Kept From You
HIPAA does not forbid a physician from obtaining the records of the patients they treated. Custody, a permission no one is required to honor, cost, and a missing design do — while the same record's de-identified twin is licensed for profit.
I. The record you made
At the end of a clinic day a physician signs a stack of notes. Each is a small act of authorship — a history taken, an examination weighed, a differential narrowed, a plan chosen and defended. It is the physician’s work, in the physician’s words, carrying the physician’s judgment and the physician’s name.
Ask that physician, a year after they have moved to another post, to see the records of the patients they treated — to study their own outcomes, to answer a question about their own practice — and the common assumption, held by the physician as firmly as by anyone, is that the answer is no. The records belong to the former employer; the door is closed; that is simply how it works.
The assumption is half right. The employer does hold the record. But the belief that follows from it — that the physician therefore has no way to reach the record of their own work — turns out to rest on a misreading of the very law most often cited to justify the refusal. This essay is about the gap between what the law permits and what the physician actually gets, and about what fills that gap: not a legal prohibition, but custody, cost, and a design choice.
This series has followed a single shape through medicine’s turn toward artificial intelligence: the person who creates a thing of value is often not the person who holds it. The scribe captured the conversation; the model absorbed the corrections; the vendor kept the asset. Here the asset is older and plainer — the record itself — and the custodian is the employer. But the ending is not the one the physician expects.
II. Who holds it, and who may use it
Two questions hide inside “whose record is it,” and conflating them is the source of most of the confusion.
The first is custody. As a matter of property, in most of the United States the clinical record belongs to the practice or facility that maintains it, and employment contracts say so in as many words — the record is the institution’s, held on the institution’s systems, and the physician may not carry it away on departure. On the question of custody, the assumption is largely correct — though even that is a term of the contract more than a fact of nature. State law varies: New Hampshire deems the information in the record the patient’s property; South Carolina makes the physician the owner of the records they made in treating a patient; and Florida makes the treating practitioner the default owner of the record, with the employer owning it only where the employment contract expressly designates it. The institution’s ownership is, in most places, something the physician signed.
The second question is use — and here the physician is not the stranger the custody rule makes them seem. A physician bills under their own National Provider Identifier and bears individual professional liability for the care they deliver, whatever indemnity an employer layers on top. In HIPAA’s terms they are a health care provider in their own right — a covered entity, by the government’s own reckoning: the Centers for Medicare & Medicaid Services, answering the question of who the privacy law covers, states that providers who submit claims electronically are covered and puts “Doctors” at the head of the list. The arrangement is visible in the plumbing of a hospital-owned practice, which typically maintains the physician’s office and the hospital as separate units — distinct record sets, merged only behind a single sign-on — and bills the office’s work under the physician’s personal number. The physician is not a visitor to this record. They are one of the two parties who made it. And that party is, increasingly, an employee: most physicians now practice in hospital-owned or hospital-employed settings rather than their own, and some subspecialties are almost entirely institutional: in the American Thoracic Society’s pediatric pulmonary workforce survey, 96 percent of respondents practiced in academic institutions and just 2 percent in private practice. The custody question is not a niche grievance; for a large and growing share of the profession, it is the condition of the work.
That distinction matters, because the federal privacy rule governs use, not custody, and it does not treat the treating physician as an outsider to the information they generated.
III. What the privacy rule actually permits
Read the operative provisions with a departed physician in mind, and they say something most physicians have never been told.
HIPAA permits a covered entity to disclose protected health information “for treatment activities of a health care provider” — the continuity-of-care pathway, by which a former institution may send a patient’s records to the physician now responsible for, or reviewing, that patient’s care. And it goes further. Under § 164.506(c)(4), a covered entity “may disclose protected health information to another covered entity for health care operations activities of the entity that receives the information, if each entity either has or had a relationship with the individual … the protected health information pertains to such relationship, and the disclosure is … for a purpose listed in paragraph (1) or (2) of the definition of health care operations.”
