It's natural to wonder who can look at your medical records. HIPAA sets clear limits: your health information can be used and shared for specific, defined purposes, and most other uses require your written permission. Here's a plain-language map of who can see what, and when your sign-off is needed. Understanding these boundaries can be reassuring: your records aren't an open book, and the law draws real lines around how they may be used.
Access without your separate authorization
HIPAA permits certain uses and disclosures without asking you to sign an authorization each time, mainly so that your care and coverage can actually function day to day:
- Treatment: The clinicians and staff directly involved in your care.
- Payment: Your health plan and billing staff, to process and pay claims.
- Health care operations: Activities like quality review, care coordination, and certain administrative functions.
Other permitted disclosures
HIPAA also allows disclosures in specific public-interest situations — for example, certain required public-health reporting, specific law-enforcement requests, and responses to court orders or subpoenas. These are limited, rule-bound, and not a free pass for general sharing.
Uses that require your authorization
For most other purposes, a provider or plan must obtain your written authorization before sharing. Common examples include:
| Use | Authorization needed? |
|---|---|
| Sharing records with an employer | Yes |
| Most marketing | Yes |
| Sale of your information | Yes |
| Sharing psychotherapy notes | Yes, with narrow exceptions |
What HIPAA doesn't cover
HIPAA applies to covered entities and their business associates — not to everyone who might hold health information about you. Many wellness apps, websites, search engines, and consumer devices you use directly are not covered by HIPAA, so the information you share there is governed by their privacy policies and other consumer-protection laws, not by HIPAA's rules.
Your tools to control access
- Review the Notice of Privacy Practices your providers and health plan give you.
- Ask for an accounting of disclosures to learn about certain ways your information has been shared.
- Request restrictions on specific uses or disclosures — providers may or may not be required to agree.
- File a complaint with the HHS Office for Civil Rights if you believe your privacy was violated.
Common myths worth clearing up
A few misunderstandings come up again and again. HIPAA does not prevent your own doctor and the specialists treating you from sharing information with each other — coordination of your care is specifically permitted. It does not mean a hospital can never tell a worried family member anything; sharing relevant information with those involved in your care is allowed in many situations. And HIPAA does not cover every company that touches health data, so a wellness app or a website you visit may not be bound by it at all. Knowing what the law actually does — and doesn't — do helps you direct your energy to the protections and tools that genuinely apply.
The takeaway
The people who can see your records without extra paperwork are mostly those involved in treating you and getting you covered. Beyond that, the default shifts toward needing your permission — and you have concrete tools to see and shape how your information is used.