United States · in depth

Health record rights in the United States

The answer: 48 of 100, Mixed

In 2026, the United States scores 48 of 100 on a person's right to see, control and share their own health record. That puts it in a tie for 55th of 198 countries; allowing for scoring error, its likely rank is 45th to 80th. It sits in the Mixed band (45 to 64).

The US scores above the median of 39 across all 198 countries, but below the UK (59), Canada (52), Australia (66) and Germany (63). Its two lowest scores are control over who sees the record (35) and protection from commercial use (38). They are its only scores in the Weak range. Both are below all four of those countries.

48score of 100
55thrank of 198 (tied)
45 to 80likely rank
Mixedband, 45 to 64
Institutionalwho holds the keys
highconfidence

Data as of · page updated · version 1.0

Not legal advice. This page explains how our index scores the United States and what US law says, in plain English. Laws change, and your situation may differ. For advice about your own records, ask a lawyer or the agency named in each section.

Who holds the keys: Institutional. Providers and insurers decide. Doctors, hospitals and insurers each keep their own records, and there is no national health record.

On this page:

  1. The eight categories
  2. US law in plain English
    1. Your HIPAA right of access: getting a copy
    2. Who decides who sees your record
    3. Information blocking: the Cures Act rule
    4. Your insurer's data: the Patient Access API
    5. Connecting records: TEFCA
    6. What HIPAA does not cover
    7. Health apps: the FTC and its cases
    8. Security, breaches and police access
    9. State laws
    10. Rules for AI in care
    11. Research
  3. The enforcement record
  4. How fair is 48?
  5. What the scoring rules reward
  6. States, coming next
  7. Stories, brief and data

The eight categories, against the world and four peers

The US scores above the world median in 7 of 8 categories. It scores below all four comparison countries in 3: control over who sees the record, privacy and protection from commercial use. Access to the record and control over it count most, 20% each.

Scores out of 100, data as of October 2, 2026, 198 countries. Black dot: the US. Gray line: the median (middle score) of all 198 countries; light bar: the middle half of them. Hollow dots: the UK, Canada, Australia and Germany; where dots overlap, read the numbers. Ticks mark the band edges (25, 45, 65, 85).
Category and weightUSMedianUKCanadaAustraliaGermanyPosition on a 0 to 100 scale
Overall483959526663UK 59Canada 52Australia 66Germany 63United States 48
Patient access to the full record 20%504366507064UK 66Canada 50Australia 70Germany 64United States 50
Patient control and consent 20%353052556866UK 52Canada 55Australia 68Germany 66United States 35
Privacy and security 15%504556586258UK 56Canada 58Australia 62Germany 58United States 50
Connected care journey 15%603862507066UK 62Canada 50Australia 70Germany 66United States 60
Protection from commercial use 10%384560456570UK 60Canada 45Australia 65Germany 70United States 38
Clinician access at the point of care 10%553460556662UK 60Canada 55Australia 66Germany 62United States 55
Research and trial consent 5%494664495050UK 64Canada 49Australia 50Germany 50United States 49
Clinical AI governance 5%563055565550UK 55Canada 56Australia 55Germany 50United States 56

US law in plain English

The US has no single national health record and no one privacy law for all health data. Your rights come from several federal laws, each with its own reach, and from state laws that differ from state to state. Each claim below links to the law or the agency page we read. We checked the federal law against those sources on October 3, 2026.

Your HIPAA right of access: getting a copy

Under HIPAA, a doctor, hospital or health plan must act on your request for your records within 30 days. It may take one 30-day extension (45 CFR 164.524). The right covers your medical and billing records. It does not cover a therapist's separate psychotherapy notes or files prepared for a lawsuit. If you ask for an electronic copy in a form they can readily produce, they must give it to you that way. They may charge only a cost-based fee: the labor of copying, supplies, postage, and a summary if you agree to one.

The Office for Civil Rights (OCR) at the Department of Health and Human Services (HHS) enforces this right. It has brought 55 right of access cases since 2019 (HHS, August 27, 2026). HHS plans to propose a change to the response time in November 2026. The plan does not say whether the time would get shorter or longer (federal rulemaking agenda).

