HIPAA protects hospitals and clinics, not the health information itself, according to a new policy report published by the Texas Public Policy Foundation. The moment a patient's medical data crosses from a covered healthcare provider into a consumer app, wearable device, or data broker's hands, federal privacy protection ends—and Texas law doesn't pick up where HIPAA leaves off. The report argues that the state has repeatedly affirmed patients' right to access their own clinical records, yet surrenders control over a far larger universe of health data the instant it enters the commercial marketplace.
Only about three in ten U.S. adults actually accessed their health records online during 2017–2018, the report notes, even though roughly 54% were offered access and 57% of those offered it attempted to use it. Two-thirds of Americans say they understand little to nothing about what companies do with their personal data, up from 59% in 2019, and 73% report having little to no control over how businesses use the information they collect. The Federal Trade Commission found that prescription-discount service GoodRx shared users' medications and health conditions with Facebook, Google, and other advertisers, while data broker X-Mode was barred from selling precise location data revealing visits to medical and reproductive health clinics. When genetic-testing company 23andMe filed for Chapter 11 bankruptcy in March 2025, the genetic profiles of more than 15 million customers became a salable asset in the proceeding.
The report identifies what it calls the "HIPAA handoff"—the structural boundary where health information passes from institutions regulated under federal law into an unregulated commercial sphere populated by apps, vendors, and brokers that neither HIPAA nor the Texas Data Privacy and Security Act effectively governs. Texas's own medical-records privacy statute defines "covered entity" far more broadly than federal law, reaching any person who assembles, collects, or transmits protected health information for commercial gain, yet the authors write that this expansive definition "remains largely unrealized as an instrument against the downstream data trade." The state's 2023 Digital Bill of Rights, which grants Texans the power to know, correct, delete, and port their personal data, expressly exempts HIPAA-covered entities and protected health information—creating a gap precisely where health data now travels.
The foundation's analysis traces the problem to a single structural defect: protection in this domain attaches to the institution, not the information. Once a diagnosis, genetic test result, or fitness tracker reading exits a provider's system, consent rules and access safeguards lapse, even though the data remains just as sensitive and personally identifiable. The report documents how routine industry practices—sweeping terms-of-service agreements accepted with a single tap, business-to-business contracts invisible to the consumer, and "dark pattern" interface designs that steer users toward disclosure—allow health information to be transferred, aggregated, and sold without meaningful individual consent. That hidden movement carries real harm: aggregated data can be used to set insurance premiums, inform employment and housing decisions, and target individuals at vulnerable moments, such as managing addiction or seeking reproductive care, and unlike a compromised password, a genetic profile or diagnosis is permanent and implicates relatives who never consented to its collection.
The report recommends five targeted reforms, each building on legal instruments Texas already possesses. It calls on the state to strengthen patient portability by making federal information-blocking rules actionable under Texas law, imposing a 15-business-day response deadline, prohibiting fees for electronic transmission, and requiring records be delivered in standardized, machine-readable formats such as HL7 FHIR and the U.S. Core Data for Interoperability standard. It urges Texas to require affirmative, revocable patient consent before any resale or secondary use of identifiable health data, with that consent obligation traveling downstream to each subsequent recipient. The authors propose mandating tamper-evident audit logs and role-based access controls so patients can see who has touched their records, securing default parental access to minors' records through patient portals while automatically withholding segments tied to care a minor may consent to independently, and—most fundamentally—closing the coverage gap by anchoring all these duties to the broader "covered entity" definition already enacted in Texas's own medical-records statute nearly two decades ago. The bottom line, the report concludes, is that protection should follow the data, not the institution that first collected it.

