Some of this information may be urgently needed at a time when the patient is not capable of giving informed consent for its disclosure or does not have it immediately available.
Some of the information may be vital to the future healthcare of the patient and would cause serious harm to them if it were lost.
And in more of a more morally grey area, some information might be harmful to the patient if they had it. For example, consider the implications of bluntly disclosing various mental health diagnoses to someone who doesn't fully understand what they mean and whose condition means they won't necessarily respond rationally or beneficially to the information.
In this case, having the records kept locally by exactly one organisation that is run by medical professionals who are bound by strong professional ethics seems like a reasonable policy.
No system will be perfect and because there are a marginal cases where it fails shouldn't therefore push responsibility to "professionals".
I don't know what the law actually is (and perhaps none of us do since as you say the issue doesn't seem to have been tested yet) but if the medical experts are almost universally of the same opinion then I probably know what the law should be.
"Licensed professionals are infalable and always know better"
We need to find solutions within the realities of government and industry power and effectiveness.
Also, there is no reason people can't make this decision for themselves. Who are you to tell me what I must do with my personal medical records? I may decide those risks are worthwhile.
Only if you have a paternalistic view
> Some of this information may be urgently needed at a time when the patient is not capable of giving informed consent for its disclosure or does not have it immediately available.
What if I accept the risk I may die due to bad luck/odd circumstances to still refuse the information being handled out by anyone but me?
> Some of the information may be vital to the future healthcare of the patient and would cause serious harm to them if it were lost.
Likewise, what if I accept future risks? I have more skin in the game from losing my records than an hospital losing them anyway.
> And in more of a more morally grey area, some information might be harmful to the patient if they had it.
Then what about I refuse having the information, in exchange of the information also being unavailable to anyone else?
Many people here seem to have the view "more information is good" but not collecting it in the first place seems better to me.
Hence I do no healthcare in the US, only in SE Asia where most services are available in English and Chinese anyway.
1) preauthorization directive 2) encrypted backups 3) no. The real reason is doctors are really scare of opening medical records and the multitude of clerical errors in them Copy pasting in the US is so rampant one has to wonder how much liability is dormant in the different EMRs