Governing Health Data Access and Secondary Use: Information Blocking, Privacy, Consent, and Hospital Accountability, a Narrative Review

The Data Covenant, an executive review of health-data access, privacy, and accountable secondary use
Greg Wahlstrom, MBA, HCM
AuthorGreg Wahlstrom, MBA, HCMThe Healthcare Executive · August 13, 2026
Executive standardAccess is a right.
Use requires authority.

Transparency and privacy must be governed together.

Background and Objective

Hospital leaders must make electronic health information available for lawful access, exchange, and use while protecting it from unauthorized disclosure, exploitation, and avoidable harm. The legal architecture is distributed across HIPAA, the 21st Century Cures Act information-blocking rules, substance use disorder confidentiality rules, consumer-protection law, and state law. The operational question is not simply whether data should move. It is whether a movement has a lawful purpose, recognized authority, proportionate scope, and verifiable controls. This review examines how hospital leaders can govern patient access and secondary use as one accountable operating system.

Methods

A targeted narrative search was completed on August 13, 2026. PubMed/MEDLINE was searched for English-language peer-reviewed research published from January 2000 through August 13, 2026 on information blocking, patient portals, proxy access, confidentiality, online tracking, health information exchange, secondary use, de-identification, interoperability, and governance. Primary legal authorities were retrieved separately from the United States Code, Electronic Code of Federal Regulations, Federal Register, and official agency materials. News reports, vendor marketing, legal blogs, and unsupported commentary were excluded as evidence.

Key Content and Findings

Information blocking has declined but persists. Patient access has expanded, while comprehension, language access, proxy identity, adolescent confidentiality, and intimate-partner-violence risks remain uneven. Published national research found third-party tracking on nearly all hospital websites studied. Secondary use can support research, quality improvement, population health, and learning health systems, but de-identification manages rather than eliminates risk. Durable governance separates a patient’s access right from an organization’s authority to reuse or disclose data. It requires named decision rights, purpose limitation, minimum-necessary analysis where applicable, identity and proxy controls, vendor oversight, data lineage, exception documentation, equity safeguards, and outcome verification.

Conclusions

Hospitals should govern health data through an executive covenant: every material access, disclosure, or secondary use must have a stated purpose, valid authority, proportionate scope, and retained proof. Transparency and privacy are linked obligations requiring one accountable operating model and board-level assurance.

§01

Introduction: Access and Protection Are Coexisting Duties

The central health-data governance question is no longer whether a hospital possesses information. It is whether the hospital can explain who may access it, for what purpose, under which authority, in what form, for how long, and with what evidence of appropriate use. That question applies to a patient opening a laboratory result, a clinician retrieving an outside record, a family caregiver using delegated portal access, a researcher receiving a limited data set, a quality team building an analytic cohort, and a marketing vendor receiving web-event data. The technical act may be a transmission in every case, but the legal authority, ethical justification, and operational safeguards are not interchangeable.

Federal policy has strengthened the patient’s position. The HIPAA Privacy Rule provides a broad right to inspect or obtain protected health information in a designated record set, subject to defined limitations [33,34]. The 21st Century Cures Act prohibits certain practices that are likely to interfere with the access, exchange, or use of electronic health information, unless required by law or covered by an applicable exception [35,36]. The information-blocking regulations define electronic health information by reference to electronic protected health information that would be included in a designated record set, with specified exclusions, and place duties on health care providers and other regulated actors [36]. Substance use disorder records are also governed by 42 CFR part 2 [41]. These regimes overlap, but they do not collapse into a single rule.

The empirical record shows why governance cannot be reduced to a privacy approval queue. In a national survey, 27% of hospitals reported sometimes or often observing potential information blocking by any actor in 2023, compared with 42% in 2021; 13% of health information organizations routinely observed potential blocking by hospitals or health systems [1]. Earlier national research found information blocking to be prevalent before enforcement and identified pricing, contractual, and strategic restrictions as recurring mechanisms [2,3]. The executive challenge is therefore bidirectional: prevent unauthorized release without converting caution, convenience, vendor limitations, or market strategy into unlawful interference.

This review advances an operating premise: access is a right; secondary use requires authority. The premise does not imply that every access request must be granted or that every secondary use requires individual authorization. It means that the organization must distinguish the legal basis and safeguards applicable to each pathway. A hospital that cannot make that distinction at the point of work will produce delay, inconsistency, hidden disclosure, or all three.

§02

Methods

This narrative review used a purposive, reproducible search strategy designed for executive and operational relevance. PubMed/MEDLINE was searched through August 13, 2026 for peer-reviewed English-language literature published from January 2000 through August 13, 2026. Search concepts included combinations of: hospital, health system, electronic health information, health data, patient portal, online record access, information blocking, 21st Century Cures Act, immediate release, test results, proxy access, caregiver, adolescent confidentiality, intimate partner violence, tracking pixel, online tracking, secondary use, health information exchange, consent, de-identification, re-identification, semantic interoperability, learning health system, privacy, governance, and equity.

Eligible evidence included empirical studies, systematic reviews, and peer-reviewed implementation reports with direct relevance to hospital governance, patient access, privacy, exchange, or secondary use. Articles were selected for recency, methodological relevance, national or multisite scope when available, and their ability to inform an executive decision or safeguard. Technical proposals without implementation evidence were not used to support effectiveness claims. Reference lists and citing articles were reviewed to identify additional relevant studies. Because the purpose was synthesis rather than pooled effect estimation, no meta-analysis was performed.

