United States · in depth
Health record rights in the United States
The answer: 48 of 100, Mixed
In 2026, the United States scores 48 of 100 on a person's right to see, control and share their own health record. That puts it in a tie for 55th of 198 countries; allowing for scoring error, its likely rank is 45th to 80th. It sits in the Mixed band (45 to 64).
The US scores above the median of 39 across all 198 countries, but below the UK (59), Canada (52), Australia (66) and Germany (63). Its two lowest scores are control over who sees the record (35) and protection from commercial use (38). They are its only scores in the Weak range. Both are below all four of those countries.
Not legal advice. This page explains how our index scores the United States and what US law says, in plain English. Laws change, and your situation may differ. For advice about your own records, ask a lawyer or the agency named in each section.
Who holds the keys: Institutional. Providers and insurers decide. Doctors, hospitals and insurers each keep their own records, and there is no national health record.
On this page:
- The eight categories
- US law in plain English
- Your HIPAA right of access: getting a copy
- Who decides who sees your record
- Information blocking: the Cures Act rule
- Your insurer's data: the Patient Access API
- Connecting records: TEFCA
- What HIPAA does not cover
- Health apps: the FTC and its cases
- Security, breaches and police access
- State laws
- Rules for AI in care
- Research
- The enforcement record
- How fair is 48?
- What the scoring rules reward
- States, coming next
- Stories, brief and data
The eight categories, against the world and four peers
The US scores above the world median in 7 of 8 categories. It scores below all four comparison countries in 3: control over who sees the record, privacy and protection from commercial use. Access to the record and control over it count most, 20% each.
| Category and weight | US | Median | UK | Canada | Australia | Germany | Position on a 0 to 100 scale |
|---|---|---|---|---|---|---|---|
| Overall | 48 | 39 | 59 | 52 | 66 | 63 | |
| Patient access to the full record 20% | 50 | 43 | 66 | 50 | 70 | 64 | |
| Patient control and consent 20% | 35 | 30 | 52 | 55 | 68 | 66 | |
| Privacy and security 15% | 50 | 45 | 56 | 58 | 62 | 58 | |
| Connected care journey 15% | 60 | 38 | 62 | 50 | 70 | 66 | |
| Protection from commercial use 10% | 38 | 45 | 60 | 45 | 65 | 70 | |
| Clinician access at the point of care 10% | 55 | 34 | 60 | 55 | 66 | 62 | |
| Research and trial consent 5% | 49 | 46 | 64 | 49 | 50 | 50 | |
| Clinical AI governance 5% | 56 | 30 | 55 | 56 | 55 | 50 |
US law in plain English
The US has no single national health record and no one privacy law for all health data. Your rights come from several federal laws, each with its own reach, and from state laws that differ from state to state. Each claim below links to the law or the agency page we read. We checked the federal law against those sources on October 3, 2026.
Your HIPAA right of access: getting a copy
Under HIPAA, a doctor, hospital or health plan must act on your request for your records within 30 days. It may take one 30-day extension (45 CFR 164.524). The right covers your medical and billing records. It does not cover a therapist's separate psychotherapy notes or files prepared for a lawsuit. If you ask for an electronic copy in a form they can readily produce, they must give it to you that way. They may charge only a cost-based fee: the labor of copying, supplies, postage, and a summary if you agree to one.
The Office for Civil Rights (OCR) at the Department of Health and Human Services (HHS) enforces this right. It has brought 55 right of access cases since 2019 (HHS, August 27, 2026). HHS plans to propose a change to the response time in November 2026. The plan does not say whether the time would get shorter or longer (federal rulemaking agenda).
Who decides who sees your record
HIPAA lets providers and health plans share your records for treatment, payment and their own operations without asking you (45 CFR 164.506). You can ask them to limit sharing, but they can say no. One exception: if you pay for an item in full yourself, they must keep it from your health plan when you ask (45 CFR 164.522). You can get a list of disclosures from the past six years, but it leaves out sharing for treatment, payment and operations (45 CFR 164.528). So it does not show who saw your record in routine care. Records from substance use treatment have extra protection. Since February 16, 2026, one signed consent can cover future uses for treatment, payment and operations (42 CFR Part 2 rule).
Information blocking: the Cures Act rule
Under the 21st Century Cures Act rule, it can be against the law to block your access to your electronic health information. The rule calls this "information blocking." It covers providers, health IT developers and health information networks. A practice counts if it is likely to interfere with getting, sharing or using electronic health information (45 CFR Part 171). A provider breaks the rule only if it knows the practice is unreasonable. There are ten exceptions, such as preventing harm, privacy, security and requests that are not feasible. One exception allows some fees. It does not allow a fee for viewing your own records online.
