Healthcare data privacy: what the law protects, what it misses, and what to do after a breach
Industry / situation. Updated 2026-09-13. About 6 minutes to read.
Assume health apps and wearables are not covered by HIPAA, turn on two factor authentication for every patient portal, and after a breach watch your claims and statements for care you never received.
Health data is some of the most sensitive information about you, and some of the most breached. The February 2024 ransomware attack on Change Healthcare, a US claims processor, affected about 192.7 million people according to the company's July 2025 update to federal regulators, the largest healthcare breach ever reported in the US. In Australia, the 2022 Medibank breach exposed data on about 9.7 million current and former customers.
Most people assume their health data is protected wherever it goes. In the US, HIPAA only covers certain organisations, so a fitness tracker, period app or DNA test you buy yourself is usually outside it. In Australia and the UK, broader privacy laws apply, but you still need to use the controls available to you.
This guide explains the gaps, the settings worth changing, and the steps to take when a clinic, hospital or health insurer tells you your data was exposed.
What HIPAA covers, and what it does not
HIPAA applies to health plans, healthcare clearinghouses, and healthcare providers that conduct standard electronic transactions such as billing insurance, plus the business associates that handle data for them. Your doctor, hospital, pharmacy and health insurer are covered.
Health and fitness apps you download yourself, unless your provider or health plan offers them on its behalf.
Wearables such as smartwatches and fitness rings, and the data they sync to the manufacturer.
Period and fertility tracking apps, mental health chat apps and online symptom checkers bought directly.
Consumer DNA and ancestry testing companies.
Life insurers, and employers acting as employers, such as sick leave records.
Health information you post publicly or share in online communities and support groups.
The FTC's Health Breach Notification Rule, as updated from 29 July 2024, covers many health apps and connected devices outside HIPAA. They must notify users of a breach, including unauthorised sharing of health data, within 60 calendar days, and notify the FTC when 500 or more people are affected. Washington State's My Health My Data Act adds consent requirements for consumer health data.
Use your HIPAA rights before and after a problem
Right of access: a covered provider or plan must give you your records within 30 calendar days, with one 30 day extension if it explains the delay in writing. Fees must be reasonable and cost based.
Right to amend: ask for errors to be corrected. The organisation must act on the request within 60 days.
Accounting of disclosures: ask for a list of certain disclosures of your information, which can reveal records sent somewhere they should not have been.
Complaints: file with the HHS Office for Civil Rights within 180 days of when you knew about the problem.
Australia: lock down My Health Record
Sign in to myGov and open My Health Record.
Set a Record Access Code, a code of four to eight characters that new healthcare provider organisations must be given before they can view your record. Share it with providers you choose.
Restrict individual documents you do not want widely seen, such as a specific test result.
Check the access history regularly to see which organisations have opened your record.
Turn on notifications so you receive an email or text when a new provider organisation accesses the record.
If you no longer want the record, you can cancel it at any time through myGov. Cancellation permanently deletes the information. For help setting privacy controls, call 1800 723 471.
Lower the risk before anything goes wrong
Turn on two factor authentication for patient portals such as MyChart, health insurer apps and pharmacy accounts.
Remove old proxy access, such as a former partner or an adult child who no longer needs it.
Before installing a health app, read whether it sells or shares data for advertising, and turn off data sharing and ad personalisation in its settings.
Delete health apps you no longer use, and ask the company to delete your account data rather than just uninstalling.
In the UK, use the NHS national data opt-out if you do not want your confidential patient information used for research and planning.
If your clinic, hospital or insurer is breached
Read the notice and note which data was involved: contact details, government ID numbers, Medicare or insurance numbers, diagnoses, or payment details.
Expect follow up scams. Criminals impersonate the breached organisation, offering compensation or claiming you must verify details. Contact the organisation only through its official website or the number on your card.
If government ID or insurance numbers were exposed, replace documents where the issuing agency allows it and watch for misuse. In the US, freeze your credit and consider an IRS Identity Protection PIN.
Change your password for the affected portal and any account that shared it, and turn on two factor authentication.
In Australia, contact IDCARE on 1800 595 160 for a free response plan. If data is published or an extortion demand is made, do not engage with the criminals and do not pay.
Report misuse: IdentityTheft.gov in the US, cyber.gov.au in Australia, and Report Fraud in the UK.
Spot medical identity theft
Medical identity theft is when someone uses your details to get treatment, prescriptions or insurance payouts. It can put false diagnoses, allergies or blood types into your records, which is dangerous as well as expensive.
Explanation of benefits statements or Medicare statements for care you did not receive.
Bills or collection notices from providers you have never visited.
An insurer saying you have reached a benefit limit or already claimed a procedure.
Diagnoses or medications in your record that are not yours.
Request a copy of your records and claims history once a year after any health breach. Errors are much easier to correct early, before they follow you to a new provider or insurer.
Frequently asked questions
Does HIPAA cover my fitness tracker or period app?
Usually not, if you bought or downloaded it yourself. HIPAA covers healthcare providers, health plans and their business associates. Consumer health apps and devices are generally regulated by the FTC, state laws such as Washington's My Health My Data Act, and their own privacy policies.
What should I do if my medical records were exposed in a breach?
Check which data was exposed, change the portal password and turn on two factor authentication, watch for scams impersonating the organisation, and review statements and claims for care you did not receive. Freeze your credit in the US if Social Security numbers were involved.
Can I get a copy of my medical records, and can they charge me?
In the US, covered providers must provide records within 30 days, extendable once by 30 days, and can only charge a reasonable, cost based fee. In Australia and the UK you also have a right to access your health information, usually free or for a limited fee.
Can I opt out of or cancel My Health Record?
Yes. You can cancel your record at any time through myGov or by completing a cancellation form. Cancelling permanently deletes the information. If you want to keep it, a Record Access Code and document restrictions give you more control.
Can data brokers legally sell my health data?
In the US, data from outside HIPAA, such as app activity, purchases and inferences about conditions, can often be sold unless a state law restricts it or the FTC finds the practice unfair. In the EU, UK and Australia, health data is sensitive information with stricter consent rules.