Legal research was conducted separately. Primary legal sources included 42 U.S.C. 300jj-52, 45 CFR parts 160, 164, and 171, 42 CFR part 2, relevant Federal Register rules, and official agency materials [33-41]. These sources were used only to describe legal requirements, regulatory structure, and current agency positions. Peer-reviewed studies were used for empirical and operational claims. This article does not attempt a fifty-state survey, and hospital counsel should assess state-specific confidentiality, consent, minor-access, reproductive-health, genetic-information, biometric, consumer-privacy, and breach-notification requirements.

Table 1. Search strategy summary
ElementApproach
DatabasePubMed/MEDLINE; reference-list and citation-chain verification
Search dateAugust 13, 2026
TimeframeJanuary 2000 through August 13, 2026
Core conceptsInformation blocking; patient access; portals; proxy identity; adolescent confidentiality; immediate results; tracking technologies; secondary use; consent; de-identification; interoperability; governance; equity
InclusionEnglish-language peer-reviewed empirical studies, systematic reviews, and implementation reports directly relevant to hospital or health-system governance
ExclusionNews reports; vendor marketing; legal blogs; generic technology commentary; non-health-care examples; technical proposals used as proof of real-world effectiveness
Legal sourcesPrimary statutes and regulations plus official agency rules and guidance, reviewed separately from empirical evidence
SynthesisPurposive narrative synthesis; no pooled estimate
§03

One Data Environment, Different Authorities

Hospital data move through at least four governance pathways. The first is individual access: a person seeking information about themselves. The second is care delivery: treatment, payment, and health care operations under applicable law and organizational policy. The third is public-interest use, such as public health, oversight, or approved research. The fourth is discretionary secondary use, which may include product development, commercial analytics, advertising, or other activity outside the original care relationship. Each pathway may touch the same record, but it does not carry the same authority.

The HIPAA right of access reaches information in a designated record set and gives individuals rights to inspect or receive copies, including electronically when readily producible [33,34]. Information-blocking law evaluates whether a practice is likely to interfere with lawful access, exchange, or use, applying a provider knowledge standard and detailed regulatory exceptions [35,36]. By contrast, a hospital’s secondary use requires an independent basis under the Privacy Rule, another law, valid authorization, an Institutional Review Board or Privacy Board pathway, de-identification, or another legally available route. A signed technology contract is not itself a disclosure authority.

This separation has operational value. When staff label every data movement as “sharing,” the organization loses the distinctions that determine service levels, minimum-necessary analysis, authorization, accounting, contracting, and patient choice. The better unit of governance is a use case with four registered fields: purpose, authority, scope, and proof. Purpose explains the outcome being pursued. Authority identifies the legal and organizational basis. Scope defines the data, population, recipients, duration, and permitted actions. Proof retains the decision, configuration, disclosure, audit trail, and result.

The governing covenant should be written into intake forms, architecture review, privacy analysis, data-use agreements, vendor review, API governance, portal configuration, and board reporting. If a request reaches production without those fields, the control failure has already occurred.

Governing instrument 01

Four clauses before data moves

§ 01PurposeName the patient, clinical, research, operational, or public-interest outcome.
§ 02AuthorityRegister the right, duty, permission, exception, or approved pathway.
§ 03Minimum scopeLimit people, fields, recipients, functions, and duration to what the purpose requires.
§ 04ProofRetain the decision, transmission, controls, result, and closure.
The clauses distinguish lawful patient access from organizational reuse without forcing both into one generic approval process.
§04

Patient Access Is a Service Obligation

Immediate electronic release has materially changed patient behavior. At one academic center, switching to immediate release increased patient viewing of diagnostic results [5]. Research in radiology and oncology similarly found increased access following implementation of information-blocking provisions [9,10]. In a 2024 national survey, 70% of patients and 92% of portal users viewed results in a portal; 58% of patients viewed results before hearing from a clinician. Only 66% reported understanding what they viewed, and understanding was lower among people with lower digital literacy [11].

These findings reject two simplistic positions. First, access should not be delayed merely because information may be complex. Patients consistently express strong preferences for prompt access, including to imaging and sensitive results [21,22]. Second, posting information is not the same as communicating it. Published studies show that explanatory context, clinician encouragement, digital literacy, and portal design influence understanding [11,30]. A lawful release can still be a poor service if the patient receives unexplained terminology, no expected response time, inaccessible language, or no route to urgent clarification.

Hospitals should therefore manage access as a clinical-administrative service line. The operating standard should include release reliability, identity proofing, request completion time, format fulfillment, denial review, amendment pathways, interpretation support, language access, accessibility, and escalation. The standard should not rely on a central health-information-management team to repair every downstream configuration. Laboratory, radiology, pathology, clinical documentation, portal operations, and specialty leadership each own part of the release experience.

Equity must be measured rather than assumed. In a 2025 study of 511 hospitals in counties with substantial limited-English-proficiency populations, 29.4% offered patient-portal login pages only in English, and only 4.7% offered the most common local non-English, non-Spanish language [28]. Among admitted surgical patients, immediate release was associated with increased viewing, but older age, Spanish language, noncommercial insurance, and Black or Hispanic race and ethnicity were associated with lower portal use [29]. National survey research likewise identifies comfort with computers, internet access, privacy concerns, and preference for direct communication as modifiable barriers [30]. A hospital cannot claim successful transparency while access depends on English fluency, broadband, or a shared household credential.

