A method and apparatus for personally controlled sharing of medical image and other
health data are disclosed. According to one aspect, the
subject matter described herein includes a method for patient mediated access to patient
health information maintained by different healthcare facilities and other health
record repositories. The methods includes, using a central
key server and a plurality of data servers local to healthcare facilities and other health
record repositories. At the central
key server, a patient controlled registry of access keys that control access to patient
health information maintained by different healthcare facilities is provided. The central
key server receives, from a data
server of a first healthcare facility, a request for an
access key that controls access to
health information for a patient maintained by a second healthcare facility. In response to the request, the central key
server authenticates credentials of the patient and the first healthcare facility, verifies permission from the patient to release the
access key to the first healthcare facility, locates the
access key for the health information for the patient at the second healthcare facility, and provides the access key to the first healthcare facility. The access key is used by the data
server of the first healthcare facility to obtain health information for the patient directly from the data server of the second healthcare facility after successful
authentication and
verification by the second healthcare facility.