One record, gathered by the patient's own right of access.
The individual is the account holder. They verify their identity, authorize the request, receive their records across every system they have touched, and decide where it goes next.
The patient is in the driver's seat, start to finish.
The patient signs up.
The individual is the account holder. It is their account and their record, not a request made about them by someone else.
Identity verified to NIST IAL2.
Before any record is requested, the patient verifies their identity to NIST IAL2 (government-issued ID plus a liveness check) through a certified identity provider.
The patient authorizes the request.
The patient exercises their HIPAA individual right of access, with the right-of-access language shown at the point of consent. Nothing is retrieved without it.
The assembled record is delivered to the patient.
The patient views and downloads their own record: clinical data and documents from EHRs (reached directly and through HIE networks), plus claims and coverage from payers where they authorize it, all normalized into one structure.
The patient directs where it goes.
Any share with a provider, an attorney, or another app is chosen by the patient, per recipient, with an explicit consent step and a record they can revoke at any time.
One record, across every system the patient has touched.
Every source, one record.
The clinical record from EHRs, reached directly and through HIE networks: encounters, problems, medications, allergies, and the documents behind them, structured and unstructured. Claims and coverage from payers where the patient authorizes it, normalized into one record.
API, browser, and voice.
Where an API stops, browser and voice retrieval reach the rest, so no source is out of reach and no gap is left as a footnote.
HIE and network exchange.
Electronic exchange where it is available, with the right-of-access request as the path that works everywhere else.
A couple clicks for your user. No work on your end.
Your user, a couple clicks.
They verify their identity and authorize the request once. That is the whole ask on their side.
The chasing is ours, not yours.
Hubble goes and gets the records across every source, so nobody on your team logs into a portal, works a phone tree, or builds a per-provider integration.
Delivered ready to build on.
Records come back normalized through one API, with an MCP interface for agents, so your product gets the data, not a retrieval project.
Built on the patient right of access.
Every retrieval is grounded in the individual's HIPAA right of access (45 CFR 164.524), exercised by the patient and directing the copy to themselves and, where they choose, to a recipient they name.
Specially protected records (substance use under 42 CFR Part 2, psychotherapy notes, HIV and genetic information, and minors' records) are never swept into a general request. They require separate, specific authorization and are handled on their own consent path.
Request-Only IAS Provider: Hubble does not provide bidirectional services. You will have the ability to request access to your health information via TEFCA Exchange. You will not be able to use Hubble to share your health information with other participants in TEFCA.
Read the full Privacy and Security NoticeThe patient gets the record first, then decides.
Their attorney.
Personal injury, workers comp, and disability records assembled by the patient and directed to the firm representing them.
Research they opt into.
Real-world data and clinical trial matching, contributed by the patient on their own terms.
A new care team.
A history the patient can hand to the next provider on day one.
An app they choose.
Personal health record and vertical health apps the patient connects their record to themselves.
Patient-mediated access, explained.
What is patient-mediated access?
Patient-mediated access lets an individual authorize access to their own medical records once and receive a normalized record in return. The patient is the account holder. Hubble gathers the record across every system they have touched (EHRs reached directly and through HIE networks, plus payers where the patient authorizes it), and the patient directs where it goes.
How is patient-mediated access different from provider-mediated access?
Patient-mediated access is built on the individual's HIPAA right of access: the patient verifies their identity, authorizes the request, and directs their own record. Provider-mediated access is authorized reads and writes into the systems a provider customer already uses. Both run on Hubble's data layer across the same EHRs and payers.
What is the legal basis for patient-mediated access?
The HIPAA individual right of access (45 CFR 164.524) and the 21st Century Cures Act. The patient directs the copy to themselves and, where they choose, to a recipient they name, per recipient, with consent they can revoke at any time.
How is the patient's identity verified?
Before any record is requested, the patient verifies their identity to NIST IAL2 (a government-issued ID plus a liveness check) through a certified identity provider. No record is retrieved without an authorized, identity-verified request.
What sources make up the record?
Clinical data and documents from EHRs, reached directly and through HIE networks (encounters, problems, medications, allergies, and the documents behind them), plus claims and coverage from payers where the patient authorizes it, all normalized into one structure.
How are specially protected records handled?
Specially protected records (substance use under 42 CFR Part 2, psychotherapy notes, HIV and genetic information, and minors' records) are never swept into a general request. They require separate, specific authorization and are handled on their own consent path.
Connected to the systems your data lives in




+ moreSee how patient-mediated access works in 20 minutes.
Bring a real scenario and we'll walk through how we'd retrieve the records.