Who Owns Healthcare Records: Patients or Providers?

In almost every state, the doctor, hospital, or clinic that creates your chart owns the physical record, but you own strong federal rights to the health information inside it. That split is the heart of the question of who owns medical records in the United States: the file belongs to the provider, the data belongs, in every practical legal sense, to you. Federal law gives you enforceable rights to see, copy, correct, and control that information, and providers who ignore those rights have paid settlements running into the hundreds of thousands of dollars.

What the Provider Owns

The healthcare provider or facility that creates your record owns the physical charts, digital files, and storage systems that hold it. A hospital owns its servers and filing cabinets the same way a bank owns the computers that hold your account data. A handful of states go a different direction and declare by statute that the patient owns the information itself, but that is the exception.

Owning the file is not the same as owning what is in it. Federal law treats the provider as a custodian with duties to protect the information, maintain it, and share it with you on request. The provider cannot refuse to hand over your information because it owns the folder, and it cannot charge whatever it wants for a copy. Those obligations run to every patient in every state, because they come from federal law.

What You Control Under Federal Law

Two federal laws do most of the work. The HIPAA Privacy Rule, in effect since 2003, sets your core rights to access and control protected health information.1U.S. Department of Health and Human Services. Individuals’ Right under HIPAA to Access their Health Information The 21st Century Cures Act, fully in force since 2022, pushed further by requiring providers to share your electronic health information without delay and at no cost, and by making it illegal to block that access.2Office of the National Coordinator for Health Information Technology. ONC’s Cures Act Final Rule

Together, these laws give you four rights that matter most for the ownership question:

  • You can inspect your health information and get copies in paper or electronic format, and you can direct the provider to send those records to a third party of your choosing, such as a new doctor or a family member.1U.S. Department of Health and Human Services. Individuals’ Right under HIPAA to Access their Health Information
  • You can ask the provider to correct something wrong in your file. The provider can refuse, but you then have the right to attach a written statement of disagreement that travels with the record on any future disclosure.
  • You can request an accounting of disclosures, which lists who received your information and why.
  • You can ask the provider not to share specific information with your health plan, particularly when you pay for a service entirely out of pocket.3U.S. Department of Health and Human Services. Summary of the HIPAA Privacy Rule

These rights exist regardless of whether your state calls the record the provider’s property or the patient’s. That is why the practical answer to “who owns your medical records” is less about title to the file and more about who can do what with the contents.

Getting a Copy of Your Records

Access usually happens one of three ways: through an online patient portal, through a written request (sometimes called a medical record release form), or by email, fax, or mail. Providers cannot create unreasonable barriers to access.4Office of the National Coordinator for Health Information Technology. Get It They can require reasonable identity verification, which in practice usually means a photo ID and date of birth.

A provider cannot require you to explain why you want your records as a condition of giving them to you.1U.S. Department of Health and Human Services. Individuals’ Right under HIPAA to Access their Health Information

What It Can Cost

Providers can charge a reasonable, cost-based fee for paper copies. That fee can cover copying labor, supplies, and postage, but it cannot include the cost of searching for or retrieving the records.1U.S. Department of Health and Human Services. Individuals’ Right under HIPAA to Access their Health Information Per-page charges typically run from about $0.25 to $1.00 or more depending on the state.

For electronic copies of records already stored electronically, providers can choose a flat fee of no more than $6.50 instead of calculating actual cost. The $6.50 figure is an alternative, not a cap; a provider that calculates its actual cost-based fee could charge more.5U.S. Department of Health and Human Services. $6.50 Flat Rate Option is Not a Cap on Fees Electronic access through a patient portal, where available, is generally free under the Cures Act.2Office of the National Coordinator for Health Information Technology. ONC’s Cures Act Final Rule

How Long It Should Take

HIPAA gives providers up to 30 calendar days to respond to an access request. If the records are archived offsite or otherwise hard to retrieve, the provider can take one additional 30-day extension, but it must notify you in writing within the original 30 days and explain the delay. Only one extension is allowed per request.1U.S. Department of Health and Human Services. Individuals’ Right under HIPAA to Access their Health Information

The Cures Act has effectively raised the bar for anything electronic. Providers using certified electronic health record systems are expected to share electronic health information without unnecessary delay, and deliberate foot-dragging can be treated as information blocking. Penalties reach up to $1 million per violation for health IT developers and health information networks.6Office of Inspector General. Information Blocking

When a Provider Can Refuse Access

Your right of access is broad, not absolute. Federal regulations split denials into two groups: those you cannot appeal and those you can.

