by Twila Brase, RN, PHN, President and Co-founder of Citizens’ Council for Health Freedom
Our previous article, “AI Has Entered Your Doctor’s Office — and It’s Recording,” examined how ambient listening tools are turning private exam room conversations into digital records, often without your permission.
This second article follows the record after the visit, showing how patient data can be sold, fed into AI systems, used in coverage decisions, and exposed through the government-mandated electronic health record infrastructure.
Once AI turns a doctor’s visit into data, the health care system can move, sell, analyze, and use that record long after the appointment ends.
Your Patient Records Are Being Sold
AI scribes are one data pipeline into the health AI industry. They are not the only ones.
Patient records are already feeding commercial AI development. The Mayo Clinic transferred de-identified patient data to 16 companies over two years for commercial development of health AI products. Truveta launched a project to pair genetic data from up to 10 million consented with existing health records. Other companies buy de-identified patient records from hospitals and resell them to AI developers and researchers.
The Health Insurance Portability and Accountability Act (HIPAA) — the 1996 law that led to the 2003 federal “HIPAA rule,” which patients believe protects their privacy — is the legal mechanism that makes the sharing of your data possible. We have written extensively about HIPAA’s role as a permissive data-sharing rule, not a privacy law.
The U.S. Department of Health and Human Services (HHS) acknowledged in a 2010 rule that HIPAA permits 2.2 million entities to access patient data. It also allows patient data stripped of obvious identifiers to be sold without consent if those who hold your data choose to sell it. HHS has acknowledged that so-called “de-identified” data could be re-identified.
In 2009, Congress used the HITECH Act to push electronic health record (EHR) adoption across hospitals and clinics through federal incentives and penalties tied to “meaningful use.” These networked systems collect, store, and transmit patient data electronically. They then extended that network further through creation of the eHealth Exchange data system and nationwide interoperability requirements, including the Trusted Exchange Framework and Common Agreement (TEFCA).
AI now sits on top of this entire architecture — ingesting records that patients never agreed to share, at a scale no previous technology could achieve. That data doesn’t just move through the system – it is increasingly used to make decisions about your care.
AI Is Denying Your Care
Created by CCHF
The data flowing through EHRs does more than feed AI training sets and consumer health apps. Health insurers are feeding it into AI systems that are used to decide whether patients receive treatment at all.
Prior authorization is the process by which a health plan must approve a treatment, medication, or procedure before a patient can receive it. Health plans have begun to automate this gatekeeping function using AI. Physicians are already seeing the effects. Three out of five physicians — 61% — report concern that health plans’ use of AI is increasing prior authorization denials, producing systematic care refusals with little or no human review. AI tools have been accused of producing denial rates in some cases 16 times higher than typical.
The outcome data is striking. A January 2026 study in Health Affairs cited by Stanford researchers found 82% of appealed prior authorization denials in Medicare Advantage plans are ultimately overturned in the patient’s favor. This figure does not mean AI is identifying fraud or preventing unnecessary care —it means patients who have the time and determination to fight a denial win more than four out of five times. The catch is that barely 0.2% of denied prior authorization decisions are appealed, leaving most denials unchallenged.
Thus, health plans running AI systems across millions of prior authorization requests face almost no challenge to the denials generated by their technology—and reap all the financial benefits.
The AMA survey also found that more than one in four physicians claim prior authorization requirements have led to a serious adverse event for a patient — including hospitalization, permanent impairment, or death. More than 90 percent of physicians reported that prior authorization has a negative impact on patient clinical outcomes.
On January 1, 2026, the Centers for Medicare and Medicaid Services (CMS) expanded AI’s role to the care of senior citizens in Original Medicare. CMS launched the Wasteful and Inappropriate Service Reduction (WISeR) Model, introducing AI-assisted prior authorization for select services in six states — Arizona, New Jersey, Ohio, Oklahoma, Texas, and Washington — affecting nearly 1 in 5 Original Medicare beneficiaries nationwide. Patients have no way to know if AI drove the decision that denied their care. No obligation exists for Medicare or its AI contractors to disclose whether AI or algorithms were used in any coverage determination.
WISeR was a topic of focus in an April 22nd Senate Finance Committee Hearing. U.S. Senator Maria Cantwell (D-WA) released a report based on data from 16 hospitals in Washington state, which showed that patients are waiting two to four times longer for medically necessary procedures than they were before the release of the WISeR pilot program.
Sen. Cantwell also pointed out that the government is paying private companies that use AI to authorize or deny claims — and that these companies are paid a percentage of savings from each denial. She told U.S. Health and Human Services Secretary Robert F. Kennedy Jr. that “AI is being used as a denial device for the CMS system.” The data AI uses to make these determinations come from the Electronic Health Record — the government-mandated digital record system. Patients have not meaningfully consented to having their records be used this way.
The Vulnerabilities Caused by Digital Data
Every electronic health record (EHR) sitting inside every hospital, clinic, and health system in the United States runs on software. Software contains vulnerabilities. Until recently, finding and exploiting those vulnerabilities required rare skill and months of work. AI is making that process quicker and easier.
Anthropic — an AI company — revealed in early April 2026 that it had developed a new AI model called Claude Mythos. Testing showed it could identify software vulnerabilities at a speed and scale beyond what human security teams could match — identifying thousands of high-severity flaws in major operating systems and web browsers, including some that had gone undetected for decades. Anthropic decided the model was too dangerous for public release.
The concern is not limited to Claude Mythos. Anthropic’s own offensive cyber research team concluded that within six to twelve months, AI with comparable capability could be broadly distributed — including by actors outside the United States. The direction is clear; the time requirements and specialized skills required to find and exploit software vulnerabilities are shrinking. What previously demanded rare technical expertise will soon demand far less.
Health care is among the most exposed sectors. The Chief Security Officer of the Health Information Sharing and Analysis Center said AI tools of this class could shrink the window for a cyberattack from months or days down to hours and minutes. A successful attack on a hospital’s EHR system does not only expose patient and financial data; it can shut down the entire facility, leaving doctors in the dark and patients in dire straits.
This is the reality. An interconnected, government-mandated, digital health record infrastructure, networked across institutions, accessible to thousands of entities, now feeding AI systems for documentation, research, data sales, and care denials — faces a cybersecurity environment where the cost of an attack is falling and the scale of exposure grows with every new connection point.
AI did not create this digital health record infrastructure. Congress and federal agencies did, first by pushing electronic health record adoption across hospitals and clinics, then by expanding nationwide interoperability requirements that move patient records across institutions. AI is now being layered onto that system, using the data it collects, stores and exchanges.
Patients who want to escape this vulnerable system can find direct-pay, independent physicians at JoinTheWedge.com (click on video below). They can also do internet searches for “direct primary care (DPC),” or “cash-based doctor,” or “private practice.” Practices operating independently (outside corporate health systems, outside corporate EHR networks and outside state, national, and corporate health information exchanges (HIEs) have a much smaller data footprint. What is said in the exam room is more likely to stay there.
This exploitative system was built without your consent — and those who built it, and are profiting from it, have no intention of asking for your consent now.
To protect themselves better, patients can ask direct questions: Is a device going to record our conversation? Is my record shared through a health information exchange? Can my data be sold or used for AI development? Does this practice use AI in documentation, billing, prior authorization, or care decisions?
Patients were never asked as this system was built around them. They should start asking now.
No posts

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.