§05

Information Blocking Requires a Governed Exception Process

Information blocking is not a synonym for any delay or failed exchange. Under 42 U.S.C. 300jj-52 and 45 CFR part 171, the analysis depends on the actor, the practice, the likelihood of interference, the applicable knowledge standard, and whether an exception is satisfied [35,36]. The current regulations include exceptions involving preventing harm, privacy, security, infeasibility, health IT performance, content and manner, fees, licensing, and other defined circumstances [36]. For providers, a practice must be known to be unreasonable and likely to interfere with access, exchange, or use, unless required by law or covered by an exception [35,36].

The operational risk lies in informal, undocumented withholding. A clinician may believe release could cause harm; registration staff may see conflicting proxy identities; a privacy analyst may identify an unmet legal precondition; an interface team may face corrupted data; or cybersecurity staff may need to contain an active threat. Those concerns can be legitimate. They become governance failures when the organization has no standard to determine breadth, duration, alternative access, documentation, review, or closure.

For example, the preventing-harm exception requires more than generalized discomfort. The regulation specifies a reasonable belief that the practice will substantially reduce a risk of harm, that the practice be no broader than necessary, and that other conditions be met [36]. The privacy exception includes pathways for unmet legal preconditions, denials consistent with HIPAA access provisions, and documented individual requests not to share [36]. Hospital policy should translate these elements into operational fields without replacing case-specific legal and clinical judgment.

Identity is another source of friction. Published implementation research describes difficulties meeting patient-identity interoperability and information-blocking requirements [4]. A weak response is to choose either indiscriminate release or indefinite delay. A stronger response uses tiered identity proofing, rapid discrepancy resolution, provisional safeguards, and retained evidence of what was done. The board should see rates of failed match, duplicate records, unresolved access tickets, exception use, review reversals, and days to closure. Without those measures, leaders cannot distinguish prudent protection from habitual interference.

HHS has established provider disincentives for information blocking through federal program authorities, while OIG may impose civil monetary penalties on specified non-provider actors up to the statutory maximum per violation [35,38,39]. Compliance should therefore be managed as an operating discipline, not a once-a-year legal attestation.

Exception docket

Withholding requires a record

PracticeWhat access, exchange, or use is affected?
AuthorityWhich law, rule, or information-blocking exception applies?
BreadthWhy is the practice no broader and no longer than necessary?
AlternativeCan lawful access be fulfilled by a different content, manner, recipient, or time?
ClosureWho reviews, reverses, expires, or verifies the decision?
An undocumented exception is not a control. It is an unresolved practice.
§06

Proxy Access, Adolescents, and Safety-Critical Privacy

Proxy access is where abstract privacy principles collide with family care. Care partners often need medication lists, appointments, results, discharge instructions, and messaging capabilities. Yet portal systems frequently fail to collect structured information about who is involved in a person’s care, and burdensome delegation processes encourage credential sharing [14]. In a survey of 102 hospitals, 68% offered proxy accounts for adult patients, 45% of surveyed personnel endorsed password sharing, and only 19% of hospitals with proxy access allowed patients to restrict the information visible to the proxy [15].

The governance defect is not family involvement. It is invisible identity. When a caregiver logs in as the patient, the audit trail cannot reliably show who viewed information, sent a message, changed a preference, or downloaded a record. The hospital also cannot apply role-specific limits. A mature proxy system uses separate credentials, records the relationship and authority, supports expiration and revocation, and distinguishes view, message, scheduling, billing, and download permissions.

Adolescent access requires additional safeguards because federal access rules interact with state minor-consent and confidentiality laws, guardianship, and clinical context. Multisite research has documented wide variation in pediatric and adolescent electronic data-sharing practices after the Cures Act [7]. Providers report continuing difficulty protecting confidential adolescent information in the EHR [18]. One institution reduced erroneous adolescent portal activation by comparing adolescent contact information with parent or guarantor information and routing discrepancies for review [17]. This is a useful model because it converts a privacy principle into a measurable registration control.

Safety risks extend beyond adolescence. Peer-reviewed analysis warns that multiuser records and proxy access can expose sensitive information if systems cannot distinguish users and data segments [16]. Research focused on survivors of intimate partner violence describes risks from immediate electronic access when an abusive partner controls credentials, devices, notifications, or proxy relationships [19]. These concerns do not justify categorical withholding. They justify confidential contact preferences, safe-notification modes, rapid proxy revocation, granular segmentation where lawful and technically feasible, individualized exception analysis, and workforce training that recognizes coercive control.

Table 2. Decision-right architecture for access and reuse
DecisionAccountable ownerRequired evidenceEscalation trigger
Patient access configurationChief health information officer or equivalent executiveDesignated-record-set map; release rules; service-level measures; denial and review pathwaySystematic delay, unexplained suppression, or repeated patient harm
Information-blocking exceptionDesignated privacy/legal-clinical authorityApplicable exception; facts; breadth; duration; alternative access; reviewerPractice affects a class of patients, persists, or lacks clear closure
Proxy and adolescent accessClinical, privacy, registration, and digital leadershipIdentity, relationship, authority, scope, expiration, revocation, notification safetyCredential sharing, conflicting authority, safety concern, or state-law uncertainty
Secondary-use approvalEnterprise data-governance council with executive accountabilityPurpose, legal basis, data scope, recipient, retention, safeguards, patient impact, benefit measureCommercial use, novel linkage, sensitive data, external model development, or unclear benefit
Tracking technologyPrivacy, security, digital, marketing, and procurement ownersData-flow test, recipient list, contract, configuration, authorization analysis, risk assessmentAuthenticated page, precise identifiers, sensitive pathway, advertising use, or unexplained third party
De-identification releaseQualified privacy/statistical authorityMethod, residual risk, recipient controls, linkage limits, re-identification prohibition, destructionHigh-dimensional data, free text, images, rare events, or broad downstream reuse
Delegated access

