Last Update: 08/01/2026 at 12:00 PM EST
Health Data Access And Privacy Gaps
Coverage from Bipartisan Policy Center, Fierce Healthcare, and others
Articles
3
Active Days
560
The Topic

Federal health data rules are expanding patient access and record portability through APIs while leaving a major privacy gap for third-party apps that fall outside HIPAA. The main tension is between interoperability and weaker downstream data protections.
First Article: 03/11/20
Latest Article: 09/21/21
Summary
- Federal interoperability rules require API access to electronic health records and support broader patient data export.
- The main privacy gap appears after data leaves hospitals and insurers, where consumer apps may not be covered by HIPAA.
- Enforcement and accountability remain uneven, with penalties delayed and oversight shifting toward lighter consumer protection tools.
- Policy discussion repeatedly returns to the tradeoff between patient access and the risk of opaque app data practices.
- Health privacy legislation is being discussed as a way to cover data that moves outside traditional health-care privacy rules.
History
This topic is new, but as new articles are added to it this area will summarize shifts, changes and expansions of the issues.
