit

Our scores, summaries, ratings and labels, and the way the data is put together, are licensed under Creative Commons Attribution 4.0 (CC BY 4.0). You may copy, change and build on them, for any purpose, if you give credit. Credit this way:

SuperTruth, Inc., Health Record Rights Index, with a link to healthrecordrights.com.

To cite the index in a paper:

Snyder, J. A., Hill, R. P., IV, Raney, D., & Sims, L. (2026). Health Record Rights Index (version 1.0). SuperTruth Inc. https://healthrecordrights.com/ https://doi.org/10.5281/zenodo.23120174

Some things in the answers are not ours to license, and CC BY 4.0 does not cover them: the words of laws and other sources we quote, the titles of other people's pages, and the pages our links point to. Their owners' terms apply. DTI™ is a trademark; CC BY 4.0 grants no trademark rights.

This license is our written permission to read this data by automated means, through the API, the MCP server and the downloads, within the rate limit. Where the general terms of use of SuperTruth, Inc. and this license differ on this data, this license governs. The full terms of use for the data are short.

Rate limits

Each address may make 60 requests a minute, with bursts up to 120. The API and the MCP server share the limit. Past it, you get a 429 with a Retry-After header that says how many seconds to wait. If you need the whole index at once, download it instead: the CSV and JSON files carry the same license.

Our code uses your address only to count requests per minute, in memory, and never writes it anywhere. Our host, Railway, records each request, including your address and browser name, in its own request logs, which it keeps for a limited time. Our own records hold only counts of requests per day, by route, by the kind of client (a browser, a script or an AI assistant, read from the User-Agent header) and by result.

Versioning

This is version 1. We will not remove or rename a field in version 1. We may add fields and routes, so ignore fields you do not know. A change that would break your code would get a new address, /api/v2/, and version 1 would keep working.

The data changes when we publish a data release. When it does, dataSha256 and the ETags change.

What this data is not

To report a wrong score, fact or source, tell us what we got wrong. How we score is on the method section of the home page.

Built by SuperTruth, which checks whether a record can be trusted before an AI acts on it. About SuperTruth · How we used AI

Health Record Rights Index, by SuperTruth. Privacy. This page last changed on .