Identity must survive the handoff

01PatientChooses or confirms the representative where applicable.
02AuthorityRelationship, legal status, scope, and limits are recorded.
03CredentialThe proxy receives a separate identity, never the patient’s password.
04AuditViews, messages, downloads, changes, and revocation remain attributable.
Delegation should make caregiving easier while preserving patient autonomy, safety, and reliable audit evidence.
§07

Secondary Use Begins With Purpose, Not Data Availability

Secondary use includes activities beyond the immediate purpose for which information was collected. It can produce substantial public value through research, quality improvement, safety surveillance, population health, operational learning, and service design. It can also obscure accountability when a data warehouse, analytics platform, or vendor contract becomes the de facto authority to reuse whatever is technically available.

The first question is not “Can the system export it?” It is “What purpose is being authorized?” A purpose statement should be specific enough to determine which data are relevant, which population is included, who may act, how long the use lasts, whether results return to care, and what would constitute misuse. “Innovation,” “analytics,” and “improving experience” are categories, not purposes.

Purpose limitation enables proportionate scope. The HIPAA minimum-necessary standard generally requires reasonable steps to limit uses, disclosures, and requests to what is necessary for the intended purpose when the standard applies, while recognizing exceptions such as disclosures for treatment [33,37]. A governance intake should therefore record whether minimum necessary applies, how the scope was determined, and who approved an entire-record request. The same discipline is useful even where the legal standard does not apply because it reduces exposure and improves analytic clarity.

Patient trust is sensitive to the identity and purpose of the recipient. Qualitative research on health information exchange found that perceived security, noncommercial recipients, transparency, and specific consent options shaped willingness to share [31]. Experimental research found that greater patient control increased intention to consent and reduced the negative effect of privacy concern [32]. These findings do not create a universal legal requirement for granular consent. They support an executive conclusion: organizations should not assume that a legally permissible use will be viewed as legitimate if the purpose, recipient, or benefit is hidden.

Every recurring secondary use should have a named service owner, privacy or legal basis, data steward, technical custodian, retention period, downstream-use limit, patient-impact assessment, and measurable benefit. Approval without a benefit owner produces permanent data exposure and temporary accountability.

§08

Tracking Technologies Are a Data-Governance Problem

Hospital leaders often treat public websites as communications infrastructure rather than health-data infrastructure. Empirical evidence challenges that assumption. A census study of United States nonfederal acute care hospital websites found third-party tracking on 98.6% of sites, including transfers to technology companies, advertising firms, social media companies, and data brokers [12]. A later longitudinal study found that pixel tracking was common and was associated with increased breach risk, although observational association does not establish that pixels caused every breach [13].

The legal analysis is fact-specific. OCR states that HIPAA obligations apply when information collected through tracking technologies or disclosed to vendors includes protected health information, particularly on authenticated pages and in mobile applications [40]. A federal district court vacated the portion of OCR guidance that treated an IP address combined with a visit to an unauthenticated public webpage addressing specific conditions or providers as sufficient by itself to trigger HIPAA obligations; the current HHS page expressly notes that limitation [40]. Hospitals should not overstate the guidance, but neither should they treat the ruling as permission to deploy unexamined trackers.

The executive control is a verified data-flow inventory. It should identify each script, tag manager, software development kit, cookie, pixel, session-replay tool, analytics endpoint, advertising recipient, and configuration across public sites, scheduling pages, portals, telehealth, mobile applications, recruitment platforms, and donation pages. The inventory must capture the actual data transmitted, not the vendor’s product description.

Deployment should require a purpose, recipient, field-level data map, authenticated-versus-unauthenticated classification, privacy and security analysis, contract, retention limits, configuration owner, and removal date. Marketing cannot own this decision alone because the consequences reach privacy, security, legal, reputation, patient safety, and consumer protection. Procurement cannot rely solely on a business-associate agreement because a contract does not cure a disclosure that the Privacy Rule does not permit.

The board-level question is simple: can the organization name every third party receiving data from its digital front door? If the answer requires a new scan each time it is asked, governance is not operating.

Digital front door

Know every recipient

Public sitePages, searches, forms, cookies, pixels, tag managersMap actual fields
SchedulingService line, location, clinician, appointment intent, identifiersTest before launch
Authenticated portalRecord data, messages, results, claims, device and session identifiersHighest scrutiny
Mobile applicationSoftware development kits, device IDs, permissions, diagnosticsVerify downstream use
Third partiesAnalytics, advertising, support, hosting, optimization, recruitmentOwner + expiry
A vendor list is not a data-flow inventory. Hospitals need evidence of the fields and events transmitted in production.
§09

De-Identification Reduces Risk; It Does Not End Accountability

De-identified information is central to research and analytics, but the term is often used imprecisely. Under HIPAA, information meeting the Privacy Rule’s de-identification requirements is not protected health information under that rule [33]. The two regulatory pathways are the safe-harbor method and expert determination [33]. Both require disciplined implementation. Neither supports the claim that re-identification is conceptually impossible.

The evidence is more nuanced than common warnings. A systematic review of re-identification attacks found high average rates across a small and heterogeneous literature, but only two attacks used data de-identified under existing standards, and the authors concluded that the evidence was insufficient to judge those standards broadly [24]. Earlier multisite work demonstrated that statistical de-identification can preserve more useful demographic detail while maintaining risks no greater than safe harbor in the studied settings [23]. A 2026 systematic review found rapidly evolving methods across free text, images, and tabular data, along with persistent limitations in generalizability, multilingual data, and reproducibility [25].

