from the seems-bad dept
This article is republished from The Conversation under a Creative Commons license. Read the original article.
You might assume that what you tell a doctor stays between you, your physician and perhaps your insurer. But the reality is more complicated.
The Health Insurance Portability and Accountability Act, the federal privacy law that governs health information and is commonly known as HIPAA, is narrower than its reputation suggests. It regulates hospitals, physicians, insurers and their business associates, but not the health data you generate everywhere else: not the period-tracking application on your phone, the internet search you ran about a diagnosis, the DNA you mailed to a genealogy company or the wearable that counts your heartbeats.
Even the records HIPAA does cover can be shared, sold or handed to the government in ways that might surprise you.
This gap in protection matters more than ever because the U.S. government is pushing hard to gather health data domestically and abroad. This is happening even as a growing body of research shows that the safeguard which these efforts to collect data lean on – anonymizing data by removing identifying information to make it difficult to trace back to an individual – is far weaker than officials claim.
As a professor of law at Indiana University, I study health information privacy and medical data regulation, which includes tracing how sensitive health information moves among clinics, government agencies and law enforcement. As a co-investigator on a federally funded study about opioid prescribing, I rely on health data in my own research. I appreciate its value for science, and I also see the danger of collecting it without meaningful safeguards.
Limits of medical privacy
HIPAA gives you several rights: You can see your health records, demand corrections and expect that a covered provider will not casually disclose your information.
But the law also permits release of some information without your consent. A hospital fully bound by HIPAA may release certain types of records without your authorization and without telling you. There are roughly a dozen such categories. Information about treatment, payment and routine healthcare logistics require no sign-off. Neither does information released for public health reporting, law enforcement, judicial and administrative proceedings, health plan oversight, research or the broad catchall of essential government functions.
The statute is also thick with additional exceptions. In practice, much of your health information can be shared through these many open doors. And once data is sent outside the system covered by HIPAA, the HIPAA limits fall away.
For instance, prescription drug monitoring programs, which every state now operates, assemble detailed logs of who filled which controlled substance prescription and when. Federal law enforcement can often access these logs with a self-issued administrative subpoena – an order that doesn’t require a judge’s approval or oversight.
These programs have expanded beyond opioids into a dragnet that shares health data across state lines, exposing patients who seek reproductive or gender-affirming healthcare to surveillance far from home.
Health records can flow to many destinations under different rules. A given disclosure might feel more like a violation depending on who decides where it can go and who can then see it.
RFK Jr.’s push to access Americans’ health records
Since the spring of 2025, Health and Human Services Secretary Robert F. Kennedy, Jr. has sought federal access to Americans’ medical records to investigate whether vaccines cause autism. The scientific community has studied this question for decades and has shown decisively that they do not.
According to KFF Health News, HHS has been courting state health information exchanges – the little-known systems that let hospitals and clinics swap detailed, identifiable patient records – and asking how those records might be used for vaccine research. One proposal floated by state organizations would give HHS data on 90% of Americans’ medical records by 2028. In Nebraska, millions of federal grant dollars have flowed to a statewide health information exchange nonprofit that has cooperated with the effort.
Large health datasets can be useful. Pooled records can expose drug side effects, track outbreaks and reveal disparities in care that smaller studies miss. Public health has always depended on some surrender of individual privacy for collective benefit.
The concern is not that the government should never collect health data. It is that meaningful safeguards have not kept pace with the scale of collection and capabilities of modern data analytics.
In seeking access to Americans’ medical records for a vaccine and autism study, HHS has declined to say how many states are involved, what data it collects, who can see it or how it will be protected.
Building a comprehensive repository to chase a question that science has already answered inverts the logic of research. Usually a hypothesis justifies the data collected, rather than the reverse.
Collecting identifiable records for tens of millions of people in a single database also creates a target for breaches, secondary uses that no one consented to and abuses by current or future administrations with different priorities.
‘Anonymized’ doesn’t protect your health privacy
Officials have offered reassurances that data will be aggregated and stripped of identifiers so no individual can be singled out.
Decades of computer science research undercuts that promise. A study published in Nature in June 2026 sharpened the point, showing that in this age of artificial intelligence, stripping identifiers from patient records to protect identity does not protect all patients equally.