Who decides who sees your record

HIPAA lets providers and health plans share your records for treatment, payment and their own operations without asking you (45 CFR 164.506). You can ask them to limit sharing, but they can say no. One exception: if you pay for an item in full yourself, they must keep it from your health plan when you ask (45 CFR 164.522). You can get a list of disclosures from the past six years, but it leaves out sharing for treatment, payment and operations (45 CFR 164.528). So it does not show who saw your record in routine care. Records from substance use treatment have extra protection. Since February 16, 2026, one signed consent can cover future uses for treatment, payment and operations (42 CFR Part 2 rule).

Information blocking: the Cures Act rule

Under the 21st Century Cures Act rule, it can be against the law to block your access to your electronic health information. The rule calls this "information blocking." It covers providers, health IT developers and health information networks. A practice counts if it is likely to interfere with getting, sharing or using electronic health information (45 CFR Part 171). A provider breaks the rule only if it knows the practice is unreasonable. There are ten exceptions, such as preventing harm, privacy, security and requests that are not feasible. One exception allows some fees. It does not allow a fee for viewing your own records online.

Health IT developers and networks can face penalties of up to $1 million per violation, the figure in the law before inflation adjustments (42 U.S.C. 300jj-52). Providers do not face these money penalties. Since July 2024, a hospital or clinician found to be blocking can instead face what HHS calls "disincentives" in Medicare programs (HHS rule, 2024). In September 2025, HHS announced what it called a "crackdown" on information blocking (HHS). As of May 27, 2026, the HHS Inspector General had published no information blocking penalties (OIG).

Your insurer's data: the Patient Access API

Since January 1, 2021, some health plans have had to offer a Patient Access API (42 CFR 422.119, 431.60 and 457.730; 45 CFR 156.221; the Centers for Medicare & Medicaid Services, CMS). An API, or application programming interface, is a standard way for apps to get data. Here it lets patients get their plan's data electronically. The rule covers Medicare Advantage plans, Medicaid, the Children's Health Insurance Program (CHIP) and plans on the federal marketplace. A 2024 rule, CMS-0057-F, adds prior authorization data to it. It also requires two more connections, one to your doctors (Provider Access) and one between insurers (payer-to-payer), mostly by January 1, 2027 (CMS-0057-F). You will be able to opt out of the Provider Access exchange (CMS fact sheet).

Connecting records: TEFCA

TEFCA (the Trusted Exchange Framework and Common Agreement) is a national framework that lets health networks exchange records with each other. HHS says the number of records exchanged through it grew from 10 million to more than 1 billion in less than a year (HHS, June 2026). There are 11 networks designated to carry TEFCA exchange (list), and 22 apps are listed to fetch records for patients who ask (list). Some of these apps may not be covered by HIPAA, so once your data reaches them, other rules may apply.

What HIPAA does not cover

HIPAA covers doctors, hospitals, health plans and the companies that work for them. It does not cover a health app you download yourself, a fitness tracker or smartwatch, or a data broker that buys and sells data. Inside HIPAA, marketing and any sale of your health information need your written permission (45 CFR 164.508). But data with identifiers removed ("de-identified") is outside HIPAA and can be sold (45 CFR 164.514).

Health apps: the FTC and its cases

For many health apps, the Federal Trade Commission's Health Breach Notification Rule applies instead. The FTC says the rule can apply to health apps and similar technologies (FTC, 2024). Since July 29, 2024, a "breach" under the rule includes sharing your data without your permission, not only a hack (16 CFR Part 318). The rule requires notice. It does not require your consent for each use.

The FTC's first case under the rule was GoodRx in 2023: the company was barred from sharing health data for ads and paid a $1.5 million civil penalty (FTC). The FTC also uses its general power against deception. It barred BetterHelp from sharing health data for ads and required it to pay $7.8 million (2023, FTC). It required Flo Health to get users' consent before sharing their health data (2021, FTC). These orders bind one company each. The enforcement record below counts the FTC's health privacy cases.

