We are currently living in a paperless society, where health data has moved from filing cabinets to electronic health records. This shift raises an important question: who actually has access to this information, and is it truly private? With the growing use of artificial intelligence in healthcare systems, including chatbots and data analysis tools, it can be difficult to know who is viewing or using personal medical information. The reality is that health data may not be as private as many people assume.
Who Owns Medical Records?
You may be surprised to learn that individuals do not technically own their medical records. Legally, healthcare providers, hospitals, and medical institutions control and maintain these records. However, the Health Insurance Portability and Accountability Act (HIPAA) gives patients rights to access their own health information. HIPAA is a U.S. federal law designed to protect sensitive patient data and prevent it from being shared without consent. Even with these protections, control of the records still remains largely with healthcare organizations rather than individuals.
AI and the Changing Landscape of Privacy
As of early 2026, health data protection has undergoing a major shift. Artificial intelligence is improving healthcare efficiency by speeding up administrative tasks, analyzing large amounts of patient data, and supporting faster and more personalized diagnoses. While these advancements improve care, they also introduce new risks.
A growing concern involves how AI systems are accessed within healthcare environments. Chatbots, automated tools, and data analysis systems may allow employees or software programs to view sensitive information, sometimes without full oversight from IT or security teams. This raises concerns not only about AI analyzing records, but also about who is authorized to access them. Additionally, health data from wearable devices and wellness apps may not always fall under HIPAA protection, allowing some companies to access information outside traditional healthcare systems.
Laws and Protections for Health Data
Health data is protected by several laws and regulations, including the HIPAA Privacy Rule, the FTC Health Breach Notification Rule, 42 CFR Part 2, and various state laws. The FTC rule requires companies that manage personal health records outside HIPAA-covered systems to report data breaches. Meanwhile, 42 CFR Part 2 protects substance use treatment records with additional confidentiality rules. Despite these protections, the rise of AI has made health data security more complex.
New Technologies for Privacy Protection
To address these challenges, privacy-enhancing technologies (PETs) are being developed. Federated learning allows systems to learn from data without directly sharing it. Homomorphic encryption keeps data secure while it is being processed. AI-based anonymization generates realistic but non-identifiable data, and differential privacy adds small changes to datasets so individuals cannot be identified while still preserving useful insights.
Take Control of Your Health Data
Despite ongoing risks, individuals still have ways to better protect their health information. It is important to check whether health apps are HIPAA-compliant and connected to regulated healthcare providers. Reading privacy policies can help identify whether data is being used to train AI systems, and many apps offer options to opt out. While AI has increased concerns about privacy, legal protections and security technologies continue to improve, helping patients maintain greater control over their data.
Written by special guest Eric with contributions from wolterskluwer.com, medtechsolutions.com, cambridge.org, healthjournalism.org,rstreet.org and insprago.com



Signs You’re Overtraining (and What to Do About It)