Proxy access means someone else — a spouse, an adult child, a caregiver — can see a patient’s health information through a patient portal. There are two very different ways this happens: a patient shares their own login, or a health system sets up a separate, authorized proxy account. The first is a workaround with no formal protections. The second is a documented arrangement covered by federal privacy rules. Before sharing any portal access, the questions below sort out which situation applies and what it means for privacy, consent, and control.
Sharing a Login Is Not the Same as Proxy Access
Handing someone a username and password is common, especially for an aging parent or a patient recovering from surgery. But it is not the same as formal proxy access. When credentials are shared, the health system has no record of who is actually viewing the account, no way to limit what that person can see, and no way to verify the arrangement was the patient’s real choice. Formal proxy access, set up directly with the provider or health system, creates a documented, verifiable connection instead.
The first question to ask is simple: is this account sharing, or is it a proxy relationship the provider’s office has verified and put on file?
What Federal Privacy Rules Actually Establish
The HIPAA Privacy Rule gives patients the right to access their own health records, and it extends that same right to a “personal representative” — generally someone who has authority under state law to make health care decisions for the patient, such as through a health care power of attorney, guardianship, or a parent acting for a minor child. A verified personal representative can request records, and can direct the provider to send those records to a third party, under the same rules that apply when a patient requests their own information.
Separately, federal privacy rules also allow a provider to share limited health information informally with a family member or friend who is involved in a patient’s care, even without a formal personal-representative designation, if the patient does not object. This is a narrower, more situational allowance and is not the same as ongoing portal access.
Providers are expected to verify the identity and authority of anyone requesting access on a patient’s behalf, whether that verification happens in writing or in person. In limited situations, a provider can deny access to a personal representative if a licensed health professional determines that access is reasonably likely to cause serious harm, and that denial can be reviewed.
What’s Established vs. What Depends on Your Situation
Federal rules set a floor, but they don’t answer everything. Here’s how to separate what’s consistently true from what varies:
- Established by federal rule: Patients have a right to access their own records, and a verified personal representative has that same right for the scope of their authority.
- Established by federal rule: Providers must verify who is requesting access before granting it.
- Depends on state law: Who legally counts as a personal representative — this is determined by state law, powers of attorney, and guardianship documents, not by HIPAA itself.
- Depends on the health system: How proxy accounts are set up, what forms are required, whether access is full or partial, and how long it lasts are decided by each provider’s or hospital system’s own portal policies.
- Not addressed by these federal rules: The specific mechanics of any one portal software — that’s a question for the provider’s office directly.
Questions to Ask Before Sharing or Requesting Portal Access
Organize the conversation with the provider’s office around these four areas:
Account access questions:
- Is this a shared login, or a separate proxy account the office can set up and track?
- Can the proxy account be limited to certain information, or does it show everything?
- Who can remove or change this access later, and how?
Consent questions:
- What paperwork or verification does the office require to confirm the patient agreed to this?
- Does the arrangement need to be renewed, or does it stay active indefinitely?
- If the patient’s condition or wishes change, how is access updated?
Privacy questions:
- Does the proxy account holder’s own portal activity get logged separately from the patient’s?
- Can the patient see a record of who has accessed their information and when?
- What happens to access if the caregiving relationship ends?
Record-sharing questions:
- Can the proxy account holder request that records be sent to another provider, or only view them?
- Is there a cost or fee tied to record requests made through the proxy account?
- Who does the office contact if there’s a dispute about what the proxy account should be able to see?
A Practical Checklist Before Sharing Access
- Confirm with the provider’s office whether proxy access is offered as a formal, documented option — don’t assume a shared login is the only path.
- Ask what identification or authorization document (power of attorney, guardianship paperwork, or the office’s own consent form) is required.
- Get in writing what the proxy account can and cannot do — view only, request records, message the care team, or all three.
- Set a plan for reviewing or ending the access, especially if it was set up for a temporary situation like a hospital stay or recovery period.
- Keep a note of which offices or health systems have proxy access set up, since portals are usually managed separately by each provider or hospital system rather than in one place.
Where to Get State-Specific Answers
Because personal-representative status depends on state law, questions about who legally qualifies — and what documentation proves it — should go to the provider’s office, a patient advocate, or a legal professional familiar with the relevant state’s rules. This guide explains the federal framework and the practical questions to raise; it is not a substitute for reviewing a specific power of attorney, guardianship order, or state statute.
This article is for general educational purposes and does not provide legal or medical advice. It does not replace guidance from a patient’s health care provider, health system, or a qualified attorney familiar with the applicable state law. For more on how this publication verifies sources, see How We Research. To understand the scope of topics this site covers, start with Start Here.
Sources: HealthIT.gov, Patient Access Information for Individuals; HHS.gov, Individuals’ Right under HIPAA to Access their Health Information.
By Connected Care Guide Editorial Team. Last updated September 9, 2026.
Leave a Reply