Hospital policy should therefore treat de-identification as an evidence-backed process tied to context. Risk depends on the data’s dimensionality, rarity, free text, image pixels, geography, dates, linkability, recipient capability, public auxiliary data, and downstream permissions. High-dimensional data can be identifying even after obvious fields are removed. Expert determination should document anticipated recipients and controls rather than evaluate a dataset in a vacuum.

Contracts should prohibit re-identification, redisclosure, and unauthorized linkage; require safeguards and incident reporting; define retention and destruction; and preserve audit or verification rights. These controls do not transform a deficient de-identification method into a compliant one. They add accountability to a technically and legally valid release.

§10

Interoperability and Learning Require Semantic Stewardship

Data availability is not the same as usable information. Semantic interoperability requires that exchanged data retain meaning across systems. A systematic review identified terminology, information models, standards, governance, and implementation context as recurring elements of semantic interoperability [27]. If a hospital releases data that are technically complete but clinically ambiguous, inconsistent, or detached from provenance, the patient and receiving organization inherit a new safety burden.

Learning health systems also require distributed trust. The Cumulus platform illustrates a federated model using Fast Healthcare Interoperability Resources to support multisite learning without centralizing every source record [26]. The design is important not as proof that one architecture fits all hospitals, but as evidence that governance and technical structure can reduce unnecessary data movement while enabling research and public-interest analysis.

Hospital leaders should require provenance, common definitions, data-quality thresholds, and ownership for every enterprise data product. A denominator called “active patient,” “avoidable admission,” or “portal user” should not change silently between analytics teams. Semantic drift creates legal risk when a stated purpose and minimum scope no longer match what the data product actually represents.

The stewardship model should distinguish source-system ownership, data-product ownership, and use-case accountability. Source owners maintain integrity and lineage. Product owners maintain definitions, transformations, and fitness for use. Use-case owners justify purpose, authority, and benefit. No single role can substitute for the others.

§11

An Executive Operating Model for the Data Covenant

The Data Covenant is an operating model, not a mission statement. It places four tests before every material data movement:

  1. Purpose: What patient, clinical, operational, research, public-health, or legally required outcome will this access or use serve?
  2. Authority: Which right, permission, duty, exception, authorization, contract, or approved research pathway permits the action?
  3. Minimum scope: Which people, fields, dates, systems, recipients, functions, and retention period are necessary and proportionate?
  4. Proof: What evidence will show who approved, what moved, who received it, what controls operated, what benefit resulted, and when the use ended?

The governing body should assign one accountable executive, supported by privacy, legal, compliance, clinical, health-information management, security, digital, research, analytics, marketing, procurement, and patient-experience leaders. The accountable executive is not expected to make every decision. The role ensures that decisions occur at the right level, use one vocabulary, and close with evidence.

Routine cases should be standardized. Patient access requests, common treatment exchanges, established quality reports, recurring public-health submissions, and approved research extracts should move through tested pathways. Novel or high-risk cases should escalate based on defined triggers: commercial purpose, sensitive data, new linkage, external model development, unclear authority, patient-safety risk, broad population scale, or inability to verify downstream use.

The operating rhythm should include a weekly review of unresolved access and exception cases, monthly review of high-risk secondary uses and trackers, quarterly review of performance and incidents, and annual board assurance. Exceptions should have owners and expiration dates. A permanent exception without periodic review is policy drift.

Executive standard

The Data Covenant

Authorized use
01Purpose namedThe outcome is specific enough to test.
02Authority registeredThe legal and organizational basis is explicit.
03Scope boundedData, people, recipients, functions, and time are proportionate.
04Proof retainedApproval, movement, control, benefit, and closure remain auditable.
Every material access, disclosure, or secondary use enters one executive vocabulary without losing its distinct legal pathway.
§12

A 24-Month Implementation Agenda

During the first three months, the organization should establish accountability and visibility. Name the executive owner. Inventory patient-access pathways, information-blocking policies, portal release rules, proxy arrangements, secondary-use approvals, external data recipients, tracking technologies, de-identification methods, and key contracts. Resolve any active access backlog or unidentified tracker rather than waiting for the inventory to be perfect.

Months four through nine should standardize decision rights. Implement the four-field intake, codify exception documentation, establish proxy and adolescent identity controls, classify sensitive uses, create a secondary-use register, and require field-level data maps for new vendors. Define service levels for access and review. Update contracting templates to address purpose, downstream use, re-identification, retention, incident reporting, and verification.

Months ten through eighteen should integrate the controls into technology and work. Configure auditable release rules, proxy roles, consent and authorization capture, API registration, lineage, role-based access, tracker management, and expiration. Build equity measures by language, age, disability, payer, race and ethnicity, geography, and access channel where lawful and methodologically appropriate. Train staff through scenarios, not policy recitation.

Months nineteen through twenty-four should verify benefit and retire exposure. Test whether patients receive timely, understandable access. Sample exception decisions. Reconcile the vendor and tracking inventories with network observations. Review whether secondary uses delivered stated benefits. Destroy or return data when purpose ends. Present the board with evidence, unresolved risks, and corrective actions.