Paragraphs (1) and (2) are the physician’s own purposes: “conducting quality assessment and improvement activities, including outcomes evaluation,” and reviewing “the competence or qualifications of health care professionals, evaluating practitioner and provider performance.” A physician who wants to study the outcomes of the patients they treated is asking to do exactly what the rule names, and the rule contemplates precisely this transaction: a disclosure from one covered provider, who had the treatment relationship, to another covered provider, who also had it. The only condition of substance is that the work be quality improvement and not research — the definition excludes activities whose “primary purpose” is “the obtaining of generalizable knowledge,” which is to say, a physician auditing their own practice is inside the rule; a physician conducting a study for publication needs authorization or a board’s waiver.
So the premise beneath the common assumption is wrong. The privacy rule does not forbid a former employer from giving a treating physician the records of the patients they treated, for continuity or for quality improvement. It affirmatively permits it.
IV. A shield, not a bar
Why, then, is the answer still no?
Because the rule permits; it does not compel. Its verb is “may.” A covered entity may disclose for these purposes — and may decline to. HIPAA is a permission slip, not a mandate, and it supplies the physician no lever to force the holder’s hand. It also creates no private right of action: a physician refused their records cannot sue under HIPAA to obtain them — federal courts have held uniformly that the statute confers no private remedy and leaves enforcement to the Department of Health and Human Services (Acara v. Banks, 5th Cir. 2006). On its own, the privacy rule can neither open the door nor be used to pry it.
This inverts the way the law is usually invoked. When a physician asks for the records, the reflexive institutional answer is that “HIPAA” prevents it — the privacy rule deployed as a bar. It is not a bar. It is, if anything, a shield the requester can raise against the objection: the disclosure the physician seeks is one HIPAA expressly allows. The mistake, then, is to make the request under HIPAA at all, as though the privacy rule were the source of the right. It is not. It is only the answer to the refusal.
Where the right itself would live is a different and largely unmapped place. If a physician has an enforceable claim to a copy of the records they authored, it rests not on the privacy rule but on state law — on common-law and tort principles about a professional’s access to their own work product, and on the terms of the employment contract. And here the documents are conspicuously one-sided: the standard agreement asserts the institution’s ownership of the record while saying nothing at all about the physician’s right to a copy of it. That silence is not the same as prohibition. It is an open question — one that would have to be answered, if it ever is, in a test case.
It has largely not been. The reported case law appears essentially silent — no published decision squarely resolves a physician’s right to obtain a former employer’s records for quality improvement or continuity, and no court appears to have construed the operations-disclosure provision at all — and an unreported trial-court suit, quietly filed and quietly settled, is exactly the kind of thing a search of published opinions would miss. A right that is never asserted produces no law, and physicians rarely assert this one: challenging a former employer through legal channels carries a cost to a career that most are unwilling to pay. The permission sits on the page, unlitigated, while the practice runs the other way.
But it is not merely hypothetical, and one state has already shown what the answer looks like when a legislature bothers to give it. Florida’s records statute makes the treating practitioner the default owner of the record, and then, in a subsection most physicians have never read, converts the federal permission into a command: a records owner “shall release to a health care practitioner who, as an employee of the records owner, previously provided treatment to a patient, those records that the health care practitioner actually created or generated when the health care practitioner treated the patient.” Not may — shall, limited to the notes, orders, and summaries the physician personally wrote. The precise right this essay has been circling — the one the federal rule allows but will not enforce — exists as a mandate in at least one state. Such statutes are rare: a check of several states with otherwise-detailed records laws turned up no equivalent, though New Mexico’s medical board at least bars a practice from denying a departing physician the information needed to reach their patients. Florida is the outlier that shows the thing can simply be written down. What is missing elsewhere is not the concept. It is the statute.
V. The privilege shields the product, not the record
One structure is often assumed to seal the record shut, and it is worth separating from the rest, because it does less than it appears to.
Peer review is confidential by design. The federal Health Care Quality Improvement Act immunizes qualifying professional review from most liability, and it does so only when the review meets its standards — a reasonable belief that the action furthers quality care, a reasonable effort to find the facts, adequate notice and hearing, and a reasonable belief the action was warranted; a review that fails those standards can lose the protection. State privilege laws add confidentiality for the committee’s proceedings, and the Patient Safety and Quality Improvement Act adds a separate privilege for “patient safety work product.”
But each of these protects the committee’s deliberative material — its analyses, its minutes, the work it creates in the course of review. None of them converts the underlying medical record into privileged material. The patient safety statute is explicit that its protected work product does not include a patient’s medical record, billing information, or any other original patient record. The record of the care itself remains what it was: an ordinary medical record, governed by the privacy rule, reachable through the same operations pathway as any other. The privilege walls off the room where the physician’s work was judged. It does not wall off the physician’s work.
