Patient health data ownership usually means you have rights to access, copy, send, and request correction of your medical information, not that you personally own every record like property. In the United States, provider records are governed by federal access and privacy rules plus state law, and health apps may follow different rules once your data leaves a covered provider or health plan.
This guide explains what digital health users can actually do with medical records, patient portals, wearable data, and third-party health apps. You’ll see where the Health Insurance Portability and Accountability Act (HIPAA) helps, where it stops, and what steps protect your records when you request, download, or connect them to an app.
What Does Patient Health Data Ownership Actually Mean?
Patient health data ownership is not a single, simple rule. In practice, you should think in terms of access rights, privacy protections, correction rights, portability, and limits on how your data can be used.
The word “ownership” can be misleading with medical records. A hospital, clinic, or health plan may maintain the official record system, and state law may affect who owns the physical or electronic record. That does not mean you are powerless. Under HIPAA, you generally have enforceable rights to see and receive copies of much of the health information held about you by covered providers and health plans.
The better question is not only “Who owns my medical records?” It is “What can you access, what can you send, what can you correct, and what happens when your data moves somewhere else?” That shift matters when you use patient portals, telehealth platforms, pharmacy systems, fitness trackers, and wellness apps. Patient health data ownership becomes practical when you know which organization holds the data and which rule applies to that organization.
What Health Data Do You Have A Right To Access?
You generally have the right to access protected health information about you in a designated record set held by a covered provider or health plan. That can include medical records, billing records, lab reports, imaging, clinical notes, and insurance information, with limited exceptions.
A designated record set is broader than the small slice you may see in a portal. It includes records a provider or health plan uses to make decisions about you. That may cover visit notes, medication lists, diagnoses, test results, care plans, claims information, payment records, and materials used to manage your care. You may also have access to information in your medical record that came from another provider or that you supplied yourself.
Some information may be excluded or handled under special rules. Psychotherapy notes, certain information prepared for legal proceedings, and records restricted by another law may not be available through a standard access request. Your provider still needs to explain a denial when the rules require it. If you need your “complete record,” ask for the designated record set rather than only a visit summary or portal download.
Why Doesn’t Your Patient Portal Show Your Complete Medical Record?
A patient portal is usually an access tool, not a full copy of everything a provider maintains about you. Your portal may show test results, messages, summaries, and selected notes, but a formal record request can reach more information.
This is one of the most common points of confusion for digital health users. You log in, see a few lab results and after-visit notes, then assume that must be the whole file. It often is not. A portal may be configured to display only certain record types, certain date ranges, or records from one provider group rather than every organization that has treated you.
Digital access is growing, but fragmentation is still normal. Federal health information technology data found that most people were offered online access to medical records, and many accessed a portal or online record. The same data showed that many people had multiple portals, yet only a small share used an app to combine records from different portals. That explains why your information can feel scattered across a hospital portal, a specialist portal, a lab portal, and a health plan account.
If your portal looks incomplete, use it as a starting point. Download what is available, then submit a separate request for the records you do not see. Ask the records department for the designated record set, specify dates if you know them, and state whether you want an electronic copy. If you need records for a second opinion, surgery, disability paperwork, insurance review, or caregiving, do not rely only on the portal screen.
How Does HIPAA Protect Your Medical Records And What Does It Not Cover?
HIPAA protects health information held by covered entities and business associates, including many health care providers, health plans, and service vendors working for them. It does not automatically cover every health app, wearable, wellness site, or direct-to-consumer platform.
HIPAA focuses on protected health information held by organizations that fall under the law. Covered entities include many providers, health plans, and health care clearinghouses. Business associates are vendors or partners that handle protected health information for covered entities under required agreements. When your information is held inside that system, HIPAA sets rules for privacy, access, permitted use, and certain breach notices.
HIPAA also allows many disclosures for treatment, payment, and health care operations without asking you to approve each one. That can feel surprising if you expected every data movement to require a signature. A doctor can share information with another treating provider, a health plan can process claims, and a provider can use records for care coordination under HIPAA’s permitted-use rules. These permissions are part of how routine health care works.
The major gap appears when data leaves the HIPAA-covered system. If you direct your provider to send electronic health information to a consumer app that is not covered by HIPAA and is not acting as a business associate, HIPAA may no longer protect that information after the app receives it. Then the app’s privacy policy, consumer protection rules, Federal Trade Commission (FTC) requirements, and state privacy laws may matter more than HIPAA. That is why digital health data privacy depends on where the data sits, not just what the data describes.
How Can You Request, Download, Or Send Your Health Records?
You can request your records from a covered provider or health plan, ask for an electronic copy when available, and direct the organization to send the data to another person or app. HIPAA generally requires action within 30 calendar days, with one possible written extension of up to 30 more days.
Start with a written request so you have a record of what you asked for and when you sent it. Name the provider, the date range, the record types you need, and the format you prefer. Use clear wording: “Please provide my designated record set in electronic form if readily producible.” If you want records sent to another doctor, caregiver, legal representative, or app, include the recipient’s details and follow the provider’s identity-verification process.
Fees should be limited. HIPAA allows a reasonable, cost-based fee for copies, but it does not allow providers to charge you for search, retrieval, system maintenance, storage infrastructure, or other excluded costs. If access is provided through an electronic view, download, and transmit function with no labor or supply cost, federal guidance says the provider cannot charge a fee for that access. If a bill looks inflated, ask for a fee breakdown before paying.
Use this short checklist when you request records:
- Ask for the designated record set, not just a visit summary.
- Request an electronic copy if the records are maintained electronically.
- Track the date your request was received.
- Save copies of forms, messages, confirmations, and fee notices.
- Ask whether the provider can send the record directly to your chosen recipient.
