Senator Ron Wyden has called on major electronic health record (EHR) vendors to implement stronger privacy controls that give patients greater authority over how their health information is shared and accessed. This initiative comes as the Department of Health and Human Services (HHS) intensifies enforcement of regulations promoting interoperability and secure data exchange, including the 21st Century Cures Act's information blocking rule. Wyden emphasized the need to balance improved data-sharing for care coordination with robust privacy protections, contacting ten leading EHR vendors to advocate for product features that empower patient privacy.
The senator's push highlights growing national security and privacy concerns as health data becomes increasingly accessible across digital platforms. Federal regulators are focusing on ensuring that the benefits of interoperability do not come at the expense of sensitive patient information, urging vendors to prioritize privacy in their technology roadmaps. The move signals heightened scrutiny of EHR systems and a shift toward more patient-centric data governance in the healthcare sector.

See the reporting duties and controls this puts on the clock.
5 events from the most recent confirmed update back to the earliest known activity.
Epic, the largest U.S. EHR vendor, said it is building new MyChart capabilities that would let patients opt out of sharing, hide records, view access logs and confirm sharing preferences for sensitive care. The announcement came in response to the broader push for stronger patient-directed privacy controls.
Senator Ron Wyden contacted 10 major electronic health record vendors, including Epic, Oracle Health and Meditech, urging them to add features that give patients direct control over who can access their health data. He framed the issue as both a patient privacy and national security concern.
A Department of Defense investigation examined improper access to military health records, highlighting the privacy and national security risks associated with broad health data interoperability. The case was cited as an example of why stronger patient controls are needed.
The HHS Office for Civil Rights recently reached a settlement with Concentra concerning delayed access to patient records, continuing enforcement of HIPAA's right of patient access. The action underscored federal scrutiny of how healthcare organizations handle individuals' access to their own health data.
The Department of Health and Human Services increased enforcement of regulations tied to interoperability and secure patient data exchange, particularly the 21st Century Cures Act's information-blocking rule. This regulatory push forms the backdrop for later calls to strengthen patient privacy controls in EHR systems.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.