Denials With No Appeal

A provider can deny access without any review in these situations:

Denials You Can Challenge

A provider can also deny access on safety grounds, but only if a licensed healthcare professional determines that releasing the information is reasonably likely to endanger you or someone else, cause substantial harm to a person mentioned in the records, or harm a patient whose personal representative made the request. In those cases, you can ask for review by a different licensed professional who was not involved in the original decision.8eCFR. 45 CFR 164.524 – Access of Individuals to Protected Health Information

Refusal to Correct a Record

If you ask for an amendment and the provider says no, your statement of disagreement becomes part of the file. The provider can limit its length and can attach its own rebuttal, but any future disclosure of the disputed information must include your statement or an accurate summary of it. Your version of events travels with the record even when the provider refuses to change what it wrote.

Records That Follow Different Rules

Not every category of health information lives under the same access framework. A few situations shift where control sits.

Substance Use Treatment Records

Substance use disorder treatment records maintained by federally assisted programs get a stricter layer of protection under 42 CFR Part 2. These programs include opioid treatment centers, residential treatment facilities, and other providers that receive federal funding or prescribe medications like methadone or buprenorphine for addiction treatment. Records generally require the patient’s specific written consent before disclosure to anyone.9U.S. Department of Health and Human Services. Fact Sheet 42 CFR Part 2 Final Rule

A final rule that took effect in February 2026 lets patients sign a single consent covering treatment, payment, and healthcare operations, closer to how HIPAA works. Once records are shared under that broader consent, downstream HIPAA-covered recipients can redisclose them under HIPAA. The update also created a new protected category for substance use disorder counseling notes, analogous to psychotherapy notes, requiring separate specific consent.9U.S. Department of Health and Human Services. Fact Sheet 42 CFR Part 2 Final Rule Law enforcement generally needs a special court order specific to 42 CFR Part 2 to obtain these records; a regular subpoena or search warrant is not enough.

Children’s Records

Parents and legal guardians are generally treated as a minor’s personal representative and can access the child’s records, but HIPAA defers to state law on where that authority ends. Three situations strip a parent of personal representative status for specific records: when the minor lawfully consented to care on their own, when the child received care at the direction of a court, and when the parent agreed to a confidential relationship between the child and provider.10U.S. Department of Health and Human Services. The HIPAA Privacy Rule and Parental Access to Minor Children’s Medical Records Many states let minors consent independently to reproductive health services, mental health treatment, or substance abuse care, which can put those specific records out of a parent’s reach.

Records After a Patient Dies

When a patient dies, the personal representative of the estate, meaning an executor or administrator named in a will or appointed by a court, steps into the patient’s shoes for records purposes. That representative can access the health information and authorize disclosures. HIPAA protections last for 50 years after death. Family members who were involved in the patient’s care but are not the estate’s representative can still receive limited information, unless the patient expressed a contrary preference before death.11U.S. Department of Health and Human Services. Health Information of Deceased Individuals

Adults Who Cannot Decide for Themselves

For an adult who cannot make their own healthcare decisions, the holder of a healthcare power of attorney or a court-appointed guardian acts as personal representative and has the same access rights the patient would have, including copies, disclosures, and amendment requests.

Employers

An employer can ask you directly for a doctor’s note or health documentation. If the employer contacts your provider instead, the provider cannot release your information without your authorization unless another law requires it.12U.S. Department of Health and Human Services. Employers and Health Information in the Workplace One boundary catches people off guard: HIPAA does not protect health information sitting in your employment records, even when the content is medical. Once you hand a doctor’s note to HR, it lives in your personnel file and HIPAA no longer governs it.

Health Apps

The Cures Act requires certified electronic health record systems to support standardized APIs that let you connect third-party apps to your data, and a provider cannot require an app developer to sign a HIPAA Business Associate Agreement as a condition of giving you access through the app.13Office of the National Coordinator for Health Information Technology. Getting Real about Information Blocking and APIs The catch is what happens after your data leaves the provider’s systems. Once it flows into a consumer health app that is not a HIPAA-covered entity, HIPAA generally stops applying. Those apps fall under the FTC’s Health Breach Notification Rule, which requires notice to users, the FTC, and sometimes the media after a breach, with penalties up to $51,744 per violation.14Federal Trade Commission. Health Breach Notification Rule – The Basics for Business That is meaningful, but thinner than HIPAA. Check an app’s privacy policy before connecting it, particularly for language about selling or sharing data with advertisers.

If a Provider Refuses to Give You Your Records

File a complaint with the Office for Civil Rights at the U.S. Department of Health and Human Services. Complaints can be submitted through the OCR complaint portal.15U.S. Department of Health and Human Services. Filing a Health Information Privacy Complaint Since 2019, OCR has settled dozens of enforcement actions targeting providers who failed to give patients timely access, with individual settlements ranging from a few thousand dollars to $240,000. Dental practices, hospitals, mental health clinics, and solo practitioners have all been on the receiving end. The complaint process exists for exactly this situation, and it works.