our health records are arguably one of the most private documents about yourself. They contain not only your general information such as name, date of birth, address, etc. But they also contain almost every detail about your health such as the diagnoses you have received, procedures you have undergone, and all the medications you take.

When you go to the doctor or any other health care provider, your medical history will be recorded and kept in a computer and sometimes paper file so the doctor can keep track of any of your symptoms and past conditions.

Over the last few decades, efforts have been made in the medical community to have become a community standard because they are more secure, the streamline the process of getting and reviewing your health information from one provider to the other, and they have the potential to avoid redundant medical tests and incorrect diagnoses by keeping up-to-date and accurate information readily available for providers.

The implementation of electronic medical records also brought a wave of concern regarding how the electronic medical records were going to protect the patient and keep their information confidential and secure at all times.

What Is HIPAA?

In 1996 the United States congress enacted Health Insurance Portability and Accountability Act (HIPAA), that among other things, mandates any person, agency or entity on the medical industry that handles your personal health information to keep it secure and confidential.

External link: What Is HIPAA?

Through 18 identifiers, HIPAA lists what kind of information is legally considered personally identifiable information. Any health-related information including diagnoses, lab results, treatment plans, etc. that contain any of the 18 HIPAA identifiers is considered protected health information (PHI) and must be handled according to the law.

These 18 identifiers are:

  • Names
  • Address (all geographic subdivisions smaller than state, including street address, city, county, and zip code)
  • All dates and elements that can make it possible to identify a person’s age.
  • Telephone numbers
  • Fax number
  • Email address
  • Social Security Number
  • Medical record number
  • Health plan beneficiary number
  • Account number
  • Certificate/license number
  • Any vehicle or other device serial number
  • Web URL
  • Internet Protocol (IP) Address
  • Fingerprint or voice recordings
  • Photographic image, not limited to just the face
  • Any other characteristic that could make it possible to uniquely identify an individual

HIPAA also applies to clinical research; clinical trials or any other kind of research studies that handle either directly or indirectly any PHI, must take special data safety precautions when handling this information. Data for publication, reporting, or correspondence must be made completely unidentifiable prior to release.

  • Natural Language Processing for Screening Opioid Misuse
    on February 27, 2023 at 5:00 pm

    Conditions:   Opioid Use Disorder;   Opioid MisuseIntervention:   Other: Opioid Misuse Screening with an Addiction Consult ServiceSponsor:   University of Wisconsin, MadisonRecruiting

  • Colonoscopy Screening: Setting Epic Follow-up Times
    on November 30, 2022 at 5:00 pm

    Conditions:   Concordance Between Colonoscopy Follow up Interval Noted in Patient Letters vs. Electronic Health Record Chart;   Colorectal CancerIntervention:   Other: Assistance with implementing Epic SmartlistSponsors:   Massachusetts General Hospital;   Harvard Risk Management FoundationRecruiting

  • NUDGE-EHR Replication Trial at Mass General Brigham
    on September 13, 2022 at 4:00 pm

    Conditions:   Aging;   Benzodiazepine Sedative Adverse Reaction;   Anticholinergic Adverse Reaction;   Adverse Drug EventInterventions:   Other: Follow-up booster Alert;   Other: Pre-commitment;   Other: Enhanced AlertSponsors:   Brigham and Women's Hospital;   Massachusetts General Hospital;   National Institutes of Health (NIH);   National Institute on Aging (NIA)Recruiting

  • Patient Portal Flu Vaccine Reminders_RCT 5 (LADHS)
    on September 10, 2022 at 4:00 pm

    Conditions:   Influenza;   Respiratory Tract InfectionsInterventions:   Behavioral: Enhanced texts with Callback by a Person;   Behavioral: Enhanced Bidirectional TextsSponsors:   University of California, Los Angeles;   National Institute of Allergy and Infectious Diseases (NIAID);   Los Angeles County Department of Public HealthRecruiting

  • Patient Portal Flu Vaccine Reminders (5)
    on September 1, 2022 at 4:00 pm

    Conditions:   Influenza;   Respiratory Tract InfectionsInterventions:   Behavioral: Text Fixed R/R Messages with Direct Appointment Schedule Link;   Behavioral: Text Pre-Appointment Reminder;   Behavioral: Portal Pre-Commitment Prompt with Tailored R/R Messages with Direct Appointment Schedule Link;   Behavioral: Portal Fixed R/R Messages with Direct Appointment Schedule Link;   Behavioral: Portal Pre-Appointment ReminderSponsors:   University of California, Los Angeles;   National Institute of Allergy and Infectious Diseases (NIAID)Recruiting

