Medical groups say the new federal data-sharing rules, allowing patients to access health records through apps, lack strong data protections to preserve privacy
Americans may soon be able to get their medical records through smartphone apps as easily as they order takeout food from Seamless or catch a ride from Lyft. Tweets: @yoda , @yoda , @yoda , @ragnarsmate , @went1955 , @nytimestech , @farzad_md , and @drleanawen Tweets: Drew Olanoff / @yoda : we simply cannot fathom in our brains a massive data breach of private medical information. the ramifications would make facebook's issues look like a traffic ticket. https://twitter.com/... Drew Olanoff / @yoda : i cannot stress this enough: we need to move EXTREMELY slow on this and *listen* to experts. and lots of experts. https://twitter.com/... Drew Olanoff / @yoda : if we get this one wrong, there's no going back....and it's gonna be bad. https://twitter.com/... @ragnarsmate : Estonia has done this. Patient heath data is stored & secured by blockchain and access is gained by use of an ID system secured by the same. Patients can see which doctors accessed their records any time they want. https://e-estonia.com/... https://twitter.com/... Robert Went / @went1955 : Americans may soon be able to get their medical records through smartphone apps. But prominent medical organizations are warning that patient data-sharing with apps could facilitate invasions of privacy, and they are fighting the change https://www.nytimes.com/... @nytimestech : People who authorized an app to collect their medication lists would not be able to stop it from retrieving specific data — like the names of H.I.V. or cancer drugs — they might prefer to keep private. https://www.nytimes.com/... https://twitter.com/... Farzad Mostashari / @farzad_md : A complex issue wrt data protection, but I'm with @donrucker “patients have a right to choose as opposed to the right being denied them by the forces of paternalism” Getting Your Medical Records Through an App? There's a Catch. And a Fight. https://www.nytimes.com/... Leana Wen / @drleanawen : Fair warning by @AmerMedicalAssn & other medical orgs: be careful of medical record-sharing apps. Patients need control over our own medical records, but also need oversight to protect personal information https://www.nytimes.com/...
Context & Ripple Effects
This 2019 warning landed mid-fight over the federal interoperability rules: Epic Systems had already called on large hospitals to oppose the draft rules, arguing open record access exposed patients, while reporting on Google's Project Nightingale showed exactly the mass-collection scenario privacy critics feared when third parties get medical data.
First-order effects
- The administration pressed ahead anyway, finalizing rules that let patients pull records into any app of their choice, putting hospitals and EHR vendors on the hook for sharing while app developers face no equivalent safeguard requirements.
- Patients gain takeout-style access to their records, but data flowing to consumer apps sits largely outside the protections governing providers.
Second-order effects
- Vendors like Epic, which fought the rules as too risky, are positioned to argue their closed systems were the safer design as breaches of third-party apps would vindicate their stance — while Google's healthcare ambitions draw sharper scrutiny with each new access channel.
Third-order effects
- With the rules taking effect in October 2022, consumer medical data structurally moves beyond HIPAA's perimeter, pointing toward a regulatory gap where app-side privacy law lags mandated provider-side sharing — a gap England's NHS plan to share 55M patient histories with third parties widens internationally.
The trend: Health systems worldwide are mandating patient access to digital records faster than privacy law extends to the third-party apps receiving them.