Security, breaches and police access

HIPAA requires breach reporting, and the HHS breach portal lists every large breach. A major update to the HIPAA Security Rule was proposed in January 2025; the federal agenda now targets a final rule in July 2027 (rulemaking agenda). Police can get records with a court order or a subpoena, and also with an administrative request when the law requires a response (45 CFR 164.512). A 2024 rule that added protection for reproductive health records was mostly struck down by a federal court on June 18, 2025 (HHS; court docket). The official online copy of the regulations still shows the struck-down rule. The court's ruling is what counts.

State laws

Some states add their own rules. Washington's My Health My Data Act covers health data outside HIPAA. Since March 31, 2024, no one may sell a person's consumer health data there without the person's signed permission; small businesses had until June 30, 2024 (RCW 19.373.070). New York's legislature passed a similar bill, which was vetoed on December 19, 2025 (NY Senate). Texas requires electronic health records to be stored in the United States from January 1, 2026 (Texas SB 1188). Our national score credits state law only in a few places; the state layer below will look at every state.

Rules for AI in care

The FDA regulates AI tools that count as medical devices and lists about 1,600 of them (FDA). Its final guidance from August 2025 lets makers plan approved updates in advance (FDA guidance). HHS lists two rules as in force. Certified health record systems must show users who built a predictive tool, what it is for, its known risks and what data trained it. HHS proposed removing those requirements in December 2025; no final rule had been published when we checked (HTI-5 proposal). Since May 2025, providers that take federal funds must look for decision support tools that use race, color, national origin, sex, age or disability. They must also reduce the risk of bias these tools create (45 CFR 92.210). HHS plans to propose changes to this rule in February 2027. In Texas, practitioners must review records made with AI and tell patients when they use AI for diagnosis (Texas SB 1188).

Research

A review board can let researchers use your records without your permission. The privacy risk must be minimal. The research must also be impractical to do without the waiver or without the data (45 CFR 164.512). A limited data set, with names and other direct identifiers removed, can be shared for research under a data use agreement. De-identified data needs no consent (45 CFR 164.514). There is no general way to opt out of research use. Research that federal agencies fund or run follows the Common Rule, which requires informed consent or a board waiver and allows "broad consent" to future research (45 CFR 46.116). Research funded by the National Institutes of Health that meets set criteria automatically has a Certificate of Confidentiality, a federal protection for research records (NIH).

The enforcement record

From October 1, 2024 to October 1, 2026, OCR announced 6 right of access actions (3 civil money penalties and 3 settlements), totaling $592,500. The Inspector General had published no information blocking penalties. Large breach reports covered 234,919,800 people, counted once per breach, so a person hit twice counts twice. None of this feeds the score.

US enforcement, October 1, 2024 to October 1, 2026, with the record since each program began. Counts and totals are computed from the rows of our enforcement file, built October 3, 2026. A settlement is an agreement to pay; a civil money penalty is imposed by the regulator. Other states' attorneys general were not checked.
Who actsWhat we countedIn the windowSince the start (includes the window)Source
HHS Office for Civil Rights (OCR)Right of access actions: a provider or plan was slow to give patients their records6: 3 civil money penalties ($370,000) and 3 settlements ($222,500). Total $592,500.55 since the program began in 2019OCR list
HHS Inspector GeneralInformation blocking penalties published0 (through May 27, 2026)0OIG page
HHS health IT office (ONC) complaint portalInformation blocking claims that name a health care provider. Claims received, not findings1,042 (Oct 2024 to Jul 2026)1,938 since April 5, 2021Claims data
Same portal, all claimsClaims filed by patients, whatever organization they name. One claim can name more than one type of organization, so this is not a share of the row above900 (Oct 2024 to Jul 2026)1,554
Federal Trade Commission (FTC)Health privacy cases: those the FTC tags "Health Privacy", plus Cerebral2 with a new complaint or order: Hims & Hers Health (complaint, pending); Kochava Inc. and Collective Data Solutions. 2 where the only new step was refunds: BetterHelp; Cerebral (refunds for cancellation practices, not health data).20 casesCase pages, linked
HHS OCR breach portalBreaches of 500 or more people, reported by HIPAA-covered organizations1,546 reports. 34 affected 1 million people or more. 234,919,800 people in all, counted once per breach. Largest: Conduent Business Services LLC, 62,224,658.Breach portal
California attorney generalHealth data privacy cases under state law1: Healthline Media LLC, a settlement of $1.55 million (July 1, 2025)Release
Washington attorney generalCases under the My Health My Data Act0 foundAG page
The 6 OCR right of access actions in the window, by date
AnnouncedOrganizationActionAmount
October 17, 2024Gums Dental Care, LLC, MDCivil money penalty$70,000
November 19, 2024Rio Hondo Community Mental Health Center, CACivil money penalty$100,000
January 15, 2025Memorial Healthcare System, FLSettlement$60,000
March 6, 2025Oregon Health & Science University, ORCivil money penalty$200,000
December 16, 2025Concentra, Inc.Settlement$112,500
August 27, 2026Azul Vision, Inc., CASettlement$50,000
Total$592,500

