Who's Keeping an Eye on Your Online Health Records?

Google, Microsoft and other providers of Web-based services for managing health care information promise to keep it secure, but privacy policies vary from site to site

Join Our Community of Science Lovers!


On supporting science journalism

If you're enjoying this article, consider supporting our award-winning journalism by subscribing. By purchasing a subscription you are helping to ensure the future of impactful stories about the discoveries and ideas shaping our world today.


The push toward electronic medical records has made storing personal health information in a locked filing cabinet in your doctor's office an outmoded guarantee of confidentiality. Today, patients can gather their jumbled health information—hospital visits, drug prescriptions and health insurance plans—and manage them through a number of different online services, including Google Health, Microsoft's HealthVaultand AOL co-founder Steve Case's Revolution Health.

Privacy advocates, however, point out that even though these companies are storing sensitive medical information, they are not bound by the strict data sharing and protection laws that govern the health care industry. The 1996 Health Insurance Portability and Accountability Act (HIPAA) regulates how health care entities, such as insurance companies and hospitals, exchange an individual's health information, but the law does not apply to personal health record storage services, according to the U.S. Department of Health and Human Services.

Because there are no laws that directly protect a user's online health information, all of the vendors who sell weight scales and/or blood glucose and pressure monitors that can send data directly to services like HealthVault set their own privacy policies, which means some will be weaker than others. "There isn't anyone to regulate the security and privacy of the personal health information records," says Deven McGraw, director of the Health Privacy Project at the Center for Democracy and Technology, a nonprofit Washington, D.C.–based public advocacy group that focuses on the impact of technology on individual rights. "It is not a very good landscape for consumers in regards to very sensitive health information."

It’s Time to Stand Up for Science

If you enjoyed this article, I’d like to ask for your support. Scientific American has served as an advocate for science and industry for 180 years, and right now may be the most critical moment in that two-century history.

I’ve been a Scientific American subscriber since I was 12 years old, and it helped shape the way I look at the world. SciAm always educates and delights me, and inspires a sense of awe for our vast, beautiful universe. I hope it does that for you, too.

If you subscribe to Scientific American, you help ensure that our coverage is centered on meaningful research and discovery; that we have the resources to report on the decisions that threaten labs across the U.S.; and that we support both budding and working scientists at a time when the value of science itself too often goes unrecognized.

In return, you get essential news, captivating podcasts, brilliant infographics, can't-miss newsletters, must-watch videos, challenging games, and the science world's best writing and reporting. You can even gift someone a subscription.

There has never been a more important time for us to stand up and show why science matters. I hope you’ll support us in that mission.

Thank you,

David M. Ewalt, Editor in Chief, Scientific American

Subscribe