But there are lots of political barriers. NHS is trying, and pretty open to private tenders. I'm actually working on a very related field.
Smaller or more atomized healthcare systems than NHS would be probably even difficult to deal with initially.
What needs to happens is for the US federal government to issue a mandate: if a hospital wants to get federal dollars (Medicare, etc), its computer system has to comply with the FXHR rules (Federal eXchange for Health Records, or whatever they want to call it). To establish FXHR, they get the top 5 vendors in a room and tell them that they WILL come up with a data exchange protocol and format within x months. They did this with HIPPA, they can do it with data exchange too.
And it is sorely needed. I went to Mayo Clinic for a week, which generated 80 pages of medical reports. To get these transferred to my regular doctors, I had to call Mayo, request the transfer, and they had to schedule the transfer, which sometimes took up to a week. This isn't because they are inefficient (far from it). It's because when they do a fax, sometimes the fax machine isn't on, so it can't go through. They have to retry until they get through. The receiving machine ran out of paper. Etc. It's ridiculous.
Beyond that, I watched my eye doctor try to flip through 80 pages of crap that mostly didn't relate to him to find the pages that were eye related. None of this has any structure; it's just a bunch of pages of text. Horribly inefficient use of his time, and very likely he would miss something important. You want to see blood test results? Well, I had about 10 of them testing various things, and the lab results are spread all through the report. Good luck finding what you want. Truly a mess, and the large software companies have zero incentive to fix this problem. Their goal is to be "the one to rule them all", or at least one of the few. And when there are only a few, there still won't be any data exchange, because they will be duking it out with each other.
Government screws stuff up all the time, but so do private companies, and government is the only player in a position to force the private companies to do the right thing.
It is unfortunate because obviously in principle a single centrally-administered records facility with robust security and audit trails for all access and a Hippocratic Oath level of privacy protections would be far better than the status quo in many ways. But we have no constitutional way to establish adequate legally binding safeguards that some later government can't just overturn for its own convenience in the future.
> It is unfortunate because obviously in principle a single centrally-administered records facility with robust security and audit trails for all access and a Hippocratic Oath level of privacy protections would be far better than the status quo in many ways.
Funny, one would have thought that pretty much is the status quo already: Looks to me like the UK already has (or should have) a single centrally-administered records facility with robust security and audit trails -- isn't that the NHS?
If it doesn't at the moment quite fulfill your requirements, it certainly ought to anyway, oughtn't it? So the problem is one of fixing its possible current deficiencies, not one of lacking it entirely. Or?
In normal circumstances an individual's primary point of contact with the NHS is supposed to be their GP, and the GP's surgery will normally hold the main medical records for each person under their care. But then other parts of the NHS, such as hospitals or therapists, may hold their own records in connection with the specialised treatments they provide. There are all kinds of protocols for sharing health records between clinical professionals who are directly responsible for a patient's care and potentially others and successive governments keep meddling with them in ways that make you nervous about those others and what they get to know and what they can do with it.
I kind of assumed there was some public administrative service run by the national government behind it all. That would have been the logical entity to run a central storage repository, and perhaps to administer and maybe even define the storage and transmission format(s). IMO.
I just had an email from Mouser(online electronics store), that gave me the option to send in export for by fax...
It's also very annoying that most EU banks rely on SMS codes to confirm transactions as it's quite easy to clone SIM cards. Yet they don't support real OATH OTP.
I hate Office 365, but I have to concede that their login is much more robust. I use passwords + OATH and it's truly reliable.
Gmail has locked me out very often for no clear reason. Besides they don't support TOTP unless you use a key or a phone app. So I can't use an airgapped device to store my keys.
AFAIK, N26 still uses on-time codes sent by SMS which I regard as very insecure.
Phone 2 factor is pretty much the only kind of 2 factor most people will accept, and for most people the phone number probably has better security than most people's emails, because most people reuse passwords, while with phones you had to do a special non-password effort for them.
E: Seriously? This is a multi billion dollar industry. Oh no, Google would never do that…