Medical records privacy

Is it safe to send your medical records to a clinic abroad?

You wouldn’t leave your passport on a park bench. Why are you sending your medical history through unencrypted email?

The short answer: yes, when the record stays encrypted under a key only you hold, and the doctor reads it without keeping a copy you have no say over.

Email, cloud links, USB sticks and clinic portals each leave a readable copy with someone else. That is fine for a single referral letter. For thirty years of history, it is worth knowing who ends up holding it.

Private Health Passport · · 7 minute read

Four ways records travel

Who can read it, once it leaves you.

Every way of sending a record answers two questions: who holds the key, and whether you can take it back.

  • Email

    Protected between mail servers when both providers support it, and readable on each server afterwards: your sent folder, the clinic's inbox, every forward.[S81]

    Who holds the key
    Your email provider, and the clinic's
    Can you take it back
    Once sent, it stays sent
  • A cloud link

    Google Drive encrypts files in transit and at rest with AES-256, and in a standard account Google manages the keys. A shared link opens for anyone who has it until you switch it off.[S80]

    Who holds the key
    The cloud provider
    Can you take it back
    The link, yes. A download, no
  • A USB stick or disc

    Offline, which is its strength. It is as private as whoever is holding it, and to read it the clinic loads the files onto one of its own computers.

    Who holds the key
    Whoever holds the stick
    Can you take it back
    The clinic keeps its copy
  • The clinic's portal

    Built for exactly this. The record then lives on the clinic's servers, for as long as the clinic keeps records, under the law of the clinic's country.

    Who holds the key
    The clinic
    Can you take it back
    Only by asking the clinic

A portal is the clinic’s filing cabinet. You are handing them a copy.

What the law covers

The law stays home. Your record travels.

HIPAA covers US health plans, clearinghouses and providers, and the businesses working on their behalf[S75]. A clinic in Istanbul or Bangkok answers to Turkish or Thai law. And when a US provider sends your records to an app you picked yourself, the provider carries no further responsibility for what that app does with them, breaches included[S74].

GDPR treats health data as a special category, and an organisation moving it out of the European Economic Area needs an adequacy decision for the destination country or other safeguards[S76]. South Korea holds one, confirmed again in July 2026[S77]. The European Commission publishes the full list, and it is short.

The protection that goes everywhere you go is the one on your own phone.

Your data, other projects

“Anonymised” is a weaker word than it sounds.

Health records are valuable beyond your own care, for research, product testing and training software. The usual safeguard is to strip out names. A 2019 study in Nature Communications estimated that 99.98% of Americans could be correctly re-identified in any dataset using 15 demographic attributes[S78].

In 2017 the UK’s data regulator found that a London hospital trust had given the records of around 1.6 million patients to Google DeepMind to test a clinical app, and that patients had been told too little about how their data would be used[S79]. Those were NHS records, held by the NHS, under UK data protection law.

A record that stays encrypted on your own phone sits outside every one of those datasets.

The 30-second privacy check

How private is the way you send them now?

Three questions about the channel you use today. You get a score and a line on what each answer means. It also has its own page to share.

01 How are you sending your records to the clinic?
02 Who holds the key that unlocks the file?
03 Can you take access back after the doctor has read it?
Answer all three and your result appears here, with what each answer means for who can read your records. Your answers stay in this page and go nowhere.

What safe looks like

Six things to look for in any way of sharing a record.

Hold any app, portal or service to these. Next to each, how Private Health Passport meets it.

01 Zero-knowledge architecture, AES-256
Your records are encrypted on your own phone with AES-256-GCM before anything can leave it. The key is derived from your passphrase through PBKDF2, one hundred thousand rounds. Zkomi holds no key and no copy, so Zkomi cannot read your files.
02 A key only you hold
The passphrase stays with you, and only the salt is kept, on your own device. There is no account and nothing on our servers to hand over.
03 Device-to-device sharing
In the consulting room, a sharing session runs directly between your phone and the doctor's, with a screen written for the clinician: current medication and recent results.
04 Self-destructing links
A link you send expires by itself. The family status link carries its contents in the part of the address that browsers keep off the network.
05 Offline access
The emergency card is encoded inside a QR code and reads on a paramedic's phone in aircraft mode. The in-room handshake works in a basement clinic with one bar.
06 Photo data extraction on the phone
Photograph a discharge letter or a prescription and the app extracts the text on the phone itself, in English, French, Spanish, Russian or German. The photo is read on your device and stays there.

