Medical record privacy: who should have access
The information is yours and the paper may not be. Who can legitimately ask, what minimum necessary means, and the failures that cannot be undone.
· 6 min read
Two things people mean by “my records”
The question of who has access begins with a distinction that is usually skipped: the information in a record and the physical document recording it are not the same object, and they can sit with different people.
A hospital that treats you generates and holds a record. That document is the hospital's, kept as part of its own obligations, and it is not handed over merely because you ask for the file itself. What you are generally seeking is a copy — and the entitlement to obtain a copy is a different thing from ownership of the paper.
The information, on the other hand, is about you, and that is what the privacy question concerns. Frameworks governing personal data operate on the information rather than on the medium, which is why a report is subject to the same considerations whether it is a printout in a folder, a scan in cloud storage, or an image forwarded in a chat.
That distinction resolves a common confusion. Not receiving an original does not mean access has been refused; and holding a document does not mean the holder is free to do anything with the information in it.
This explains how access works as a matter of records and paperwork. It is not legal advice on any particular request or refusal, and where a specific entitlement is disputed that is a question for a professional.
The Indian framework, as it stands
Several instruments bear on this and none is a single dedicated health-records statute, which is the main reason clear answers are hard to find.
The Digital Personal Data Protection Act, 2023 is the general law governing the processing of digital personal data, structured around notice, consent, purpose limitation and the rights of the individual the data is about. It applies to health data as personal data rather than through a separate health-specific chapter, and its provisions are being brought into effect alongside rules made under it, so the operative position depends on the date.
Record-keeping obligations on healthcare providers come from a different direction: the Clinical Establishments (Registration and Regulation) Act, 2010 and the rules made under it, where adopted, together with state legislation, impose requirements on establishments to maintain records and returns.
Professional conduct regulations have separately required a registered practitioner to supply records to a patient on request within a stated period. This is an area where the applicable regulations have been revised and replaced, and one set of regulations notified in recent years was placed in abeyance, so the current instrument in force is the one to check rather than a remembered figure.
And the national digital health infrastructure being built under the Ayushman Bharat Digital Mission is designed around consent-based sharing, using a health account identifier to link records that remain under the individual's control.
Who legitimately asks, and for how much
The useful organising idea is minimum necessary: each party has a legitimate interest in some part of a record, and almost never in the whole of it.
A clinician treating you has the strongest case, and it extends to whatever bears on the treatment. This is the one category where withholding is more often harmful than protective, and where a complete history is the point of keeping records at all.
An insurer's interest arises from the policy and the claim, and it is bounded by them. What is required is what substantiates the claim being made — the discharge summary, the bills, the reports for that episode — rather than an unrestricted history. Insurers commonly ask for authorisation to obtain records, and the scope of what is being authorised is set out in that document, which is worth reading as a scope question rather than a formality.
An employer's position is the narrowest and the most frequently overreached. What can be required is generally what a law or the role requires, commonly the outcome of a fitness assessment rather than the underlying diagnostic record. What precisely may be asked depends on the applicable law and the nature of the work.
Family members have no automatic entitlement by relationship alone, though in practice they act as custodians for children and for adults who ask them to.
And a facility's administrative and billing functions see part of a record as an ordinary consequence of treatment.
Consent, and what it is supposed to look like
Consent is the mechanism the framework relies on, and it works only if it is specific about three things.
What is being shared. “My medical records” is not a scope; a named set of documents for a named episode is. A consent that covers everything is a consent whose limits nobody can identify afterwards.
With whom, and for what purpose. Sharing a report with a specialist for an opinion and sharing it with an insurer to substantiate a claim are different purposes, and a permission given for one is not a permission for the other.
For how long, and whether it can be withdrawn. Frameworks built on consent generally provide for withdrawal, and the design of the national digital health infrastructure reflects this by treating sharing as a granted and revocable permission rather than a transfer.
The practical difficulty is that the moment consent is requested is usually the moment when reading it carefully is least convenient — at an admission desk, or in a claim form under a deadline. That is not a reason to sign nothing; it is a reason to know that the scope clause is where the substance sits.