Table 3. Board data-governance assurance scorecard
DomainPrimary evidenceBalancing measure
Patient accessMedian and 90th-percentile fulfillment time; portal-release reliability; denial and review ratesComprehension, support demand, language access, accessibility, patient-reported harm
Information blockingOpen cases; exception category; days unresolved; repeat practices; reversalsPrivacy, safety, security, data-integrity events
Proxy identityDelegated accounts; credential-sharing reports; activation errors; revocation timeCare-partner access, patient burden, missed communication
Secondary useActive use cases by purpose and authority; overdue reviews; unverified benefitsPatient trust, equity impact, downstream-use breaches
Tracking technologiesApproved scripts and recipients; unknown endpoints; removal time; authenticated-page findingsDigital service performance and legitimate measurement needs
De-identificationReleases by method; expert determinations; linkage approvals; residual-risk reviewsAnalytic utility, re-identification attempts, recipient compliance
Equity and accessibilityPortal use, fulfillment, comprehension, and support by relevant populationsAvoid stigmatizing segmentation or inaccurate disparity inference
AccountabilityCompleted audits; control failures; corrective-action aging; contract exceptionsWorkforce burden, duplicated review, time to lawful access
Implementation instrument

Twenty-four months to verifiable control

Months 0-3 · SeeName accountability, inventory access and reuse pathways, and contain unidentified exposures.
Months 4-9 · GovernStandardize decision rights, exception records, proxy controls, use registers, and contracts.
Months 10-18 · EmbedConfigure identity, release rules, lineage, tracking governance, expiration, and equity measures.
Months 19-24 · ProveTest access, sample exceptions, reconcile recipients, verify benefit, and retire ended uses.
Implementation advances from visibility to governance, embedded controls, and independent proof.
§13

External Accountability, Incidents, and Independent Challenge

An effective program expects challenge. Privacy, compliance, internal audit, information security, research oversight, patient advocates, ethics, and legal counsel should be able to test whether the registered purpose matches actual use. Independence matters most when a high-revenue partner, strategic transaction, or public commitment creates pressure to approve.

Incident response should begin with containment but not end there. A tracking disclosure, proxy misuse, inappropriate download, failed access request, or unauthorized secondary use should be traced to the governing defect: unclear authority, excessive scope, identity failure, configuration drift, unmonitored vendor behavior, weak training, or missing closure. Corrective action should address the pathway, not only the individual event.

Patients need understandable notice and recourse. Access denials should identify the basis and any review rights. Delegation should be visible and revocable. Secondary-use transparency should describe meaningful categories and recipients rather than hide behind a generic privacy notice. Where notification is legally required, the hospital should meet the applicable rule and avoid language that minimizes uncertainty or harm.

Annual assurance should ask whether the hospital can prove five facts: lawful access is timely; exception use is bounded; external recipients are known; secondary uses remain within purpose; and corrective actions close. A presentation of policies is not proof.

§14

Strengths and Limitations

This review integrates recent peer-reviewed evidence with current primary United States legal authorities and translates them into an executive operating model. It distinguishes empirical findings from statements of law and emphasizes hospital decision rights, service design, and verification.

Several limitations apply. The literature is heterogeneous and includes cross-sectional surveys, observational studies, qualitative research, implementation reports, and systematic reviews with different settings and outcomes. Findings from single health systems may not generalize. Some secondary-use and de-identification research is technical or international, and this review did not use unvalidated technical proposals as evidence of effectiveness. Regulatory interpretation continues to evolve, including information-blocking implementation, health-data tracking guidance, reproductive-health privacy, Part 2 alignment, and state privacy law. The search was purposive rather than systematic, and no risk-of-bias instrument or pooled analysis was used. This article is not a comprehensive survey of state law and does not provide legal advice.

§15

Conclusions

Health-data governance fails when access and privacy are assigned to separate silos with no shared decision model. Patients experience the result as delay, confusion, hidden disclosure, or loss of control. Hospitals experience it as rework, regulatory exposure, vendor dependence, and strategic distrust.

The solution is not maximal release or maximal restriction. It is accountable movement. Patient access should operate as a reliable service. Information-blocking exceptions should be specific, bounded, documented, and reviewable. Proxy identity should be explicit. Secondary use should begin with purpose and authority. Tracking technologies should be inventoried as data flows. De-identification should be treated as managed residual risk. Interoperability should preserve meaning. Boards should receive proof of lawful access, controlled use, patient benefit, and corrective action.

Every disclosure needs purpose, authority, minimum scope, and proof. That covenant makes transparency and privacy mutually reinforcing rather than administratively opposed.

Acknowledgments

None.

Publication Statements

Reporting Checklist: This article is presented in accordance with a narrative review reporting checklist.

Funding: None.

Conflicts of Interest: The author has completed the ICMJE uniform disclosure form. The author is President and Chief Executive Officer of The Healthcare Executive. No other conflicts of interest are declared.

Ethical Statement: The author is accountable for all aspects of the work in ensuring that questions related to the accuracy or integrity of any part of the work are appropriately investigated and resolved. This narrative review did not involve human participants or animals; institutional review board approval and informed consent were not applicable.

Data Sharing Statement: No original datasets were generated or analyzed for this narrative review. The completed search strategy is reported in the manuscript and supplementary material.

Disclaimer: The views expressed are those of the author and are intended for executive education. This article does not constitute legal, regulatory, privacy, cybersecurity, reimbursement, accounting, investment, or clinical advice. Organizations should obtain advice specific to their facts and jurisdiction.

