US Government Push for Medical Records Threatens Health Data Privacy
- has sought federal access to Americans’ medical records since the spring of 2025 to investigate whether vaccines cause autism, raising pressing questions about health data privacy and the...
- The Health Insurance Portability and Accountability Act, commonly known as HIPAA, is narrower than its reputation suggests.
- In pursuing medical records for vaccine and autism research, HHS has been engaging state health information exchanges, which allow hospitals and clinics to swap detailed, identifiable patient records.
Health and Human Services Secretary Robert F. Kennedy, Jr. has sought federal access to Americans’ medical records since the spring of 2025 to investigate whether vaccines cause autism, raising pressing questions about health data privacy and the limits of the Health Insurance Portability and Accountability Act. According to KFF Health News, the Department of Health and Human Services has been courting state health information exchanges to ask how identifiable patient records might be used for vaccine research, despite decades of scientific study showing definitively that vaccines do not cause autism.
The Limits of Federal Medical Privacy Law
The Health Insurance Portability and Accountability Act, commonly known as HIPAA, is narrower than its reputation suggests. According to Jennifer D. Oliva, a professor of law at Indiana University, the federal privacy law regulates hospitals, physicians, insurers, and their business associates, but leaves out the health data individuals generate everywhere else, including period-tracking applications, internet search queries, mailed DNA samples, and consumer wearables. Even the medical records HIPAA covers can be shared, sold, or handed to the government under roughly a dozen statutory exceptions. Information regarding treatment, payment, routine healthcare logistics, public health reporting, law enforcement, and essential government functions requires no patient sign-off. Once data leaves the system covered by HIPAA, those statutory limits fall away entirely. Prescription drug monitoring programs operated by every state assemble detailed logs of controlled substance prescriptions that federal law enforcement can access using self-issued administrative subpoenas without judge oversight.
Federal Push for State Health Datasets
In pursuing medical records for vaccine and autism research, HHS has been engaging state health information exchanges, which allow hospitals and clinics to swap detailed, identifiable patient records. One proposal floated by state organizations would provide the federal agency with data on 90% of Americans’ medical records by 2028. In Nebraska, millions of federal grant dollars have flowed to a statewide health information exchange nonprofit that cooperated with the federal effort. While pooled health datasets can expose drug side effects, track disease outbreaks, and reveal care disparities that smaller studies miss, the HHS has declined to state how many states are involved, what specific data is collected, who can view it, or how the repository will be protected. Building a comprehensive repository to investigate a question that science has already answered inverts standard research logic, creating a significant target for data breaches, unconsented secondary uses, and potential government abuses.
Anonymization Vulnerabilities in the Age of AI
Artificial Intelligence and Membership Inference Attacks
Federal officials have offered reassurances that collected data will be aggregated and stripped of personal identifiers so that no individual can be singled out. However, decades of computer science research and a study published in Nature in June 2026 challenge that promise. The research team audited artificial intelligence diagnostic models trained on clinical data, including chest X-rays, electrocardiograms, and electronic health records, to determine whether an outsider could identify if a specific person’s data helped build the model. This exploit, known as a membership inference attack, demonstrated that while the average risk of reidentification often looked low, certain patients faced near-certain exposure. The burden fell unevenly across populations, sorting by race, insurance status, or medical diagnosis, leaving underrepresented groups most vulnerable to discrimination. Today’s artificial intelligence technology makes carrying out these remote attacks faster and easier, rendering traditional anonymization methods unreliable for protecting sensitive health data.