  • Antibiotic Prescription Relevance Indicators: Calculation From Electronic Health Records
    on June 15, 2022 at 4:00 pm

    Conditions:   Surgery;   AntibioticIntervention:   Other: Automatic tool to identify inappropriate antibiotic prescriptionsSponsors:   University Hospital, Bordeaux;   University of BordeauxRecruiting

  • The Brain Health Study: A Pragmatic, Patient-Centered Trial
    on May 2, 2022 at 4:00 pm

    Conditions:   Dementia;   Alzheimer DiseaseIntervention:   Other: Brain Health AssessmentSponsors:   Kaiser Permanente;   University of California, San FranciscoRecruiting

  • Electronic Health Record Strategies to Promote Diverse Participation in Research
    on April 27, 2022 at 4:00 pm

    Condition:   Patient ParticipationInterventions:   Other: Traditional Letter;   Other: Direct to Patient Message;   Other: Chatbot;   Other: BannerSponsors:   Yale University;   Food and Drug Administration (FDA)Recruiting

  • Survivorship Plan HEalth REcord (SPHERE) Implementation Trial
    on April 26, 2022 at 4:00 pm

    Condition:   CancerIntervention:   Behavioral: Survivorship Care Plan-Personal Health Record (SCP-PHR)Sponsors:   Indiana University;   National Cancer Institute (NCI)Recruiting

  • Clinical Decision Support for PrEP
    on February 17, 2022 at 5:00 pm

    Conditions:   HIV Infections;   Preexposure Prophylaxis (PrEP)Interventions:   Other: Standard of care;   Other: Clinical decision support for PrEPSponsors:   Harvard Pilgrim Health Care;   OCHIN, Inc.;   Oregon Health and Science University;   National Institute of Mental Health (NIMH);   Beth Israel Deaconess Medical CenterRecruiting

  • Preoperative Smoking Cessation in Patients Undergoing Surgery
    on January 14, 2022 at 5:00 pm

    Conditions:   Smoking Cessation;   Smoking Reduction;   Surgery--Complications;   Surgery;   Cancer;   Postoperative Complications;   Perioperative Complication;   Smoking;   Abdominal Cancer;   Thoracic Cancer;   Urologic Cancer;   Gynecologic Cancer;   Head and Neck CancerIntervention:   Behavioral: Intensive preoperative smoking cessation counsellingSponsor:   Luzerner KantonsspitalRecruiting

  • Point of Care RandOmisation Systems for Performing Embedded Comparative Effectiveness Trials Of Routine Treatments
    on December 8, 2021 at 5:00 pm

    Conditions:   Atrial Fibrillation New Onset;   Magnesium DeficiencyInterventions:   Other: Electronic Point of Care Randomisation tool;   Drug: MagnesiumSponsors:   University College, London;   University College London HospitalsRecruiting

Do I Have Control Over My Health Records?

In the United States, different states have different laws regarding the extent of the access and ownership each patient has over his or her medical records. In 49 states except New Hampshire, the patient cannot claim legal rights over their medical record, and must follow different rules to obtain them.

Some doctor offices upload patient’s medical records to a secure web portal where the patient can access his or her record. However, doctors are not obligated to do this nor to disclose the entirety of the patient’s record.

However, with the exception of psychiatry and psychotherapy notes, which you don’t have the right to access, in all states youhave the right to request a copy of your medical records and they must be provided to you. Also, providers also must ask your explicit permission before sending your records to another medical provider or third party.

External link: Your Medical Records

What Can I Do To Keep My Records Secure?

Though the privacy rules under HIPAA were implemented to keep your medical and personal information confidential and secure, only healthcare providers and third parties doing business with them are mandated to follow HIPAA rules.

This means that if you request your health information and want to keep it for your own personal records, you should be very mindful of how and where you will be storing it to keep it private and secure at all times.

Here are some tips on how to keep your health records secure:

  • If you want to store any of your medical information in a software or app research how they keep their user’s information secure, and read their terms and conditions to make sure you agree how your information will be handled.
  • Don’t post or share online any of your health information that you don’t want to be made public. Any content or information posted on the Internet may remain permanently even after you delete it.
  • If you decide to store your medical records on your personal computer consider installing encryption software.
  • Protect any folders or files with passwords.
  • Use a strong password and don’t share it with anyone.