VI. The practical wall
If the law permits the disclosure and the privilege does not forbid it, what actually keeps the record out of the physician’s hands is a set of frictions that never appear in a statute.
The first is custody plus leverage. The holder is not required to release, faces no HIPAA penalty for refusing, and has every institutional incentive to say no to a departed clinician. The physician’s only recourse is the test case they will not bring.
The second is infrastructure, and it is underappreciated. A physician who receives a copy of patient records becomes responsible for protecting them — which in practice means maintaining a certified electronic record system with an ongoing subscription, carrying cyber-liability coverage, and standing up the breach-notification processes the law requires if the data leaks. The institution can also charge for the copy: the labor of searching, segregating, and exporting the records into a downloadable file. For a single continuity question this is manageable. For the aggregate a physician would need to study their own practice, it is a second job with a startup cost, and most physicians, weighing it, leave their work product behind rather than build a compliance apparatus to reclaim it.
The third is design. Access to an institution’s record system is provisioned by the institution and revoked on departure — the security rule requires terminating a former workforce member’s access — and there is no mechanism, anywhere in the current architecture, that gives a physician durable, portable, read-only access to the records of the patients they personally treated once they have left. The login dies with the badge. Nothing replaces it.
VII. The twin that is sold
Hold that picture beside another, because the contrast is the point.
The same record the physician cannot readily retrieve is, in de-identified form, flowing out of the institution at enormous scale. The dominant electronic-record vendors aggregate their customers’ clinical data into vast research networks — one vendor’s platform describes drawing on the records of hundreds of millions of patients and tens of billions of encounters — and that de-identified data is licensed and used to build products, exactly as the second essay in this series described: once de-identified, the information leaves the privacy rule and can be pooled and sold. The identified record, which the treating physician has a lawful pathway to obtain and a genuine reason to study, stays locked in custody. The anonymized shadow of that same record moves freely to whoever will pay for it.
It is the series’ pattern in its starkest form. The physician generated the record. The law does not forbid the physician from using it. And still the physician is the one party in the whole arrangement who cannot get it — while its de-identified twin is treated as an asset and monetized.

VIII. The case for the custodian, and the fix that is not a law
The custody arrangement is not an abuse, and the honest version of this argument has to say why it exists — because the reasons are real. A single, stable custodian keeps the record intact when a clinician leaves, retires, or dies; concentrates the duty to safeguard it in an accountable entity; and prevents patient data from scattering across the devices of everyone who ever touched a chart. The peer-review privilege exists so that candid review can happen at all. A regime that simply handed every physician a permanent copy of every record they ever wrote would trade these protections for a sprawl of risk. Grant all of it.
None of it answers the narrow question this essay has arrived at, because that question no longer needs a new law to answer it. The privacy rule already permits the treating physician to receive the records of their patients for continuity and quality improvement. What is missing is not permission. It is a way to exercise the permission that does not require a lawsuit, a second compliance apparatus, and a fee — and a holder willing, or obliged, to honor it.
The shape of a fix is therefore not exotic, and it already exists, in pieces, on two tracks. One is legislative: a state can require what the federal rule merely permits, as Florida has, turning the permission into a duty to hand a departing physician the notes they wrote. The other is architectural. The vendors that already aggregate and license the de-identified record could provide the identified one back to its author on the narrowest possible terms — a physician-linked, read-only credential, tied to the National Provider Identifier, that survives a change of employer and reaches only the records of the patients that physician personally treated, priced, if it must be, as a subscription or per-access fee. The capability plainly exists; it is the same infrastructure that moves de-identified data to commercial buyers today. Neither the law nor the technology is the obstacle. Its absence for the physician is a choice.
The question to carry out of the exam room is the one the common assumption is built to prevent a physician from asking, because the assumption says the answer is already no: the record of the care you gave — which the law says you may have, for the reasons you would actually want it — who, exactly, is keeping it from you, and why?
Satyanarayan Hegde, MD, is a pediatric pulmonologist and the founder of Access Pediatric.
The author is not an attorney, and nothing in this article is legal advice. Readers must consult their attorney for legal questions.