Health IT developers and networks can face penalties of up to $1 million per violation, the figure in the law before inflation adjustments (42 U.S.C. 300jj-52). Providers do not face these money penalties. Since July 2024, a hospital or clinician found to be blocking can instead face what HHS calls "disincentives" in Medicare programs (HHS rule, 2024). In September 2025, HHS announced what it called a "crackdown" on information blocking (HHS). As of May 27, 2026, the HHS Inspector General had published no information blocking penalties (OIG).
Your insurer's data: the Patient Access API
Since January 1, 2021, some health plans have had to offer a Patient Access API (42 CFR 422.119, 431.60 and 457.730; 45 CFR 156.221; the Centers for Medicare & Medicaid Services, CMS). An API, or application programming interface, is a standard way for apps to get data. Here it lets patients get their plan's data electronically. The rule covers Medicare Advantage plans, Medicaid, the Children's Health Insurance Program (CHIP) and plans on the federal marketplace. A 2024 rule, CMS-0057-F, adds prior authorization data to it. It also requires two more connections, one to your doctors (Provider Access) and one between insurers (payer-to-payer), mostly by January 1, 2027 (CMS-0057-F). You will be able to opt out of the Provider Access exchange (CMS fact sheet).
Connecting records: TEFCA
TEFCA (the Trusted Exchange Framework and Common Agreement) is a national framework that lets health networks exchange records with each other. HHS says the number of records exchanged through it grew from 10 million to more than 1 billion in less than a year (HHS, June 2026). There are 11 networks designated to carry TEFCA exchange (list), and 22 apps are listed to fetch records for patients who ask (list). Some of these apps may not be covered by HIPAA, so once your data reaches them, other rules may apply.
What HIPAA does not cover
HIPAA covers doctors, hospitals, health plans and the companies that work for them. It does not cover a health app you download yourself, a fitness tracker or smartwatch, or a data broker that buys and sells data. Inside HIPAA, marketing and any sale of your health information need your written permission (45 CFR 164.508). But data with identifiers removed ("de-identified") is outside HIPAA and can be sold (45 CFR 164.514).
Health apps: the FTC and its cases
For many health apps, the Federal Trade Commission's Health Breach Notification Rule applies instead. The FTC says the rule can apply to health apps and similar technologies (FTC, 2024). Since July 29, 2024, a "breach" under the rule includes sharing your data without your permission, not only a hack (16 CFR Part 318). The rule requires notice. It does not require your consent for each use.
The FTC's first case under the rule was GoodRx in 2023: the company was barred from sharing health data for ads and paid a $1.5 million civil penalty (FTC). The FTC also uses its general power against deception. It barred BetterHelp from sharing health data for ads and required it to pay $7.8 million (2023, FTC). It required Flo Health to get users' consent before sharing their health data (2021, FTC). These orders bind one company each. The enforcement record below counts the FTC's health privacy cases.
Security, breaches and police access
HIPAA requires breach reporting, and the HHS breach portal lists every large breach. A major update to the HIPAA Security Rule was proposed in January 2025; the federal agenda now targets a final rule in July 2027 (rulemaking agenda). Police can get records with a court order or a subpoena, and also with an administrative request when the law requires a response (45 CFR 164.512). A 2024 rule that added protection for reproductive health records was mostly struck down by a federal court on June 18, 2025 (HHS; court docket). The official online copy of the regulations still shows the struck-down rule. The court's ruling is what counts.
State laws
Some states add their own rules. Washington's My Health My Data Act covers health data outside HIPAA. Since March 31, 2024, no one may sell a person's consumer health data there without the person's signed permission; small businesses had until June 30, 2024 (RCW 19.373.070). New York's legislature passed a similar bill, which was vetoed on December 19, 2025 (NY Senate). Texas requires electronic health records to be stored in the United States from January 1, 2026 (Texas SB 1188). Our national score credits state law only in a few places; the state layer below will look at every state.
Rules for AI in care
The FDA regulates AI tools that count as medical devices and lists about 1,600 of them (FDA). Its final guidance from August 2025 lets makers plan approved updates in advance (FDA guidance). HHS lists two rules as in force. Certified health record systems must show users who built a predictive tool, what it is for, its known risks and what data trained it. HHS proposed removing those requirements in December 2025; no final rule had been published when we checked (HTI-5 proposal). Since May 2025, providers that take federal funds must look for decision support tools that use race, color, national origin, sex, age or disability. They must also reduce the risk of bias these tools create (45 CFR 92.210). HHS plans to propose changes to this rule in February 2027. In Texas, practitioners must review records made with AI and tell patients when they use AI for diagnosis (Texas SB 1188).
