Health data privacy

Protecting our members’ personal health information

Health data privacy

Protecting our members’ personal health information


Providing high-quality care requires accessible and accurate personal health information. Kaiser Permanente pioneered comprehensive electronic health records, beginning in the 1960s. Today, these records enable us to integrate care delivery across our entire organization and keep our members healthy.

Highly connected, digital systems (like electronic health record systems) pose potential privacy challenges for any organization. Threats to privacy can happen when people provide information to third parties for one purpose, such as a health-focused app, but find it used inappropriately for an unintended purpose.

Underpinning Kaiser Permanente’s electronic health record systems are internal policies and protocols that reflect a robust, consistent, transparent data privacy approach. We use a comprehensive approach to data security to enable strong privacy protections. We advocate for policies that support the secure use of patient information for the intended purpose of delivering high-quality health care.

92%

of Americans view privacy as a right and oppose the sale of their health1

75%

of Americans are concerned about their health data privacy2

20%

of Americans know who can access their health data3

Kaiser Permanente believes sound public policies relating to health data privacy must:

  • Protect individual privacy rights and support high-quality care delivery at the same time
  • Enable clear and open communication with members, patients, providers, and customers about data and privacy
  • Require holders of personal data to communicate policies and processes for collecting, using, sharing, storing, archiving, and protecting health information
  • Promote data governance models that establish and follow: clear policies and processes for storing, archiving, backing up, and protecting personal health information; standards and procedures that define personal health information use by authorized personnel; and controls and audit procedures that ensure ongoing compliance with laws and regulations
  • Align federal, state, and local laws and regulations to ensure providers can access the health information necessary for high-quality care delivery while also protecting individual privacy rights

Kaiser Permanente advocates for policies that:  

  • Ensure patient records are accurate, complete, and reliable
  • Promote individual privacy rights while ensuring health providers have the information they need to advance high-quality care
  • Meet consumers’ expectations for accessing and sharing data while also ensuring that consumers have information about benefits and risks
  • Harmonize national, state, and local health information privacy and security laws and regulations 

 

1 AMA, 2022.
2 AMA, 2022.
3 AMA, 2022.