One record, gathered by the patient's own right of access.
The individual is the account holder. They verify their identity, authorize the request, receive their records across every system they have touched, and decide where it goes next.
The patient is in the driver's seat, start to finish.
The patient signs up.
The individual is the account holder. It is their account and their record, not a request made about them by someone else.
Identity verified to NIST IAL2.
Before any record is requested, the patient verifies their identity to NIST IAL2 (government-issued ID plus a liveness check) through a certified identity provider.
The patient authorizes the request.
The patient exercises their HIPAA individual right of access, with the right-of-access language shown at the point of consent. Nothing is retrieved without it.
The assembled record is delivered to the patient.
The patient views and downloads their own record: clinical data and documents from EHRs (reached directly, through HIE networks, and with browser and voice agents for the long tail), plus claims and coverage from payers where they authorize it, all normalized into one structure.
The patient directs where it goes.
Any share with a provider, an attorney, or another app is chosen by the patient, per recipient, with an explicit consent step and a record they can revoke at any time.
One record, across every system the patient has touched.
Every source, one record.
Clinical records from EHRs, reached directly and through HIE networks: encounters, problems, medications, allergies, and the documents behind them, plus claims and coverage from payers the patient authorizes.
API, browser, and voice.
Where an API returns thin or stops entirely, browser and voice agents retrieve the rest, so no source is out of reach and no gap is left as a footnote.
HIE and network exchange.
Electronic exchange runs wherever a network reaches the provider, with the patient right-of-access request as the path that covers everyone the networks leave out.
A couple clicks for your user. No work on your end.
Your user, a couple clicks.
They verify their identity and authorize the request once. That is the whole ask on their side.
The chasing is ours, not yours.
Hubble goes and gets the records across every source, so nobody on your team logs into a portal, works a phone tree, or builds a per-provider integration.
Delivered ready to build on.
Records come back normalized through one API, with an MCP interface for agents, so your product gets the data, not a retrieval project.
The teams building on patient records.
Built on the patient right of access.
Every retrieval is grounded in the individual's HIPAA right of access (45 CFR 164.524), exercised by the patient and directing the copy to themselves and, where they choose, to a recipient they name.
Specially protected records (substance use under 42 CFR Part 2, psychotherapy notes, HIV and genetic information, and minors' records) are never swept into a general request. They require separate, specific authorization and are handled on their own consent path.
Request-Only IAS Provider: Hubble does not provide bidirectional services. You will have the ability to request access to your health information via TEFCA Exchange. You will not be able to use Hubble to share your health information with other participants in TEFCA.
Read the full Privacy and Security NoticeThe patient gets the record first, then decides.
Their attorney.
Personal injury, workers comp, and disability records assembled by the patient and directed to the firm representing them.
Research they opt into.
Real-world data and clinical trial matching, contributed by the patient on their own terms.
A new care team.
A history the patient can hand to the next provider on day one.
An app they choose.
Personal health record and vertical health apps the patient connects their record to themselves.
Patient-mediated access, explained.
What is patient-mediated access?
Patient-mediated access lets an individual authorize access to their own medical records once and receive a normalized record in return. The patient is the account holder. Hubble gathers the record across every system they have touched (EHRs reached directly and through HIE networks, plus payers where the patient authorizes it), and the patient directs where it goes.
What is the legal basis for patient-mediated access?
The HIPAA individual right of access (45 CFR 164.524) and the 21st Century Cures Act. The patient directs the copy to themselves and, where they choose, to a recipient they name, per recipient, with consent they can revoke at any time.
How is the patient's identity verified?
Before any record is requested, the patient verifies their identity to NIST IAL2 (a government-issued ID plus a liveness check) through a certified identity provider. No record is retrieved without an authorized, identity-verified request.
What sources make up the record?
Clinical data and documents from EHRs, reached directly and through HIE networks (encounters, problems, medications, allergies, and the documents behind them), plus claims and coverage from payers where the patient authorizes it, all normalized into one structure.
How are specially protected records handled?
Specially protected records (substance use under 42 CFR Part 2, psychotherapy notes, HIV and genetic information, and minors' records) are never swept into a general request. They require separate, specific authorization and are handled on their own consent path.
70,000+ providers, across the systems patient data lives in




+ moreSee how patient-mediated access works in 20 minutes.
Bring a real scenario and we'll walk through how we'd retrieve the records.