Research
A review board can let researchers use your records without your permission. The privacy risk must be minimal. The research must also be impractical to do without the waiver or without the data (45 CFR 164.512). A limited data set, with names and other direct identifiers removed, can be shared for research under a data use agreement. De-identified data needs no consent (45 CFR 164.514). There is no general way to opt out of research use. Research that federal agencies fund or run follows the Common Rule, which requires informed consent or a board waiver and allows "broad consent" to future research (45 CFR 46.116). Research funded by the National Institutes of Health that meets set criteria automatically has a Certificate of Confidentiality, a federal protection for research records (NIH).
The enforcement record
From October 1, 2024 to October 1, 2026, OCR announced 6 right of access actions (3 civil money penalties and 3 settlements), totaling $592,500. The Inspector General had published no information blocking penalties. Large breach reports covered 234,919,800 people, counted once per breach, so a person hit twice counts twice. None of this feeds the score.
| Who acts | What we counted | In the window | Since the start (includes the window) | Source |
|---|---|---|---|---|
| HHS Office for Civil Rights (OCR) | Right of access actions: a provider or plan was slow to give patients their records | 6: 3 civil money penalties ($370,000) and 3 settlements ($222,500). Total $592,500. | 55 since the program began in 2019 | OCR list |
| HHS Inspector General | Information blocking penalties published | 0 (through May 27, 2026) | 0 | OIG page |
| HHS health IT office (ONC) complaint portal | Information blocking claims that name a health care provider. Claims received, not findings | 1,042 (Oct 2024 to Jul 2026) | 1,938 since April 5, 2021 | Claims data |
| Same portal, all claims | Claims filed by patients, whatever organization they name. One claim can name more than one type of organization, so this is not a share of the row above | 900 (Oct 2024 to Jul 2026) | 1,554 | |
| Federal Trade Commission (FTC) | Health privacy cases: those the FTC tags "Health Privacy", plus Cerebral | 2 with a new complaint or order: Hims & Hers Health (complaint, pending); Kochava Inc. and Collective Data Solutions. 2 where the only new step was refunds: BetterHelp; Cerebral (refunds for cancellation practices, not health data). | 20 cases | Case pages, linked |
| HHS OCR breach portal | Breaches of 500 or more people, reported by HIPAA-covered organizations | 1,546 reports. 34 affected 1 million people or more. 234,919,800 people in all, counted once per breach. Largest: Conduent Business Services LLC, 62,224,658. | Breach portal | |
| California attorney general | Health data privacy cases under state law | 1: Healthline Media LLC, a settlement of $1.55 million (July 1, 2025) | Release | |
| Washington attorney general | Cases under the My Health My Data Act | 0 found | AG page |
| Announced | Organization | Action | Amount |
|---|---|---|---|
| October 17, 2024 | Gums Dental Care, LLC, MD | Civil money penalty | $70,000 |
| November 19, 2024 | Rio Hondo Community Mental Health Center, CA | Civil money penalty | $100,000 |
| January 15, 2025 | Memorial Healthcare System, FL | Settlement | $60,000 |
| March 6, 2025 | Oregon Health & Science University, OR | Civil money penalty | $200,000 |
| December 16, 2025 | Concentra, Inc. | Settlement | $112,500 |
| August 27, 2026 | Azul Vision, Inc., CA | Settlement | $50,000 |
| Total | $592,500 | ||
Information blocking claims are complaints received, not findings, and one claim can name more than one type of organization. Breach reports are each organization's own count. The window matches the one our stories use, so older cases such as GoodRx (2023) and the Change Healthcare breach (reported in 2024) are outside it.
How fair is 48?
This section tests whether the index treats the US the same way as four similar countries. A separate automated review, run by an AI agent, looked for every way the US score could be too high or too low, category by category, against the UK, Canada, Australia and Germany (our internal fairness audit, October 3, 2026). Here is what it found.
The audit found the band holds. Under every way of treating the countries evenly that the audit tried, the US stays Mixed. Where the rubric gives exact steps (access, control, research and AI), the US score holds up, and the US is scored by the same steps as Canada.
The audit found the score slightly low. Where the rubric has no exact steps (privacy and protection from commercial use), the comparison does not treat every country the same way, and mostly this works against the US:
- The US commercial score leaves out how the FTC enforces its health breach rule. Canada's regulator has no similar power. The UK's commercial score did not look at apps or data brokers.
- The US privacy score counts people affected by breaches. Canada and Australia count incidents, and the UK and Germany give no national breach figure. Only the US has a public register that counts people.
- Only the US and Australia were checked for police access to records.
- Canada was scored on the laws of four provinces. The US was scored on federal law, with state law in only a few places and none for control.
