When you are treated abroad, your medical records are created, stored, and sometimes transferred under the data-protection law of another country. The strong rights you may be used to at home do not automatically follow your data across borders. This guide sets out what the UK Information Commissioner's Office (ICO) and the US Department of Health and Human Services (HHS) state about records rights — and where those rights stop. It is informational only, not legal advice.
UK and EU: the right to get a copy
In the UK, you have a right of access — often called a subject access request (SAR) — to your personal information, which includes health records. The ICO states: "You have the right to ask an organisation if they're using or storing your personal information. You can also ask them for copies of your personal information." Two practical features matter: "Organisations usually have one month to respond to a SAR", and "Anyone can make a SAR. You don't need a solicitor or a lawyer." If an organisation does not respond, or you are unhappy with how it handled your request, the ICO sets out how to raise a concern and, ultimately, to complain to it.
This right applies to organisations covered by UK data-protection law. For treatment inside the EU, the cross-border healthcare Directive 2011/24/EU separately entitles patients to "a written or electronic medical record of such treatment, and access to at least a copy" (Article 4) — a useful backstop when you have been treated in another EU country.
United States: HIPAA's right of access, and its limits
In the United States, the HIPAA Privacy Rule gives individuals a right to access their health information. HHS guidance on 45 CFR 164.524 states that a covered entity "must provide access to the PHI requested, in whole, or in part, no later than 30 calendar days from receiving the individual's request", and may extend this "by no more than an additional 30 days" where it cannot meet the first deadline. The right covers "a broad array of health information", including — in the HHS guidance's own list — medical records, billing and payment records, insurance information, clinical laboratory test results, medical images such as X-rays, and clinical case notes.
The crucial limit is who is bound. HIPAA applies to "covered entities" (and their business associates) as defined under US law — chiefly US health providers, health plans and healthcare clearinghouses. A clinic in another country is generally not a HIPAA covered entity, so HIPAA does not give you a right to demand records from it. Your rights there depend on local law.
Sending records across a border is itself regulated
Moving records between countries is not automatically allowed. Under UK GDPR, sending personal data outside the UK is a "restricted transfer" that needs a transfer mechanism — adequacy, appropriate safeguards, or an exception. The ICO states that "every restricted transfer must be covered by one of the following transfer mechanisms: UK adequacy regulations; appropriate safeguards; or an exception", and that "if you initiate a restricted transfer, you're responsible for complying with the transfer rules." So when a UK clinic sends your records to an overseas provider, there are rules about how that must be done, and the sender carries the responsibility. The ICO's "appropriate safeguards" category is not a formality but a set of documented mechanisms the sender must put in place, such as the International Data Transfer Agreement (IDTA), the International Data Transfer Addendum (the Addendum), and UK binding corporate rules.
The gap for medical tourists
Put the pieces together and the position is this: HIPAA binds US providers; UK GDPR binds organisations processing data under UK law; but a clinic in a third country may be bound by neither. The protection you actually have over records created at an overseas clinic is whatever that country's own data-protection law provides — which may be stronger, weaker, or simply different. Enforcing it can mean dealing with a foreign regulator, possibly in another language.
The practical defence is the same one clinicians recommend for safety reasons: get a complete copy of your records before you leave the clinic, in a language you can use, and keep it. The CDC advises medical tourists to "request copies of their overseas medical records in English" — advice that doubles as good data-protection practice, because a copy already in your hands does not depend on any later cross-border request. For the same reason, it is worth reading a clinic's own records and privacy policy before you book: that policy is often the clearest statement you will get of how the clinic says it will hold, share and transfer your information, and it tells you whom to ask if you later need a copy or a correction.
How to verify / where to go
- United Kingdom: the ICO (ico.org.uk) — how to make a subject access request, the one-month time limit, and how to complain if an organisation does not comply. - United States: the HHS Office for Civil Rights (hhs.gov) — the HIPAA right of access under 45 CFR 164.524, including the 30-day timeframe and fee rules. - Treatment inside the EU: your right to a copy of your record under Directive 2011/24/EU, Article 4, and the data-protection authority of the country of treatment. - Any other country: the national data-protection authority where the clinic is located, and the clinic's own records and privacy policy — ask in writing before you travel.
Confirm your rights with the authority for the country whose law actually applies. Do not assume that HIPAA or UK GDPR protects data held by a clinic abroad.