Who Can See Your Medical Data
Most people assume their health data is locked down by HIPAA. It is not. The law has big gaps that apps, websites, and data brokers drive straight through.
HIPAA Has Big Gaps
HIPAA only covers doctors, hospitals, insurers, and their direct partners. It does not cover:
- Health and fitness apps you download.
- Websites where you search symptoms.
- Wearables and the companies behind them.
- Data brokers who buy and sell health-related profiles.
Patient Portals and App Connections
- Review who has proxy access to your patient portal (old partners, adult kids).
- Be cautious connecting third-party health apps to your portal; that data leaves HIPAA's protection once it lands in the app.
Health Data Brokers Are Real
Brokers compile profiles that can include conditions, prescriptions, and pregnancy status, often inferred from purchases and web activity. Remove yourself from the big people-search brokers, see our data broker opt-out guide.
Be Careful What You Type
Many hospital and health sites have carried ad trackers that quietly sent what you looked at to advertisers. Use a private search engine, and block tracking domains network-wide so a symptom search does not become an ad profile.
Common Questions
Harbor Privacy blocks tracking and ad domains at the DNS level for every device on your home network, automatically. Get started here.