Tests, medicines & records

Medical privacy and unauthorized record access in China

Contain a misdirected report, exposed portal link or unexpected record access, then document the event and use the hospital's official complaint route.

Editorial illustration of a passport, insurance card, policy documents and hospital paperwork.
AI-generated editorial illustration; not a real hospital or patient.

A laboratory report sent to the wrong person, a record link that opens without the expected check, an unfamiliar portal session, or information shared with an unintended family member, employer or translator can require fast administrative action. This guide helps you contain exposure, preserve a clear account and contact the responsible organization. It cannot decide whether an event was unlawful, who is at fault, whether compensation is due or whether a particular person had authority under all relevant facts.

Use this as a practical starting point

Provider procedures can change, so confirm time-sensitive details with the hospital, insurer or service. A licensed professional must make clinical decisions for an individual patient.

At a glance

Key points

  • Contain the channel first: stop forwarding, ask the sender to disable an exposed link or session, and use a verified hospital contact rather than replying with more records.
  • Record what happened without copying or circulating more medical information than is necessary to identify the incident.
  • Ask the hospital to distinguish an access problem, a wrong-recipient disclosure, an inaccurate contact detail and a formal rights or complaint request.
  • Institutional traceability controls do not mean a patient automatically receives every internal access log; request an investigation outcome and ask what information can lawfully be provided.
  • Personal-information consent is important in many workflows, but it is not the only possible legal basis for processing and must not be used as a shortcut to judge an incident.
01

Identify the incident without widening it

Start with the smallest accurate description. A wrong-recipient event may involve a report emailed or messaged to another person. A link-exposure event may involve a portal URL, QR code or download token that appears usable by someone who should not have it. An unexpected-access event may appear as an unfamiliar login, device, notification or change. An unwanted-sharing event may involve a family member, companion, employer, insurer or translator receiving more information than the patient expected. These descriptions organize the response; they are not legal findings.

Do not test an exposed link by sending it to friends or colleagues, and do not ask an unintended recipient to return the entire file through an insecure channel. If you received somebody else's record, stop viewing or forwarding it, notify the apparent sender through an official contact, and follow its secure instructions. A cropped screenshot showing the date, sender and non-clinical error message may sometimes document the event, but avoid capturing or redistributing unrelated health details.

  • What was exposed or accessed: report, image, visit note, prescription, bill or portal account
  • How it happened: email, message, paper handover, shared device, QR code, portal or third-party service
  • Who appeared to send and receive it, using only the identifiers needed for follow-up
  • When you discovered it and whether the link, session or message remains active
02

Contain the channel and protect ongoing care

Contact the hospital through a number, portal or desk published on its official website or appointment materials. Ask for the team responsible for the portal, medical records, information security, patient services or complaints. Explain the immediate containment request before sending attachments: disable or replace the exposed link, close an unfamiliar session, correct an incorrect destination, or tell you how to return or securely delete a misdirected copy. The organization may need to preserve its own records while containing access, so do not demand destruction of every copy as the only acceptable action.

Change the patient's portal password if the official system allows it, end other sessions where that feature exists, and secure the email or phone account connected to the portal. Do not change clinical content, dates or identifiers inside the medical record. If the incident also blocks access to a result or an upcoming appointment, open a separate service request for a safe replacement and follow-up route so privacy handling does not interrupt necessary care.

If another person received the information, ask them not to open, save or forward it and to follow the sender's secure disposal instructions. Avoid threats or public accusations. A calm containment message creates a clearer record and reduces additional disclosure while the facts are checked.

Article 57 of the Personal Information Protection Law provides an incident-response and notification framework when personal information is or may be leaked, tampered with or lost. It calls for immediate remedial measures and notice to the departments performing protection duties and to affected individuals, while allowing the handler not to notify an individual when its measures can effectively avoid harm; the responsible department may still require notice if it considers harm may occur. Ask the hospital whether it assessed the event under its incident process, what containment it completed, whether notification was considered and which contact handles questions. Do not assume from this page that every reported exposure must produce an individual notice or that a non-notification decision proves compliance.

Containment is not a conclusion about legality or fault. Ask the responsible organization to secure the channel, preserve relevant evidence and investigate under its formal process.

03

Create a precise incident record

Write a timeline with the discovery time, affected account or document, device or channel, people contacted, case numbers and actions taken. Keep the original notification headers, portal alert or envelope if it can be stored securely. Record statements as statements—who said what and when—rather than turning them into conclusions about intent, authorization or harm.

Ask the hospital to acknowledge the report and identify the team handling it. Request preservation and review of relevant operational records under the institution's process. The 2025 electronic medical-record measures emphasize role- and task-appropriate permissions, minimum necessary access, traceability and controls on sharing. Those controls support a focused institutional investigation, but they do not by themselves promise that the patient will receive raw audit logs, staff identities or security details. Ask instead for the scope of review, containment completed, correction made and the outcome that can be disclosed.

  • Hospital or vendor case number
  • Exact portal account, document date or visit identifier
  • Containment request and time acknowledged
  • Safe contact address for the written response
  • Any replacement report or corrected contact route supplied
04

Separate access, correction, privacy and complaint requests

A request to obtain the patient's own record, a request to correct inaccurate personal information, a request to investigate an apparent disclosure and a complaint about service are different tasks. Label each one. Under the Personal Information Protection Law, medical and health information is sensitive personal information, and individuals have rights that include consulting, copying and requesting correction of their personal information. The Civil Code also addresses patient access to medical records and confidentiality obligations. The exact route, identity checks and available response depend on the request and applicable rules.