Can You Correct Or Delete Health Data?
You can request a correction or amendment to protected health information in a designated record set, but you usually cannot force a provider to delete medical records it must keep. App deletion rights depend on the app, the data involved, and applicable state or consumer protection rules.
If your record has an error, submit a written amendment request. Be specific about what is wrong, where it appears, and what correction you are asking for. A provider may accept the amendment, deny it under permitted reasons, or add your statement of disagreement when the process allows. Amendment is different from editing your own chart directly.
Deletion is more limited in clinical settings. Providers often have duties to retain medical records for care, billing, compliance, and risk management. That is why a request to erase a diagnosis, medication history, or visit record may be denied, even when you would prefer that the data disappear. A better path is often to request an amendment, add a patient statement, or ask how the disputed information is used.
Consumer health apps are different. Some apps may let you delete an account, delete uploaded records, export data, or revoke a connection to a patient portal. Others may retain backups, derived data, or information already shared with partners. Before you connect a wearable or health app, read the deletion, retention, export, and sharing terms, then decide whether the convenience is worth the data exposure.
What Should You Check Before Connecting A Health App?
Before connecting a health app, check whether HIPAA applies, what data the app collects, who receives the data, whether you can export or delete it, and how the app protects your account. Treat app access as a data-sharing decision, not just a convenience feature.
Many apps make health tracking easier. They can help you gather portal records, monitor activity, organize medications, or share data with caregivers. The tradeoff is that an app may collect more than you expect, including device data, account identifiers, location-related data, usage patterns, or information you type into forms. If the app is outside HIPAA, its own terms may control what happens after import.
Use plain-language tests before connecting anything to your medical record:
- Coverage: Is the app part of your provider’s HIPAA-covered service, or is it a separate consumer app?
- Collection: What record types, device signals, or personal details does it collect?
- Sharing: Does it share data with analytics vendors, advertisers, affiliates, researchers, or service providers?
- Control: Can you disconnect the app, export records, delete an account, or revoke permissions?
- Account protection: Does it support strong passwords, multi-factor authentication, and alerts for unusual access?
Federal Trade Commission guidance for mobile health app developers emphasizes privacy, safeguards, and affirmative express consent before collecting or sharing health data. The FTC Health Breach Notification Rule also matters for certain personal health record vendors and related services outside HIPAA. Several states have added consumer health data rules that may apply to certain health-related data beyond traditional medical records. Your safest habit is to connect fewer apps, review permissions often, and remove access when a tool no longer serves you.
What Can You Do If Records Are Denied, Delayed, Or Wrong?
If a provider delays, denies, or gives you only partial access, submit a clear written request, track the deadline, ask for the reason in writing, and escalate when needed. If you believe a HIPAA-covered organization violated your rights, you can file a complaint with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights.
Start by reducing confusion. Ask whether the organization treated your message as a HIPAA access request or just a portal support question. Confirm that you requested the designated record set, not only portal-visible information. If the organization says it cannot provide a record, ask which exception it relies on. Keep every message, mailed form, upload receipt, and phone note in one place.
Information blocking rules may also matter when electronic health information is being withheld in a way that interferes with access, exchange, or use without a valid reason. These rules support easier access to electronic health information and apply to certain health care actors. They are separate from your HIPAA access right, but they point in the same practical direction: patients should not face unreasonable barriers to their own electronic health information. If a portal, health information exchange, or electronic health record process seems to be blocking access, ask the organization to identify the legal or technical reason.
For wrong records, use the amendment process rather than arguing informally through portal messages. For denied access, ask for a written denial and instructions for review when available. For privacy concerns involving a covered provider, health plan, or business associate, review the HHS complaint process and timing rules. For a consumer app concern outside HIPAA, look at the app’s complaint process, the FTC complaint route, and any state privacy options that apply where you live.
Do Patients Own Their Health Data?
- You may not own every record as property.
- You generally can access, copy, send, and request corrections.
- Apps outside HIPAA may follow different rules.
Your Health Data Rights Are Practical, Not Just Legal
Patient health data ownership is best understood as a set of usable rights. You may not control every record like personal property, but you can request access, receive copies, send records to another destination, challenge errors, and ask questions when your information moves across systems. Your strongest protection starts with knowing whether the data is held by a HIPAA-covered provider or plan, a business associate, a consumer health app, or a wearable platform. Use portals for convenience, but do not assume they show everything. Before connecting a new app, compare the benefit against the privacy terms, sharing rules, deletion options, and account safeguards.
References:
- The Need For Clear Medical Data Ownership Laws
- HHS: Individuals’ Right Under HIPAA To Access Their Health Information
- HHS: What Personal Health Information Individuals Have A Right To Access
- HHS: Access To Information In A Medical Record
- HHS: The Access Right, Health Apps, And Application Programming Interfaces
- HHS: Covered Entities And Business Associates
- HealthIT.gov: Individuals’ Access And Use Of Patient Portals And Smartphone Health Apps
- HealthIT.gov: How To Get Your Health Records
- HealthIT.gov: What You Can Do To Protect Your Health Information
- HealthIT.gov: Information Blocking
- HHS: Filing A Health Information Privacy Complaint
- Federal Trade Commission: Health Breach Notification Rule Update
- Federal Trade Commission: Mobile Health App Developers Best Practices
- Health Information And The Law: Who Owns Medical Records, 50 State Comparison
Nirdosh Jagota is Managing Partner at GRQ Biotech Advisors with 30+ years in the biotech industry. A former executive at Amgen, Genentech/Roche, Merck, and Pfizer, he has led >25 NDAs/BLAs/MAAs and hundreds of INDs across global regulatory, quality, and compliance.