Applying the fixes the audit could verify, the US would score 49.55, which rounds to 50: tied for 51st instead of tied for 55th. That is still Mixed. Applying only the fixes that lower the US score gives 47. The highest score the audit argues for, counting fixes it could not yet verify, is 54. Our own computed score range for the US (the middle 90% of simulations that allow for scoring error) is 43 to 53.
Comparisons that are too fragile to quote. The US commercial score (38) is the lowest of the 38 OECD countries, but only 4 points below Chile (42). Scores move in steps of about 5 points, so "last in the OECD" is not a finding. Nor is 48 a precise number: read it with its range.
The US score will not change in this version. The audit proposes 4 written rules. They cover how to score countries without a national system and using one unit for breaches. They also say proposed laws earn no credit or penalty, and areas no one checked count as missing. The US score moves only in version 1.1 of the index, when those rules are written and applied to every country, not to the US alone.
What would raise the US score: what the scoring rules reward
These are the legal changes the published scoring rules reward, at the low end of each step. This is a description of the scoring rules, not a recommendation. A proposed law earns nothing until it is in force.
- Patient control and consent 20% · now 35
A working way to say no to sharing in care (an opt-out or opt-in), or a log you can see of who opened your record in care, including routine care. Either one puts control at 40 to 55. Both, plus finer choices about who sees what: 60 to 80. At the low end, this adds 1.0 points to the overall score. Both, plus finer choices, add 5.0. - Patient access to the full record 20% · now 50
A national portal that shows part of the record (a summary, prescriptions and lab results) to most residents: 60 to 75. At the low end, this adds 2.0 points to the overall score. - Protection from commercial use 10% · now 38
A privacy law that covers health data held outside HIPAA, by apps, wearables and data brokers, with limits on selling it or using it for ads. This category has no numbered step in the rubric yet; reaching the Mixed range starts at 45. At the low end, this adds 0.7 points to the overall score. - Research and trial consent 5% · now 49
A general way to opt out of research use of your record, honored in practice: 55 to 70. At the low end, this adds 0.3 points to the overall score.
All four together, each at the low end of its step, would give about 52 (tied for 47th on today's data). That is still Mixed. The next band, Strong, starts at 65, so it would take more than these changes at their lowest.
States, coming next
HIPAA sets a floor, and states can add to it. We are now researching what each of the 50 states and the District of Columbia adds. We are looking at 7 areas:
- health data held outside HIPAA, such as by apps and brokers
- rights to a copy that go further than HIPAA's
- the consent rule for the state's health information exchange
- extra rules for sensitive records (reproductive, mental health, HIV and genetic)
- whether a person can go to court on their own
- whether breach laws cover health data
- rules for AI in care
Each state will get a profile with the law quoted and dated. There will be no state total and no state ranking. Beside each profile, we will show public statistics on conditions that affect whether people can use these rights. Examples are income, health insurance and internet access at home. These statistics will not be scored. The national score will not change. No state results are published yet.
Stories, brief and data
What people report
9 published accounts from the US, from regulators, courts and the news, sit beside the score without changing it.
- July 29, 2026 Federal and state regulators sue telehealth company over sharing health details with advertisers U.S. Federal Trade Commission, allegation, not proven
- December 16, 2025 Six requests and more than a year before a patient got his records U.S. Department of Health and Human Services, Office for Civil Rights, regulator or court finding
- September 30, 2025 Care provider posted patient stories online without written permission U.S. Department of Health and Human Services, Office for Civil Rights, regulator or court finding
- July 1, 2025 Health website shared article titles that could reveal a reader's diagnosis California Department of Justice, Office of the Attorney General, regulator or court finding
- April 2025 Second round of refunds after counseling service shared users' health answers with advertisers U.S. Federal Trade Commission, regulator or court finding
- March 6, 2025 Patient's full records arrived more than two years after her representative first asked U.S. Department of Health and Human Services, Office for Civil Rights, regulator or court finding
- January 24, 2025 Insurer confirms health data of about 190 million Americans hit in one attack TechCrunch, admitted by the organization
- January 15, 2025 Patient asked by mail, phone and portal, then waited about nine months U.S. Department of Health and Human Services, Office for Civil Rights, regulator or court finding
- November 18, 2024 Patient asked for her records in writing in March and got them in October U.S. Department of Health and Human Services, Office for Civil Rights, regulator or court finding
Open the United States on the globe · Stories from every country
More on the United States
Health Record Rights Index, version 1.0, by SuperTruth. Everything here comes from public information: laws, agency pages, court records and published news. SuperTruth built this index and sells health data verification products; no one paid to be included. Research tool, not legal advice. Text and scores CC BY 4.0.