The Right to Data Portability: Patient Access and Challenges via FHIR APIs
The right to data portability: FHIR APIs and what patients can actually access | SuperTruth
Summary
While US law grants patients the right to access medical records (via HIPAA/21st Century Cures Act), data retrieved through FHIR APIs remains limited. The key challenge is not merely providing data, but ensuring its 'trustworthiness' and 'provenance.'
Details
In the United States, patients legally possess the right to access their Protected Health Information (PHI). Under HIPAA, covered entities must provide copies of records, but this scope is narrow, covering only data held by a specific entity. The concept of data portability, similar to GDPR, is advancing through the CMS Interoperability and Patient Access Final Rule. This rule mandates the use of FHIR R4 standards via Patient Access APIs, allowing patients to access claims and clinical information. Technically, FHIR defines standardized resources (e.g., Condition, Observation) exchanged via RESTful APIs. While this enables third-party apps to pull data, the scope is limited, often only exposing minimum elements defined by US Core, leaving out critical data like radiology images or full pathology reports. Furthermore, a major gap exists: even when structured, coded data (ICD-10, LOINC) is provided without indicators of its trustworthiness (Provenance)βit is unclear if the diagnosis was assigned by a clinician or auto-populated by billing system. Thus, access does not equal understanding or trust.
Original content copyright by respective publishers