Medical Records and Public Access: Where the Wall Is
Health information is among the most protected data in the U.S. Understand exactly how HIPAA limits what enters the public record.

Photo: searchopenrecords editorial
—— In This Article
Key Takeaways
- Medical records are not part of the public record system in the United States.
- HIPAA restricts disclosure to covered entities — hospitals, clinics, insurers, and their business associates.
- Patients themselves have the right to request and obtain copies of their own records.
- Narrow exceptions exist for public health reporting, court orders, and certain research purposes.
- Death does not immediately make a person's medical history publicly accessible.
Why Medical Records Are Treated Differently
Most public records exist because governments create and maintain them for accountability or administrative purposes — court filings, property deeds, vital records. Medical records are different. They are created by private healthcare providers for clinical purposes, and Congress has explicitly walled them off from the general public record system.
That wall has a name: HIPAA. Enacted in 1996, the law recognizes that health information is uniquely sensitive. A diagnosis, a prescription history, or a mental health treatment note can affect someone's employment, relationships, insurance, and personal safety if disclosed without consent. The Privacy Rule therefore treats individually identifiable health data as a protected category by default, not as information that is public unless otherwise restricted.
This design is the opposite of how most government records work. With public records, the default is openness and exceptions carve out privacy. With medical records, the default is privacy and exceptions carve out limited access. Understanding that structural difference helps explain why medical information almost never appears in background checks, public databases, or records searches. For a broader view of how federal law shapes what enters the public record at all, see our explainer on federal privacy laws that shape what you can access.
Who HIPAA Applies To — and Who It Doesn't
HIPAA binds covered entities: hospitals, physicians, pharmacies, health insurance plans, and healthcare clearinghouses. It also extends to their business associates — contractors who handle PHI on their behalf, such as billing companies or cloud storage vendors.
Critically, HIPAA does not bind everyone. If you tell a neighbor about a health condition and that neighbor tells others, HIPAA has no jurisdiction. If a journalist obtains medical information through sources outside the covered-entity system, the law does not prevent publication — though other legal and ethical standards may apply. The law governs the flow of records from the healthcare system, not the behavior of private individuals.
Your Right to Your Own Records
If you need a copy of your own medical records, contact the health information management or medical records department at the provider directly. Under HIPAA, they must respond within 30 days. You may be charged a reasonable cost-based fee, but you cannot be denied access simply because you have an outstanding balance with the provider.
This gap matters in practice. Records that patients voluntarily share — in social media posts, memoir excerpts, or legal filings they themselves submit — can enter the public sphere. HIPAA does not protect information that the patient has chosen to disclose publicly.
Narrow Exceptions to the Privacy Default
HIPAA lists specific circumstances where covered entities may disclose PHI without patient authorization. These are not loopholes — they are tightly scoped by regulation and generally require the minimum necessary information:
- Treatment, payment, and operations: Providers can share records among themselves for direct patient care.
- Public health activities: Reporting communicable diseases to state health departments or the CDC is permitted, but only to authorized public health authorities.
- Court orders and legal proceedings: A judge may compel disclosure, but the order must be specific. Even then, providers typically produce records to the court, not to the general public.
- Law enforcement: Limited disclosures are permitted for specific law enforcement purposes, subject to defined conditions.
- Research: Approved research may access PHI under strict protocols, including de-identification or Institutional Review Board oversight.
None of these exceptions open medical records to unrestricted public inspection. They allow narrow, regulated flows of information for defined purposes. For context on how this balance is struck across different record types, see how public interest and personal privacy are balanced in practice.
18
Identifiers HIPAA requires removed for de-identification
The HHS Office for Civil Rights specifies 18 categories of information that must be removed before health data is considered de-identified and no longer subject to HIPAA's Privacy Rule.
50 years
Post-death PHI protection period under HIPAA
HIPAA extends privacy protections to deceased patients for 50 years following their death, according to the HHS Privacy Rule at 45 CFR 164.502(f).
30 days
Maximum response time for patient record requests
Under the HIPAA Privacy Rule, covered entities must act on a patient's request to access their own records within 30 days, with one possible 30-day extension if notice is provided.
Where Medical Details Can Indirectly Surface
Even though medical records themselves are protected, health-related information can sometimes appear in adjacent public documents — not because HIPAA was bypassed, but because other record systems don't carry the same restrictions.
Court records: Disability litigation, personal injury suits, workers' compensation cases, and probate proceedings may reference medical conditions. If those documents are filed in a court without a sealing order, they may be publicly accessible through court record systems.
Death certificates are another example. Cause of death is typically listed on a death certificate, which is a public vital record in most states. The certificate reflects a clinical determination, but it is maintained by a government vital records office — not a covered entity — and is generally accessible to the public, subject to state-specific rules. This is one reason genealogical research can surface health information about ancestors long deceased. Our guide to historical records access explains how these documents fit into a genealogy search.
It is also worth noting what does not surface: detailed treatment notes, lab results, imaging reports, medication histories, and psychiatric records. These stay within the healthcare system unless a patient explicitly authorizes their release. If you are curious about the broader scope of what background checks can and cannot access, the article on records that almost never appear in a standard background check covers this in detail.
This article is for general informational purposes only and does not constitute legal advice. For questions about your specific health records rights, consult a qualified attorney or your healthcare provider's privacy officer.
