up:: What’s At Risk
Are my medical records safe?
They’re one of the two categories that matter most, and the reason is time rather than technology.
A stolen credit card is inconvenient for a week. Your diagnoses, prescriptions, therapy notes, and reproductive history stay true for the rest of your life, and they stay consequential for insurance, employment, custody, and how people treat you. Nothing about them expires.
That combination, permanently sensitive and held by institutions on your behalf, is exactly what makes them worth collecting today.
The short version:
- Health information stays sensitive for life, which puts it near the top of the list.
- U.S. rules require certain health documentation be retained for 6 years, and the clinical facts stay relevant far longer than that.
- Your health apps and fertility trackers rebuild much of the same picture from outside the medical system.
- Medical devices are the hardest case, because encryption inside a pacemaker can’t be updated the way a phone can.
- You can ask your provider what their timeline is, and it’s a fair question with a real answer.
Why are health records so exposed?
Because of what stays true about them.
Diagnoses, prescriptions, therapy and psychiatric treatment, reproductive-health decisions, addiction treatment, and disability records don’t stop being accurate. Someone reading them in 2040 learns the same facts they’d learn today, and those facts still affect insurance, employment, custody disputes, immigration proceedings, and how a person is treated by people who find out.
There’s a retention floor underneath it too. U.S. health-privacy rules require certain documentation be kept for 6 years, and clinical relevance runs far past any retention minimum, because your medical history is a permanent part of your care.
Source: 45 CFR § 164.316(b)(2)(i), documentation retention requirement, ecfr.gov.
What about my health apps and my fertility tracker?
They matter more than most people assume, because they reconstruct the medical record from outside the medical system.
Heart rate, sleep, cycle and fertility tracking, weight, and workout locations sync continuously over everyday connections. Taken together, that data reveals pregnancy, pregnancy loss, chronic illness, mental-health patterns, and substance use, without any of it ever passing through a doctor’s office.
Fertility tracking deserves specific mention. It records information a person may urgently need private later, and depending on where they live, that need can arrive suddenly and for reasons entirely outside their control.
Health apps also generally sit outside health-privacy law, so the protections covering your doctor’s files often don’t cover the app on your wrist.
What are hospitals and insurers actually doing?
The picture is uneven, and the honest summary is that most large health organizations are at the beginning rather than the middle.
The first task in fixing any of this is producing a list of everywhere cryptography is used across their systems. Health systems are among the hardest places to do that, because they run decades of accumulated software, equipment from dozens of vendors, and devices that were installed once and never touched again.
A large share of what they’d need to change also sits inside purchased products, which means their timeline depends on manufacturers rather than on their own budget.
None of that is an excuse, and it is the actual reason for the pace.
What about pacemakers and insulin pumps?
That’s the hardest category in this entire subject, and it gets its own page: Is my pacemaker safe?
The short version is that a device implanted in a body for a decade or more carries encryption fixed at manufacture, where updating it is a medical procedure rather than a download. The FDA’s 2023 premarket cybersecurity guidance is the regulatory anchor for new devices, and it does nothing for the ones already implanted.
Source: FDA, “Cybersecurity in Medical Devices: Quality System Considerations and Content of Premarket Submissions,” final guidance, 27 September 2023, fda.gov.
How long does health information stay sensitive?
| What it is | Stays sensitive for | Why |
|---|---|---|
| Diagnoses and treatment history | A lifetime | The clinical facts stay true and keep affecting insurance and employment |
| Mental-health and therapy records | A lifetime | Stigma and disclosure consequences don’t expire |
| Reproductive and fertility history | A lifetime, and context-dependent | Legal exposure can change with where you live |
| Addiction treatment | A lifetime | Employment and custody consequences persist |
| Health-app and wearable data | As long as the account exists | Reconstructs the record above from outside the clinic |
| Retained documentation | 6 years minimum under U.S. rules | 45 CFR § 164.316(b)(2)(i) |
What can I reasonably do?
Less than you’d like about records already held, and more than nothing.
- Ask your provider what their timeline is. Hospitals, insurers, and health systems all have someone responsible for this. A patient asking is legitimate, and there’s a template for it.
- Check whether your health apps sit outside health-privacy law, because many do, and their data reconstructs the same picture.
- Delete health-app history you’re finished with, particularly cycle and fertility data if that’s a concern where you live.
- Keep your devices updated, which protects what you send from now on.
- Be selective about new health apps, since each one is another copy of the same sensitive picture crossing another network.
What you can’t do is retract records already sent. That’s genuinely outside your control, and it’s why the accountability sits with the institutions.
Questions people ask
Is my doctor’s office actually at risk? The risk is to information in transit between systems, which is constant in healthcare: labs, referrals, imaging, insurance claims, and portals all move data between organizations.
Does HIPAA protect me here? It governs how your data is handled and disclosed, and it doesn’t stop someone copying scrambled traffic off a network. Those are different problems with different remedies.
Should I stop using a fertility app? That’s a personal call about a real tradeoff. If you use one, know it sits outside most health-privacy protection, and clear out history once it’s served its purpose.
What about genetic testing my doctor ordered? Clinical genetic testing is generally covered by health-privacy rules that consumer kits aren’t, and the permanence is identical. See Is my DNA data safe?
Will I be told if my records are exposed this way? No. See Will anyone ever tell me if it happens?
Where to go next
- Is my pacemaker safe? covers implanted devices.
- Is my DNA data safe? covers the other permanent category.
- What should my doctor and my bank be doing? is the standard to hold them to.
Go deeper into the technical detail
The technical catalog is What Data Is Vulnerable to Harvest Now, Decrypt Later, and the device side is PQC in Medical Devices.
These open the Post-Quantum Field Guide, a separate site written for security professionals.
Last verified 2026-07-30 · Maintained by Addie LaMarr, LaMarr Labs.