Can doctors see other doctors’ medical records? Generally, only when they are involved in treating you, billing for your care, or running related healthcare operations. Outside those situations, another doctor needs your written authorization before pulling your chart. The Health Insurance Portability and Accountability Act (HIPAA) sets that rule, and the treatment exception inside it is how most legitimate record-sharing between physicians actually happens.
When Another Doctor Can See Your Records Without Asking You
Picture the usual referral. Your primary care physician sends you to a cardiologist, and the cardiologist needs your history before your first appointment. HIPAA allows that exchange without a separate consent form. Under the treatment, payment, and healthcare operations (TPO) exception, providers involved in your care can share the information they need to diagnose and treat you.1eCFR. 45 CFR 164.506 – Uses and Disclosures to Carry Out Treatment, Payment, or Health Care Operations The same rule covers records moving for billing and insurance claims, and for internal work like quality reviews and staff training.
Two features of this exception matter for your question.
First, treatment disclosures between providers are exempt from HIPAA’s “minimum necessary” standard.2eCFR. 45 CFR 164.502 – Uses and Disclosures of Protected Health Information – General Rules For most other disclosures, providers must limit the release to the smallest amount of information needed. Between treating doctors, they don’t. Your primary care doctor can send the cardiologist your full relevant history without parsing every page. The reasoning is clinical: a doctor treating you needs to decide what’s relevant, and pre-filtering could hide a diagnosis.
Second, and this is the part people miss, the exception is narrower than it sounds. A random physician at an unrelated practice cannot open your chart out of curiosity. The TPO exception only applies when the sharing serves treatment, payment, or operations for a provider actually connected to your care. A specialist you’ve never visited, who has no role in treating you, has no legal basis to access your records under this rule.
When Another Doctor Needs Your Written Authorization
Anything outside the TPO exception and a short list of other carve-outs (public health reporting, court orders, workers’ compensation, serious and imminent threats, and similar) requires your signed HIPAA authorization.3eCFR. 45 CFR 164.512 – Uses and Disclosures for Which an Authorization or Opportunity to Agree or Object Is Not Required A doctor who wants your records for anything other than treating you, getting paid, or running operations related to your care needs your permission in writing.
A valid authorization must include your signature, a description of the information being shared, who will receive it, the purpose of the disclosure, and an expiration date.4eCFR. 45 CFR 164.508 – Uses and Disclosures for Which an Authorization Is Required A vague, open-ended form with no expiration isn’t valid. If someone hands you a permission slip that doesn’t identify who’s getting what and for how long, it doesn’t authorize anything.
Sensitive Records That Get Extra Protection Even Between Treating Doctors
For certain categories of records, the treatment exception doesn’t fully apply. A doctor treating you still can’t see them without your specific consent.
Psychotherapy Notes
HIPAA defines psychotherapy notes as a therapist’s personal notes from a counseling session, kept separate from your main medical record. Medication prescriptions, treatment frequency, diagnosis summaries, and clinical test results are not psychotherapy notes; those live in your regular record and follow the normal sharing rules.5HHS.gov. HIPAA Privacy Rule and Sharing Information Related to Mental Health
The session notes themselves require your written authorization before anyone can see them, including another doctor treating you. The normal treatment exception does not apply. Narrow exceptions exist for disclosures required by other laws, such as mandatory abuse reporting or duty-to-warn situations involving imminent harm.5HHS.gov. HIPAA Privacy Rule and Sharing Information Related to Mental Health
Substance Use Disorder Treatment Records
Records from federally assisted substance use disorder treatment programs fall under 42 CFR Part 2, a separate federal regulation stricter than HIPAA. These records cannot be used or disclosed without written consent, and they cannot be used in any legal proceeding against the patient.6eCFR. 42 CFR Part 2 – Confidentiality of Substance Use Disorder Patient Records A general medical release form isn’t sufficient. The consent must name the recipient, describe the information, state the purpose, carry an expiration date, and include notice that the recipient cannot redisclose the information. Every disclosure must carry a written reminder that redisclosure is prohibited.
