Last Update: 08/01/2026 at 2:00 PM EST
Health privacy notices and data controls
Coverage from UMass Memorial Health, Brook Lane, and others
Articles
4
Active Days
176
The Topic

Recent privacy notices from health providers and state agencies set out how protected health information is used, shared, retained, and disclosed under HIPAA. The recurring pattern is controlled sharing for care and operations, paired with patient access rights, opt-outs, special protections for sensitive records, and complaint or breach procedures.
First Article: 01/01/00
Latest Article: 02/16/26
Summary
- HIPAA notices remain the dominant form of current privacy action, especially in health systems and public agencies.
- The notices consistently allow use of protected health information for treatment, payment, operations, public health, and other legally required disclosures.
- Patients and clients are repeatedly given rights to access records, request corrections, restrict some uses, and receive accounting of disclosures.
- Several notices add stronger limits for sensitive categories such as substance use, mental health, sexual assault, HIV/AIDS, and reproductive health data.
- Health information exchange participation appears as a recurring issue, often with explicit opt-out language or disclosure controls.
- One notice explicitly describes AI-enabled tools used with human oversight, suggesting growing operational use of AI inside health data workflows.
- Breach notification and complaint pathways remain standard features, indicating a compliance-heavy privacy posture rather than a disputed or unstable policy environment.
History
This topic is new, but as new articles are added to it this area will summarize shifts, changes and expansions of the issues.