One limit applies to every tool, ours included: what a doctor writes in their own notes becomes part of the clinic’s record. Share what the consultation needs, and keep the rest in your vault.

How the encryption works

For facilitators, doctors and clinics

Looking for a secure way to receive international patients’ records?

Private Health Passport gives your patients one encrypted record they carry themselves, and a private way to show it to you, so your team can focus on care.

Records that arrive organised
Patients bring their history, medications and recent results in one place, with a screen written for clinicians. Fewer email chains, PDFs and USB sticks to chase before the consultation.
The record stays with the patient
Records are encrypted on the patient's own phone under their own key, and Zkomi holds no copy. You see what the patient shares, in the room or through a link that expires by itself, and keep what you write into your own notes.
Patients who trust the process
Your patients decide what you see, which makes them readier to share it. Their emergency card reads offline from a QR code, in your waiting room or anywhere else.

Questions

Medical Data Privacy: Frequently Asked Questions

Can I safely send my medical records to a clinic in another country?

Yes, when the record stays encrypted under a key only you hold and the doctor reads it without keeping a copy you have no say over. Email, cloud links and clinic portals each leave a readable copy with someone else. Private Health Passport keeps your record encrypted on your own phone, hands it to a doctor device to device in the consulting room, and sends a link that expires by itself when the doctor is further away.

Is emailing medical records to a clinic in South Korea safe?

Email to Korea, or anywhere abroad, is protected between mail servers only when both providers support TLS, and it stays readable on each server afterwards: in your sent folder, the clinic's inbox and every forward. For a single letter that may be acceptable. For a full medical history, use a channel where you hold the key and the copy has an end date, such as a link that expires by itself.

Does Google Drive encrypt my medical records?

Yes, in transit and at rest, with AES-256. In a standard account Google manages the keys, so the files are readable to Google's systems. Client-side encryption, where you hold the key, is offered on certain business editions of Google Workspace and is unavailable to personal accounts.

Does HIPAA protect my records once a clinic abroad has them?

HIPAA covers US health plans, clearinghouses and providers, and the businesses working on their behalf. A clinic in another country answers to its own country's law. And once a US provider sends your records to an app you chose yourself, the provider is no longer responsible for what that app does with them.

Does GDPR protect my health data if it goes to a clinic outside the EU?

GDPR treats health data as a special category, and an organisation transferring it outside the European Economic Area needs an adequacy decision for the destination country or other safeguards. South Korea has an adequacy decision, confirmed again in July 2026. The European Commission publishes the full list. Whatever the paperwork, the clinic also answers to the law of its own country.

What is zero-knowledge encryption for medical records?

Encryption where the service holding or passing on your data has no key to read it. In Private Health Passport your vault is encrypted on your own phone with AES-256-GCM, under a key derived from a passphrase only you know. Nobody at Private Health Passport can open it.

What happens to my medical records after the consultation?

You can end what you shared. A link you send from Private Health Passport expires by itself. Anything a doctor writes into their own notes becomes part of the clinic's record, kept under the clinic's rules, so share what the consultation needs and keep the rest in your vault.

How can I share X-rays and MRIs securely with a foreign surgeon?

Ask the surgeon's team which format and channel they use for imaging, and send the scans through the channel with the shortest life. Keep the originals yourself. Private Health Passport keeps your scans encrypted on your phone with the rest of your record, and a link you send expires by itself.

How can a clinic receive medical records from international patients securely?

Ask patients to bring their records in an app that keeps them encrypted on their own phone and shows them to you in the consultation, in place of email or a USB stick. With Private Health Passport the patient shares device to device in the room, or sends a link that expires by itself, and the clinician sees current medication and recent results on one screen. Clinics, concierge doctors and facilitators can partner with Zkomi at privatehealthpassport.com/partners.

How do I move my medical records to a new doctor or clinic?

Ask your current provider for a copy: in the US and the EU that is your legal right. Keep that copy somewhere you control, then show the new doctor what they need at the first appointment. Private Health Passport keeps the copy encrypted on your phone and reads paper letters with the camera, on the phone itself.

Source transparency

Where this comes from.

Every legal and technical claim on this page links to its primary publisher: the US Department of Health and Human Services, the EU’s own legal texts, the UK Information Commissioner’s Office, Google’s documentation and a peer-reviewed study. The full list is in the reference list. This is general information, and a lawyer is the person to ask about your own case.

Private Health Passport is built by Zkomi. Zkomi leads ongoing research into continuity of care and zero-knowledge architecture in international medical data transfer, published as The Zero-Knowledge Architecture and Memory Without Custody.

Ask us privately