The researchers audited AI diagnostic models trained on clinical data, including chest X-rays, electrocardiograms and electronic health records. They asked whether an outsider could tell if a particular person’s data had been used to build the model. For instance, confirming that someone’s record helped train a cancer-prediction tool can reveal that that person has cancer. This exploit is known as a membership inference attack.
The research team found that while the average risk of being identified from data stripped of identifying information often looked reassuringly low, some patients faced near-certain reidentification The burden fell unevenly: Underrepresented groups, sorted by race, insurance status or diagnosis, were most at risk. Those most exposed were frequently already most vulnerable to discrimination.
Researchers have long established that removing identifiers from rich datasets does not reliably protect the people in them, and that identification gets easier the more information you have. Today’s AI technology makes it possible to carry out these attacks remotely and quickly.
The same privacy problems, exported
The U.S. government’s appetite for health data does not stop at the border. As ProPublica reported in June 2026, the State Department has been conditioning lifesaving aid to African nations on access to their citizens’ health data.
Under the Trump administration’s global health plan, Uganda agreed to give the United States real-time access to nine of its health data systems for seven years, including the central repository of the nation’s health information and the system managing individual electronic medical records, in exchange for up to US$1.7 billion over five years, a sum that shrinks each year and falls below prior U.S. support. Kenya struck a similar deal; Zambia, Zimbabwe and Ghana walked away from the initial terms.
The U.S. government has promised that the data will be aggregated and anonymized, but privacy experts warn that the agreements are vague and omit standard limits on how much data is taken and how it can be used. A Ugandan digital rights lawyer called the choice his country faced the essence of digital colonialism: Accept the deal and risk exploitation, or refuse it and watch people die.
The common thread
Domestic records collection and foreign data-for-aid deals rest on the same faith that anonymization neutralizes the risk of pooling sensitive health data.
The evidence says otherwise. This does not mean health data should never be gathered or studied, but I believe that the reassurances deserve skepticism, the safeguards deserve scrutiny, and the people whose bodies generated the data deserve a say. To safeguard privacy, a government seeking sensitive medical records should have to show why it needs them and how the safeguards it relies on hold up.
Privacy law was built for a world where data resided in filing cabinets. Governments from Kalamazoo to Kampala now operate in a world where even an anonymized digital record can point back to you.
Jennifer D. Oliva is Professor of Law, Indiana University
Filed Under: autism, hipaa, medical records, privacy, research, rfk jr., vaccines
Comments on “RFK Jr. Wants Your Medical Records”
But even without this implicit threat, a lot of countries are just handing their data to the U.S. Including, notably, much of Europe—although every few years that’s determined to be illegal, and then some bureaucrats make it retroactively legal again based on new U.S. promises (alright, fool me eight times…).
Anti-vaxxers, “medical choice”, and medical choice.
Anti-vaxxers love to speechify about “medical choice”. To hear an RFK Jr. cult apologist AC who sometimes trolls the comments here, some purported medical choices are sacred! In RFK Jr.’s own 2021 book, a front-matter blurb from conspiracy nut Naomi Wolf begins, “RFK Jr. is a tireless champion of Americans’ rights to be informed about their medical choices…”
Where are they now?
Are they hiding in the same place where they go, when certain other choices about medical care are directly attacked by their hero? (N.b., the second link is old news about a bad milestone in a still-developing story.)
HIPAA is about medical choice—not the choice to grant or refuse informed consent to medical treatment, but choices about access to your private medical records. HIPAA consent forms are one of the few bits of bureaucratic red tape that I myself have always liked. However, as Professor Oliva’s article explains, HIPAA has gross inadequacies which are not only problematic in themselves, but also ripe for exploitation by that noble guardian of medical choice: RFK Jr.
This mass-invasion of medical privacy does not only infringe upon privacy choices: As a second-order effect, I myself observe that it has a chilling effect on informed consent to treatment. Reading this article, I suddenly feel like I never want to see a doctor again—because I want to “opt out” of this monstrous system, which I never opted in to! I cannot take back all of my existing medical records, but I feel like taking care of my health will give even more juicy data to RFK Jr.