References

  1. Everson J, Healy D. Information-blocking trends following regulatory action. J Am Med Inform Assoc. 2025;32(4):665-674. doi:10.1093/jamia/ocaf007.
  2. Everson J, Patel V, Adler-Milstein J. Information blocking remains prevalent at the start of 21st Century Cures Act: results from a survey of health information exchange organizations. J Am Med Inform Assoc. 2021;28(4):727-732. doi:10.1093/jamia/ocaa323.
  3. Adler-Milstein J, Pfeifer E. Information blocking: is it occurring and what policy strategies can address it? Milbank Q. 2017;95(1):117-135. doi:10.1111/1468-0009.12247.
  4. Gellert GA, Erwich ME, Krivicky Herdman S. Challenges meeting 21st Century Cures Act patient identity interoperability and information blocking rules. J Healthc Qual. 2024;46(5):306-315. doi:10.1097/JHQ.0000000000000446.
  5. Wood KE, Pham HT, Carter KD, Nepple KG, Blum JM, Krasowski MD. Impact of a switch to immediate release on the patient viewing of diagnostic test results in an online portal at an academic medical center. J Pathol Inform. 2023;14:100323. doi:10.1016/j.jpi.2023.100323.
  6. Hamze MK, Joshi SS, Li Y, Repp AB, Jacobs A, McEntee R. The 21st Century Cures Act: inpatient clinician perceptions of changes to information sharing at an academic medical center. Cureus. 2023;15(6):e40184. doi:10.7759/cureus.40184.
  7. Sinha S, Bedgood M, Puttagunta R, et al. Variation in pediatric and adolescent electronic health data sharing practices under the 21st Century Cures Act. J Am Med Inform Assoc. 2023;30(12):2021-2027. doi:10.1093/jamia/ocad172.
  8. Simmons V, Boman T, Stewart SA. Impact of the 21st Century Cures Act on patients and the healthcare team. Clin J Oncol Nurs. 2024;28(1):21-25. doi:10.1188/24.CJON.21-25.
  9. Pollock JR, Petty SAB, Schmitz JJ, Varner J, Metcalfe AM, Tan N. Patient access of their radiology reports before and after implementation of 21st Century Cures Act information-blocking provisions at a large multicampus health system. AJR Am J Roentgenol. 2024;222(6):e2330343. doi:10.2214/AJR.23.30343.
  10. Polubriaginof FCG, Chimonas S, Lipitz-Snyderman A, et al. Does transparency promote engagement? Cancer patients’ access of electronic medical records before and after the information blocking rule. AMIA Annu Symp Proc. 2024;2024:900-909. PMID:40417461.
  11. Richwine C, Steitz B, Everson J. Patient-reported experiences with viewing and understanding test results in patient portals: cross-sectional survey analysis. J Med Internet Res. 2026;28:e94098. doi:10.2196/94098.
  12. Friedman AB, Merchant RM, Maley A, et al. Widespread third-party tracking on hospital websites poses privacy risks for patients and legal liability for hospitals. Health Aff (Millwood). 2023;42(4):508-515. doi:10.1377/hlthaff.2022.01205.
  13. Atasoy H, McDonough R, Zhang GM. Beyond the click: pixel tracking technologies and patient data security in hospitals. PNAS Nexus. 2025;4(12):pgaf360. doi:10.1093/pnasnexus/pgaf360.
  14. Salmi L, Peereboom D, Dorr DA, Graham LR, Wolff JL, DesRoches CM. Patient portals fail to collect structured information about who else is involved in a person’s care. J Med Internet Res. 2024;26:e49394. doi:10.2196/49394.
  15. Latulipe C, Mazumder SF, Wilson RKW, et al. Security and privacy risks associated with adult patient portal accounts in US hospitals. JAMA Intern Med. 2020;180(6):845-849. doi:10.1001/jamainternmed.2020.0515.
  16. Arvisais-Anhalt S, Lau M, Lehmann CU, et al. The 21st Century Cures Act and multiuser electronic health record access: potential pitfalls of information release. J Med Internet Res. 2022;24(2):e34085. doi:10.2196/34085.
  17. Xie J, Hogan A, McPherson T, Pageler N, Lee T, Carlson J. Creating a guardrail system to ensure appropriate activation of adolescent portal accounts. Appl Clin Inform. 2023;14(2):258-262. doi:10.1055/a-2015-0964.
  18. Goldstein RL, Mermelstein SJ, Sisk BA, Carlson JL. Provider perspectives on adolescent confidentiality and the electronic health record postimplementation of the 21st Century Cures Act final rule. J Adolesc Health. 2024;75(5):725-729. doi:10.1016/j.jadohealth.2023.11.006.
  19. Thomas KA, Bailey C. The 21st Century Cures Act: more harm than good for survivors of intimate partner violence? Violence Against Women. 2025;31(14):3780-3792. doi:10.1177/10778012241280053.
  20. Moll J, Myreteg G, Rexhepi H. Experiences of patients with mental health issues having web-based access to their records: national patient survey. JMIR Ment Health. 2024;11:e48008. doi:10.2196/48008.
  21. Hulter P, Langendoen W, Pluut B, et al. Patients’ choices regarding online access to laboratory, radiology and pathology test results on a hospital patient portal. PLoS One. 2023;18(2):e0280768. doi:10.1371/journal.pone.0280768.
  22. Norris EC, Halaska C, Sachs PB, Lin CT, Sanfilippo K, Honce JM. Understanding patient experiences, opinions, and actions taken after viewing their own radiology images online: web-based survey. JMIR Form Res. 2022;6(4):e29496. doi:10.2196/29496.
  23. Malin B, Benitez K, Masys D. Never too old for anonymity: a statistical standard for demographic data sharing via the HIPAA Privacy Rule. J Am Med Inform Assoc. 2011;18(1):3-10. doi:10.1136/jamia.2010.004622.
  24. El Emam K, Jonker E, Arbuckle L, Malin B. A systematic review of re-identification attacks on health data. PLoS One. 2011;6(12):e28071. doi:10.1371/journal.pone.0028071.
  25. Faustini P, McIver A, Sullivan R, Dras M. De-identification of clinical data: a systematic review of free text, image and tabular data approaches. Int J Med Inform. 2026;208:106225. doi:10.1016/j.ijmedinf.2025.106225.
  26. McMurry AJ, Gottlieb DI, Miller TA, et al. Cumulus: a federated electronic health record-based learning system powered by Fast Healthcare Interoperability Resources and artificial intelligence. J Am Med Inform Assoc. 2024;31(8):1638-1647. doi:10.1093/jamia/ocae130.
  27. Palojoki S, Lehtonen L, Vuokko R. Semantic interoperability of electronic health records: systematic review of alternative approaches for enhancing patient information availability. JMIR Med Inform. 2024;12:e53535. doi:10.2196/53535.
  28. Chen DW, Watanabe M, Xie S, Huston-Paterson HH, Banerjee M, Haymart MR. Language barriers and access to hospital patient portals in the US. JAMA Netw Open. 2025;8(10):e2537864. doi:10.1001/jamanetworkopen.2025.37864.
  29. Bain AP, Heslin R, Matthews L, et al. Patient portal use among admitted surgical patients following the 21st Century Cures Act. JAMA Surg. 2025;160(10):1082-1090. doi:10.1001/jamasurg.2025.2799.
  30. Turner K, Clary A, Hong YR, Alishahi Tabriz A, Shea CM. Patient portal barriers and group differences: cross-sectional national survey study. J Med Internet Res. 2020;22(9):e18870. doi:10.2196/18870.
  31. Busch-Casler J, Radic M. Trust and health information exchanges: qualitative analysis of the intent to share personal health information. J Med Internet Res. 2023;25:e41635. doi:10.2196/41635.
  32. Abdelhamid M. Greater patient health information control to improve the sustainability of health information exchanges. J Biomed Inform. 2018;83:150-158. doi:10.1016/j.jbi.2018.06.002.
  33. Standards for Privacy of Individually Identifiable Health Information, 45 CFR parts 160 and 164. Electronic Code of Federal Regulations. Accessed August 13, 2026. https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164
  34. HHS Office for Civil Rights. Individuals’ Right under HIPAA to Access their Health Information, 45 CFR § 164.524. Reviewed May 30, 2025. Accessed August 13, 2026. https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/access/index.html
  35. 42 U.S.C. § 300jj-52. Information blocking. Accessed August 13, 2026. https://www.govinfo.gov/link/uscode/42/300jj-52
  36. Information Blocking, 45 CFR part 171. Electronic Code of Federal Regulations. Accessed August 13, 2026. https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-D/part-171
  37. HHS Office for Civil Rights. Minimum Necessary Requirement. 45 CFR §§ 164.502(b), 164.514(d). Accessed August 13, 2026. https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/minimum-necessary-requirement/index.html
  38. 21st Century Cures Act: Establishment of Disincentives for Health Care Providers That Have Committed Information Blocking. 89 Fed Reg 54662. July 1, 2024. https://www.federalregister.gov/documents/2024/07/01/2024-13787/21st-century-cures-act-establishment-of-disincentives-for-health-care-providers-that-have-committed
  39. HHS Office of Inspector General. Information Blocking. Updated May 27, 2026. Accessed August 13, 2026. https://oig.hhs.gov/reports/featured/information-blocking/
  40. HHS Office for Civil Rights. Use of Online Tracking Technologies by HIPAA Covered Entities and Business Associates. Accessed August 13, 2026. https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/hipaa-online-tracking/index.html
  41. Confidentiality of Substance Use Disorder Patient Records, 42 CFR part 2. Electronic Code of Federal Regulations. Accessed August 13, 2026. https://www.ecfr.gov/current/title-42/chapter-I/subchapter-A/part-2