Do not assume that every privacy concern creates a right to delete the underlying medical record. Medical institutions may have legal and operational retention duties, and the Personal Information Protection Law describes deletion in specified circumstances rather than as an unlimited remedy. A safer request asks the hospital to correct an inaccurate destination or identifier, restrict an exposed channel, explain how the record is protected and state what action it took.

Likewise, do not assume that a family contact, emergency contact, companion, interpreter or person holding the patient's phone has blanket authority to receive all information. Ask the hospital how the recipient, purpose and scope were recorded. There can also be circumstances in which information is processed on a basis other than individual consent, so this guide does not treat absence of a familiar consent screen as proof of a violation.

05

Use the hospital complaint route, then consider specialist advice

If the service or security team does not resolve the issue, ask for the institution's official complaint office and submission method. National complaint-management measures require medical institutions to organize complaint handling, but the complaint team may need to coordinate with medical records, information technology, the clinical department or a service provider. Submit the concise timeline, the specific containment or correction still needed, and the outcome you want explained. Keep medical details limited to what the investigation requires.

The Personal Information Protection Law also allows an individual to complain or report unlawful personal-information processing to a department performing personal-information protection duties. It does not make one authority competent for every hospital, platform, insurer, employer or cross-border incident. Ask the organization to identify the personal-information handler and official external complaint route, then verify the receiving authority's current jurisdiction before disclosing records.

A hospital or regulatory complaint can produce handling and a response within the receiving body's remit; it does not itself determine civil liability, criminal responsibility, regulatory penalties or compensation. If the incident is serious, involves continuing misuse, creates a cross-border or employment issue, or requires a legal remedy, seek advice from a qualified professional who can review the jurisdiction, documents and facts. Do not publish other patients' data or unverified staff identities while seeking help.

Avoidable problems

Common mistakes

  • Forwarding an exposed link or somebody else's report to test whether other people can open it
  • Sending a passport and the full medical file to an unverified email address that claims to be support
  • Demanding raw internal access logs as if every patient automatically receives them
  • Treating deletion of the lawfully retained medical record as the only possible privacy response
  • Assuming consent is the only possible basis for every use of medical information
  • Naming staff publicly or alleging illegality before the institution has checked the facts

Common questions

Frequently asked questions

What should I do if I receive another patient's report?

Stop viewing and do not forward it. Contact the apparent sender through a verified official channel, explain that the record appears misdirected and ask for secure return or disposal instructions. Do not include more of the other patient's information than is necessary to identify the error.

Can I demand the hospital's complete access log?

Do not assume an automatic right to every raw internal log, staff identity or security detail. Ask the hospital to preserve and review relevant records and to provide the scope, containment, correction and outcome it can lawfully disclose. Obtain specialist advice if a more formal evidence request is needed.

Can I require the hospital to delete my medical record?

Not as a blanket remedy. Personal-information law includes deletion in specified circumstances, while medical records can also be subject to retention duties. Ask to close an exposed channel, correct inaccurate personal information and explain the record's protection and retention route; seek legal advice for an individual deletion dispute.

Does sharing with a family member automatically prove a privacy violation?

No conclusion can be made from that fact alone. Ask who was recorded as the recipient, what authority or purpose applied, what information was shared and whether an emergency or other rule was involved. A companion or emergency contact is not automatically authorized for every disclosure, but the full context still matters.

Should I use the hospital's complaint office for a portal problem?

Start with the official portal, records or information-security contact for urgent containment. If the issue is not acknowledged or resolved, the hospital's complaint office can coordinate an institutional response. Keep the technical request and the service complaint clearly separated.

Can this guide tell me whether the hospital broke the law or owes compensation?

No. It provides an administrative containment and documentation workflow. A legal conclusion or remedy depends on facts, applicable law, evidence and the competent authority or court, and should be reviewed by a qualified professional.

Can I complain outside the hospital?

Personal-information law provides a complaint or reporting route to departments performing protection duties, but the competent authority depends on the organization, activity and jurisdiction. First identify the personal-information handler, preserve the hospital case number and verify the external body's official scope before sending medical records.

Must the hospital notify me about every possible exposure?

Do not assume an automatic notice in every report. Article 57 contains a notification framework and an exception where remedial measures can effectively avoid harm, while the responsible department may require notice if it considers harm may occur. Ask for the hospital's incident assessment, containment and notification status; this guide cannot decide whether its legal duties were satisfied.

Evidence

Sources consulted for this guide

National rules are separated from city and provider examples. Access dates show when a source was collected; source pages and procedures can change afterward.

01Personal Information Protection Law of the People's Republic of ChinaNational People's Congress of the People's Republic of China · accessed 15 July 2026 · National personal-information framework, including the sensitive status of medical and health information, incident response and notification, individual rights and complaints or reports to departments performing protection duties; it does not identify the competent authority for every incident, decide unlawfulness or require deletion of records that must be retained02Civil Code of the People's Republic of ChinaCyberspace Administration of China (official government text) · accessed 15 July 2026 · National civil-law provisions on medical records, patient access, privacy and confidentiality; it is not an incident-specific finding about fault, liability, damages or who may receive information in every circumstance03Notice on Further Strengthening the Management and Use of Electronic Medical Record Information in Medical InstitutionsNational Health Commission of China · accessed 15 July 2026 · National 2025 institutional controls for electronic medical-record access, minimum necessary permissions, operation traceability, sharing and incident handling; traceability does not by itself give a patient automatic access to every internal log04Medical Institution Complaint Management MeasuresNational Health Commission of China · accessed 15 July 2026 · National framework for hospital complaint channels, acceptance, coordination and feedback; it does not determine whether a privacy breach occurred or what legal remedy may follow