NearSeal

2026-08-30

Your medical records are finally yours to download. Should you encrypt the copy you keep?

Two things are true about medical records in 2026, and they pull in opposite directions. The copy of your health data that lives inside the system just suffered the largest medical data breach in history — one you could do nothing about. And the copy you hold is larger than any generation of patients has ever held: downloaded lab results, visit summaries exported from patient portals, imaging discs ripped to a folder, PDFs emailed to specialists. Federal policy spent a decade making that second copy easy to get, on the sound principle that your records belong to you. What the policy conversation talks about much less is that the protections regulating the first copy stop at exactly the point where the second one begins. Once a record is in your Downloads folder, there is no HIPAA, no security rule, no breach-notification duty — just a file, as protected or as naked as you choose to make it. This post is about that second copy: what the law honestly does and doesn't cover, and what encrypting the files you hold actually changes.

The breach you couldn't do anything about

In February 2024, ransomware operators got into Change Healthcare — a UnitedHealth-owned clearinghouse that routes claims, billing, and eligibility checks between a huge share of American providers and insurers — using stolen credentials on a system that, as the parent company's CEO later told Congress, lacked multi-factor authentication. TechCrunch's timeline of the attack traces what followed: months of nationwide disruption to pharmacies and billing, a ransom paid, and a stolen trove that included names, Social Security numbers, diagnoses, medications, and test results. The affected-person count climbed for over a year as the company worked out what was taken — 100 million in October 2024, then 190 million. The final figure, reported to federal regulators in July 2025 and published in HHS's own FAQ on the incident, is approximately 192.7 million people — more than half the population of the United States. Sit with the mechanics of that for a second: nobody's data got there because they downloaded something carelessly or emailed the wrong attachment. It flowed there automatically, claim by claim, because that's how the billing system works. No personal security habit — encryption included — had any reach into that building. That's worth stating plainly at the top of a post about encryption, because it marks the boundary of what any tool in your hands can do.

Meanwhile, the copy in your hands keeps growing

What your habits do reach is the other copy — and it's no longer a niche thing. Federal survey data from ONC (the office that tracks health IT adoption) found that 65% of Americans accessed their online medical records or patient portal in 2024, and its 2022 brief found that among portal users, about one in three downloaded their records to their own device and one in five transmitted them electronically to a third party. Those downloads have good reasons: a new specialist wants your history before the first visit, an insurance or disability claim needs documentation, you're managing an aging parent's care across three providers, or you simply want your own archive after a decade of switching doctors. Each of those reasons produces the same artifact — a file on a personal laptop, and often a copy in a sent folder — holding the most intimate category of information most people possess. Unlike a leaked password, a diagnosis history can't be rotated after a breach.

Your copy is the copy no law covers

Here's the part that surprises people: HIPAA regulates providers, insurers, clearinghouses, and their contractors. It does not regulate you, and it stops following your records the moment they reach you. This isn't an obscure loophole — it's written into the government's own guidance. HHS's right-of-access guidance says a provider must honor your request to receive your records by ordinary unencrypted email if that's what you ask for — they're required to warn you once about the risk, and then required to comply. And HHS's FAQ on health apps and APIs spells out that once your records flow, at your direction, to an app you chose, the provider bears no further HIPAA responsibility for them — and if the app maker isn't working for a covered entity, the app itself isn't subject to HIPAA at all. Both rules are deliberate and, on their own terms, correct: they exist so that institutions can't use "security" as an excuse to gatekeep your own records away from you. But the design has a clear consequence that the portal's download button never mentions: the system's copy of your chart sits behind a federal security rule, and your copy sits behind whatever you personally put in front of it.

Two copies of the same records, two different worlds The system's copy — HIPAA applies Providers, insurers, clearinghouses, their contractors — regulated, audited, and breached anyway: 192.7M people Out of your reach: no habit of yours, encryption included, protects the copies inside these institutions Your copy — no law covers it Portal downloads, PDFs emailed to a new doctor, a parent's records you manage, years of results in a folder Fully in your reach: encryption here is the one protection that exists, because you are the one who applies it
HIPAA regulates the institutions that hold your records — and the largest medical breach in history happened inside that regulated world anyway. The copy you download is covered by no rule at all, which makes it both your biggest exposure and the one place your own protection actually works.

What encrypting your copy actually changes

So take the copy you control and walk through where it travels. The commonest trip is to a new provider: a specialist's front desk says "email us your records," healthcare being one of the last industries where plain email and even fax are routine, and your entire history rides one attachment. Encrypt the file first and read the passphrase over the phone — you're calling the office anyway — and every mailbox that thread touches, including your own sent folder forever after, holds ciphertext instead of your chart. Misaddressed email, a compromised account next year, an office that forwards your message around: all of them now leak an unreadable blob. The second trip is no trip at all: the archive that just sits there. The folder of lab results, visit notes, and imaging reports accumulating on a laptop is exactly what a stolen, repaired, or resold machine hands to a stranger, and an encrypted archive is the version of that folder that's safe to keep for decades. The third is shared care: if you manage records for a parent or a child, an encrypted file on a USB stick or in a shared drive means the family's medical history isn't readable by whoever ends up holding the hardware or the account. In each case the mechanic is the same one HHS's unencrypted-email warning gestures at: the risk is every hop and resting place between you and the intended reader, and file-level encryption is how you cover all of them at once without asking any institution's permission.

What it honestly can't do

The limits, stated as plainly as the benefits. First, everything in the Change Healthcare section stands: encrypting your personal copies does nothing for the records that providers, insurers, and clearinghouses hold about you — your data was in that breach, or wasn't, regardless of whether you ever clicked a download button. Anyone who tells you a personal tool protects you from institutional breaches is selling something. Second, encryption only works where ciphertext is acceptable. A portal upload form, an insurer's claims site, or a records-request system needs readable files; encryption protects storage and transport on your side of those systems, not your interactions with them. Third, medical records have an emergency-access wrinkle most files don't: a document you might want an ER or a family member to reach quickly is a bad candidate for a passphrase only you know. If you encrypt records someone else may someday need, the passphrase has to live somewhere they can get it — a password manager's emergency access, or a note in whatever arrangement your family already trusts. And the standing rule applies with full force: there is no recovery. A forgotten passphrase doesn't mean a support ticket; it means the file is gone for good.

Where NearSeal fits

There would be something absurd about protecting your medical records with a tool that asks you to upload them to its server first. NearSeal doesn't: encryption runs entirely in your browser, the file and passphrase never leave your device, there's no account, and you can watch the network tab confirm nothing is transmitted. The format is AES-256-GCM with a key derived from your passphrase via PBKDF2-SHA256 at 220 iterations, and on decrypt a file is recognized by its bytes, not its name — so the office manager at your new specialist just opens the same website, drops the file in, and types what you read them over the phone. Nothing to install matters doubly in healthcare, where you can't ask a clinic to adopt software but can ask one person to open a web page. For the archive meant to last — the record set you'll still want in twenty years — consider the opt-in age-encryption.org format: age files open in the official age CLI, rage, and any other age-compatible tool, so an archive that should outlive any one website isn't tied to this one. The trade-offs stay what they are: NearSeal can't shorten the breach-notification list at any clearinghouse, and it will never recover a passphrase you lose. What it changes is exactly the thing the law leaves entirely to you — that the one copy of your medical history you actually control stops being the most exposed copy in existence.

Sponsored
← NearSeal

This page shows ads only if you consent.