Patient Privacy Rights

About HIPAA Summit Media Contact DONATE

Report Card for: Personal Health Records (PHRs)

Offered by Employers and/or Insurers

Grade = F

Using an employer’s or insurer’s PHRs means sharing personal health information with that employer or insurance company. You aren't guaranteed any control over your private information. Sharing this information puts your employment, insurability, and credit at risk.

Employer and insurer PHRs offer enticing health quizzes that gather and share much more information than you would typically provide including alcohol and drug use, sexual history, eating and exercise habits. Often employers and insurers offer incentives for you to fill out surveys, health assessments, or participate in disease management programs. Employers and insurers can directly access your PHR, enabling them to gather MORE information about your health.

We cannot officially grade PHRs offered by any employers or insurers because access is limited to employees and enrollees. However, we did obtain copies of the form privacy policies for two employer or insurer-based PHRs. Very clearly, they control the use and disclosure of your health information, not you. Here is a sample of what we found in the policies:

Keep in mind that your personal health information can be used broadly under HIPAA without your consent (See FAQ).

View this page as a PDF