Supplementary Table S1. Detailed search strategy

SourceConcepts and example termsLimitsVerification
PubMed/MEDLINE(information blocking OR Cures Act) AND (hospital OR patient access OR interoperability)English; January 2000-August 13, 2026PMID, title, journal, year, DOI checked against PubMed record
PubMed/MEDLINE(patient portal OR online record access) AND (test results OR proxy OR caregiver OR adolescent OR confidentiality OR equity)English; January 2000-August 13, 2026Abstract reviewed for hospital governance relevance
PubMed/MEDLINE(hospital website OR mobile application) AND (tracking pixel OR third-party tracking OR privacy)English; January 2000-August 13, 2026Empirical hospital studies prioritized
PubMed/MEDLINE(secondary use OR health information exchange OR learning health system) AND (consent OR trust OR governance OR interoperability)English; January 2000-August 13, 2026Technical proposals excluded as effectiveness evidence unless implemented
PubMed/MEDLINE(de-identification OR re-identification) AND (health data OR clinical data)English; January 2000-August 13, 2026Systematic reviews and applied health-data studies prioritized
Primary legal authorities42 U.S.C. 300jj-52; 45 CFR parts 160, 164, 171; 42 CFR part 2; information-blocking disincentives; OCR tracking guidanceCurrent through August 13, 2026 as available on official sitesOfficial U.S. Code, eCFR, Federal Register, and agency sources only
The Healthcare Executive

HCE-LAW-NR-02 · The Data Covenant
For executive education. This article is not legal, regulatory, privacy, cybersecurity, reimbursement, accounting, investment, or clinical advice.

Leave us a Comment