Information blocking claims are complaints received, not findings, and one claim can name more than one type of organization. Breach reports are each organization's own count. The window matches the one our stories use, so older cases such as GoodRx (2023) and the Change Healthcare breach (reported in 2024) are outside it.

How fair is 48?

This section tests whether the index treats the US the same way as four similar countries. A separate automated review, run by an AI agent, looked for every way the US score could be too high or too low, category by category, against the UK, Canada, Australia and Germany (our internal fairness audit, October 3, 2026). Here is what it found.

The audit found the band holds. Under every way of treating the countries evenly that the audit tried, the US stays Mixed. Where the rubric gives exact steps (access, control, research and AI), the US score holds up, and the US is scored by the same steps as Canada.

The audit found the score slightly low. Where the rubric has no exact steps (privacy and protection from commercial use), the comparison does not treat every country the same way, and mostly this works against the US:

Applying the fixes the audit could verify, the US would score 49.55, which rounds to 50: tied for 51st instead of tied for 55th. That is still Mixed. Applying only the fixes that lower the US score gives 47. The highest score the audit argues for, counting fixes it could not yet verify, is 54. Our own computed score range for the US (the middle 90% of simulations that allow for scoring error) is 43 to 53.

Comparisons that are too fragile to quote. The US commercial score (38) is the lowest of the 38 OECD countries, but only 4 points below Chile (42). Scores move in steps of about 5 points, so "last in the OECD" is not a finding. Nor is 48 a precise number: read it with its range.

The US score will not change in this version. The audit proposes 4 written rules. They cover how to score countries without a national system and using one unit for breaches. They also say proposed laws earn no credit or penalty, and areas no one checked count as missing. The US score moves only in version 1.1 of the index, when those rules are written and applied to every country, not to the US alone.

What would raise the US score: what the scoring rules reward

These are the legal changes the published scoring rules reward, at the low end of each step. This is a description of the scoring rules, not a recommendation. A proposed law earns nothing until it is in force.

All four together, each at the low end of its step, would give about 52 (tied for 47th on today's data). That is still Mixed. The next band, Strong, starts at 65, so it would take more than these changes at their lowest.

States, coming next

HIPAA sets a floor, and states can add to it. We are now researching what each of the 50 states and the District of Columbia adds. We are looking at 7 areas:

Each state will get a profile with the law quoted and dated. There will be no state total and no state ranking. Beside each profile, we will show public statistics on conditions that affect whether people can use these rights. Examples are income, health insurance and internet access at home. These statistics will not be scored. The national score will not change. No state results are published yet.

Stories, brief and data

What people report

9 published accounts from the US, from regulators, courts and the news, sit beside the score without changing it.

Open the United States on the globe · Stories from every country

More on the United States

Health Record Rights Index, version 1.0, by SuperTruth. Everything here comes from public information: laws, agency pages, court records and published news. SuperTruth built this index and sells health data verification products; no one paid to be included. Research tool, not legal advice. Text and scores CC BY 4.0.