One asymmetry is worth naming. A consent can be withdrawn for the future. It cannot un-share what has already been shared, and it cannot recall a copy already in someone's hands. So the consequential decision is the first disclosure, not the withdrawal.
Where this fails in practice
The realistic risks to a household's medical records are not sophisticated. They are ordinary handling failures, and they share a characteristic: they are irreversible.
Records living in an email inbox. Reports arrive by email and stay there, which means they sit in an account that is also used for everything else, is reachable from any browser, and is protected by a password that may be shared or reused.
Forwarding in chat. A report sent to a family group is on every recipient's device, in their own backups, and beyond recall. Deleting a message does not retrieve the copies.
Shared links with open access. A cloud folder shared by a link that anyone holding it can open is not access control, and links are forwarded.
An unlocked or unencrypted phone holding the whole file.
Third-party handling. Scanning or printing at a shop leaves the documents on someone else's device unless deliberately removed.
And household backups that copy a medical folder into a general shared drive several people use for unrelated purposes.
What these have in common is that a disclosed record cannot be undisclosed. Unlike most filing errors, there is no corrective step available afterwards, which is what makes the handling decision at the moment of sharing the whole of the control.
The practical response is small: access granted to named people rather than by link, a phone lock, a folder kept separate from general storage, and a habit of sending the specific document asked for rather than the folder.
The custodian problem, and what this does not decide
Two structural points remain, and they pull in opposite directions.
Restricting access too tightly creates its own failure. A file only one person can reach fails when that person is the patient, is travelling, or is occupied elsewhere — which is precisely when it is needed. Households that respond to privacy concerns by narrowing access to a single individual have traded one risk for another, and the second is more likely to materialise.
The arrangement that addresses both is deliberate rather than default: access granted in advance to a small number of named people who would need it, rather than either a single custodian or an open share. For a dependent adult or an elderly parent, deciding this while it can still be discussed is considerably better than improvising it later.
The other point concerns what none of this settles. Deciding who should see a record is a question about handling and permission. It says nothing about what the record contains or means, and controlling access does not put the custodian in a position to interpret what they are guarding.
And where a specific question arises — whether a particular disclosure was permissible, whether a refusal to supply records was proper, what a consent form actually authorises — that is a legal question turning on the instrument in force at the time and on the facts, and the applicable statute, rules or regulations are the source rather than a general explanation.
Common questions
Am I entitled to a copy of my hospital records?
The record itself is generally the establishment's document, held as part of its own record-keeping obligations, while what a patient seeks is a copy — and those are separate things. Professional conduct regulations have required a registered practitioner to supply records to a patient on request within a stated period, but this is an area where the applicable regulations have been revised and replaced and one set was placed in abeyance, so the instrument currently in force is what governs and is the thing to check.
How much of my history can an insurer ask to see?
An insurer's interest arises from the policy and the claim, so what is required is what substantiates the claim being made — typically the discharge summary, bills and reports for that episode — rather than an unrestricted history. Insurers usually ask for an authorisation to obtain records, and the scope of what that document authorises is set out in it, which makes the scope clause worth reading as substance rather than as a formality.
Can an employer require my medical records?
An employer's position is the narrowest of the common cases and the most frequently overreached. What can generally be required is what a law or the nature of the role requires, which is commonly the outcome of a fitness assessment rather than the underlying diagnostic record. What precisely may be asked depends on the applicable law and the work involved, so a specific demand is a question about that law rather than one a general explanation resolves.
What is the biggest practical risk to medical record privacy?
Ordinary handling rather than anything sophisticated: reports left sitting in a general email inbox, a report forwarded into a family chat where it lands in every recipient's device and backups, a cloud folder shared by a link anyone holding it can open, and an unlocked phone containing the whole file. What these share is irreversibility — a disclosed record cannot be undisclosed and deleting a message does not retrieve the copies — so the decision at the moment of sharing is the entire control.
Related pages