This could be most problematic of all for people with uteri, who need to keep their fertility data secure and private to avoid the growing problem of pregnancy criminalization. But it affects everybody.
To avoid exposing one’s data to Google, Meta, ExTwitter, Microsoft, Amazon, et al., one can start by choosing not to use them. (It’s inadequate due to third-party tracking across the Web; use Tor Browser!) Whereas this is a state action which, like state censorship, cannot be avoided by any reasonable means.
Anti-vaxxers want “medical choice” like conservatives want “self-reliance and limited government”, Christian Nationalists are “compassionate” to the poor, Elon Musk is a “free speech absolutist”, RFK Jr. wants to Make America “Healthy”, and Trump wants to Make America “Great”. 🄯 impurify
Man, republicans really love creating lists of people so long as it isn’t pedophiles.
Re:
The pedophiles go on a different list. That list is cross-referenced to how much wealth they have or how useful they can be. If they don’t have enough money, they can crack some skulls for the regime to keep that information quiet.
Re:
The pedophile list is called the “RNC.”
Re:
To be fair, it would be redundant for Republicans to make a list of pedophiles. They already have donor lists.
OK, data brokers and other HHS dipshits. You can have momentary access to everything, if, and only if, you run this query, and we can all agree to accept whatever the verified data have to say:
SELECT
CASE
WHEN (SELECT COUNT() FROM people_with_autism WHERE vaccinated = ‘no’) <
(SELECT COUNT() FROM people_with_autism WHERE vaccinated = ‘yes’)
THEN ‘yes, ok, fine, we’ll look into it’
ELSE ‘no, fuck off, accept the data, and shut the fuck up about it’
END AS is_there_anything_here;
Let that be the end of it.
Well, the MAGA faithful will have their records collected by the government, as well. Still think Diaper Don is Great?
Facts Only
* HIPAA governs health information privacy.
* HIPAA regulates hospitals, physicians, insurers, and business associates.
* HIPAA does not govern all health data generated elsewhere (e.g., phone apps, internet searches).
* HIPAA permits the release of some information without consent, including for public health reporting, law enforcement proceedings, and research.
* Prescription drug monitoring programs assemble logs of controlled substance prescriptions.
* Federal law enforcement can access certain prescription logs via administrative subpoenas.
* Health data can flow outside HIPAA-covered systems where HIPAA limits do not apply.
* The Health and Human Services Secretary sought federal access to medical records to investigate vaccine causes of autism.
* Pooled health records can expose drug side effects, track outbreaks, and reveal disparities in care.
* Research on AI demonstrated that stripping identifiers from patient records does not reliably protect privacy, showing potential for reidentification through membership inference attacks.
* The U.S. government has engaged in foreign data-for-aid deals involving health data access with nations like Uganda.
Executive Summary
Full Take
The narrative surrounding health data privacy is built upon a tension between established legal frameworks and the reality of modern data collection capabilities, particularly when state and international actors are involved. The core pattern involves a shift in trust from physical record-keeping to digital systems, where the assumed safeguards—specifically anonymization—are demonstrated to be insufficient against sophisticated analytical techniques, especially AI. This creates an environment where legitimate public health goals (like vaccine research) can intersect with expansive data access mechanisms without commensurate privacy protection. The implications suggest that the pursuit of large-scale data aggregation for perceived collective benefit often overrides individual control over sensitive medical information, creating a systemic vulnerability that is amplified by global data flows and geopolitical interests. The resistance to this shift is framed not just as a legal dispute but as a defense of personal autonomy against expansive, opaque governmental and corporate surveillance capabilities.
Questions for inquiry include: If anonymization is proven insufficient under AI scrutiny, what specific, non-negotiable technical standards must be mandated for health data aggregation before any government access can be considered legitimate? How can the concept of "informed consent" be meaningfully applied to aggregated public health research when data is automatically repurposed across jurisdictional lines? What mechanisms are necessary to ensure that data-for-aid agreements shift power away from data subjects and toward true accountability?
Sentinel — Human
The text blends substantive analysis of privacy law and data science with highly partisan, emotive commentary, indicating a human author synthesizing complex issues into a specific ideological argument.