SUD counseling notes get an additional layer. The program must obtain separate, standalone consent before sharing those notes, and it cannot condition your treatment on whether you agree.6eCFR. 42 CFR Part 2 – Confidentiality of Substance Use Disorder Patient Records
Reproductive Health Information
A 2024 HIPAA final rule, effective June 25, 2024, added specific protections for reproductive health care information. Providers and insurers cannot disclose your health information to investigate or impose liability on anyone for seeking, obtaining, providing, or facilitating reproductive health care that was lawful where it was provided.7HHS.gov. HIPAA Privacy Rule Final Rule to Support Reproductive Health Care Privacy
When records that could involve reproductive care are requested for purposes such as law enforcement, judicial proceedings, or health oversight, the provider must first obtain a signed attestation that the information will not be used for a prohibited purpose.7HHS.gov. HIPAA Privacy Rule Final Rule to Support Reproductive Health Care Privacy
Electronic Sharing Through Health Information Exchanges
A doctor you’ve never personally visited may still have some access to your data through a health information exchange (HIE). HIEs are electronic networks that let providers in a region or state share patient data. Many states have them, and rules vary widely.
Some states use an opt-out model: your records flow through the HIE by default unless you affirmatively remove yourself. Others require opt-in consent before your data enters the exchange at all. If you want to know whether your records are moving through an HIE and who can see them, contact your provider’s office or your state health information exchange directly.
Even within an HIE, the underlying legal rule doesn’t change. A participating doctor’s access is supposed to be tied to a treatment relationship with you. Looking up a chart out of curiosity, or for anything not covered by TPO or another exception, remains a violation regardless of whether the data was pulled from paper files or an electronic exchange.
How to Control Who Sees Your Records
You have several concrete tools for limiting sharing.
- Authorize selectively. Sign an authorization only for the specific recipient, information, and purpose you actually want. If a form is vague or has no expiration, ask for one that meets the HIPAA elements before you sign.4eCFR. 45 CFR 164.508 – Uses and Disclosures for Which an Authorization Is Required
- Revoke in writing. You can revoke any authorization at any time by submitting a written revocation to the provider. Revocation takes effect when the provider receives it, but it doesn’t undo disclosures that already happened while the authorization was active.4eCFR. 45 CFR 164.508 – Uses and Disclosures for Which an Authorization Is Required
- Request restrictions. You can ask a provider in writing to limit how your information is shared. Providers generally aren’t required to agree, with one important exception below.8eCFR. 45 CFR 164.522 – Rights to Request Privacy Protection for Protected Health Information
- Pay out of pocket to block insurer sharing. If you pay for a service entirely out of pocket and ask the provider not to share that information with your insurance plan, the provider must honor that request. This is the one restriction request providers cannot refuse.8eCFR. 45 CFR 164.522 – Rights to Request Privacy Protection for Protected Health Information
- Get an accounting of disclosures. You can ask for a list of who has received your health information and why. If you suspect an unauthorized look, that list is the first place to check.9eCFR. 45 CFR 164.528 – Accounting of Disclosures of Protected Health Information
If a Doctor Accessed Your Records Without a Valid Reason
If your unsecured health information has been breached, the provider or insurer must notify you in writing within 60 calendar days of discovering the breach.10eCFR. 45 CFR 164.404 – Notification to Individuals The notice must describe what happened, the types of information involved, steps you can take to protect yourself, and what the provider is doing about it.
If you believe a provider or insurer violated your privacy rights, you can file a complaint with the HHS Office for Civil Rights (OCR). Complaints must be filed within 180 days of when you became aware of the violation, though OCR can extend that deadline for good cause.11HHS.gov. How to File a Health Information Privacy or Security Complaint Complaints can be filed online through the OCR Complaint Portal or by mail or email.
The consequences for a doctor or employee who knowingly looked at records without authorization aren’t limited to organizational fines. A person who knowingly obtains or discloses protected health information in violation of HIPAA faces criminal prosecution, with penalties escalating when the violation was committed under false pretenses or for personal gain.12Office of the Law Revision Counsel. 42 USC 1320d-6 – Wrongful Disclosure of Individually Identifiable Health Information Civil monetary penalties also apply to the covered entity itself, tiered by how culpable the violator was.13Federal Register. Annual Civil Monetary Penalties Inflation Adjustment
State Law Can Add More Protection
HIPAA is a federal floor, not a ceiling. State laws that provide greater privacy protection are not preempted and remain fully enforceable.14HHS.gov. Preemption of State Law Many states impose stricter rules on specific categories of information, including HIV/AIDS status, mental health records, genetic testing results, and minor consent. If your state law is stricter than HIPAA for a particular type of record, the provider has to follow the stricter state rule, which means another doctor may need your explicit permission for records that HIPAA alone would let flow freely.