The Data Portability Right Healthcare Still Can't Deliver

Brazil's General Data Protection Law guarantees the data subject, among their rights, the portability of their personal data to another service or product provider, upon express request.¹ On paper, this means a patient has the right to take their health data from one institution to another. In the practice of Brazilian healthcare, this right runs into an obstacle the law alone doesn't resolve: exporting a bunch of incomparable PDFs is not real portability, and that is what most institutions can offer today.

The distinction between delivering files and delivering portable data is subtle in discourse and enormous in practice. And it is precisely in this distinction that it is decided whether the right guaranteed by law materializes into concrete benefit for the patient or remains a formality fulfilled on paper and empty in substance.


What the law guarantees and what practice delivers

The right to portability, as established in the LGPD, has a clear purpose: to give the data subject effective control over their data, allowing them to transfer it between providers without losing the accumulated history.¹ The legislator's intent is that the patient not be locked into an institution for the simple reason that their data is held there. Portability is, in this sense, an instrument of subject autonomy and of reduction of the asymmetry between them and the organizations that hold their data.

The problem is that Brazilian healthcare, in most cases, can only fulfill the letter of this right, not its spirit. When a patient requests their laboratory data, what they typically receive is a collection of PDFs, each visually reproducing a report, with nomenclatures, units, and reference ranges that vary according to the laboratory that issued them. Technically, the institution delivered the data. Substantially, it delivered documents that the next provider will have the same work of deciphering that it would have had if the patient had simply brought the original papers.


Why a PDF is not portable data

The reason a report PDF does not constitute real portability is the same one that makes it an obstacle in any other context: a PDF is the image of a datum, not the datum itself. It contains the numbers, units, and reference ranges in a form readable by a human, but not structured to be consumed by software. For the destination provider to effectively use this data, integrate it into their system, compare it with new tests, feed it into their alerts and analyses, the PDF needs to be converted into structured data, in a process that involves extraction, interpretation, mapping, and normalization.

This means portability via PDF only transfers the problem, without resolving it. The patient took their files from one institution to another, but the work of making those files usable remains entirely undone, now at the destination. The history that should accompany the patient in a useful way arrives at the new provider in the same unstructured condition it was in, and the promise of continuity that justifies the right to portability is lost in the incomparability of the transferred data.

McDonald and colleagues, in describing LOINC as a universal standard for identifying laboratory observations, make clear why semantic structuring is what makes clinical data effectively transferable between systems: without a common identity for each test, data from one source cannot be reliably interpreted by another.² Real portability, therefore, is not moving files. It is moving data the destination can interpret.


Portability as a harmonization problem, not a transfer problem

There is a tendency to treat portability as a logistical transfer problem: how to get the data out of one place and into another. This view captures the easy part of the problem. The hard part, and the one that effectively determines whether portability generates value, is semantic: how to make the data that arrived at the destination mean there the same thing it meant at the origin.

Vest and Gamm, in one of the main reviews on health information exchange, are explicit about this point: the technical transfer of clinical data resolves only the simplest layer of the problem, and semantic fragmentation persists even after the data has been moved.³ Applied to portability, this means an institution can fully comply with the obligation to transfer the patient's data and still not deliver real portability, because the transferred data isn't interpretable at the destination without a new structuring effort.

Real portability depends, therefore, on the data being structured and harmonized before or during the transfer: with each test mapped to a recognized standard, each unit normalized, and each reference range documented. Only then is what arrives at the destination a history that can be immediately integrated and used, rather than a new pile of documents to be deciphered. Harmonization is not a refinement of portability. It is the condition for portability to fulfill the function the law assigned to it.


What changes when portability is real

When the portability of health data is real, and not just formal, the effects are distributed among the three actors in the relationship. For the patient, the right guaranteed by law materializes into concrete benefit: their history accompanies them in a useful way, and changing providers stops meaning the practical loss of their accumulated clinical trajectory. For the destination provider, the data that arrives is immediately usable, which reduces rework, avoids the unnecessary repetition of tests, and allows real continuity of care. For the origin provider, the ability to deliver real portability stops being a compliance risk and becomes a differentiator in the relationship with the patient.

This last point deserves attention, because it inverts the logic with which portability is usually seen. Institutions frequently regard the right to portability as a regulatory burden, something to be fulfilled at the minimum necessary to avoid sanction. But an institution that delivers real portability, with structured and immediately usable data, demonstrates to the patient and to the market a level of digital maturity that converts into trust. Compliance, in this framing, stops being a cost and becomes a signal of quality.

The regulatory context reinforces the direction. The REL model of the National Health Data Network, established by Ordinance GM No. 8,276 of the Ministry of Health in October 2025, requires structured submission of laboratory results with recognized terminologies.⁴ The infrastructure an institution builds to comply with this model is, to a large extent, the same it needs to deliver real portability: structured data, mapped to standards, comparable across sources. Regulatory compliance and effective portability converge on the same need for semantic structuring of the data.

This is where OpenHealth Technologies operates. The platform automatically correlates multiple data streams with rigorously validated logical layers of laboratory tests, transforming laboratory data in any format, including PDF, into structured data, mapped to LOINC, with normalized units and documented reference ranges, across over 3,500 biomarkers. For institutions that need to fulfill the right to portability, this means the data transferred to the patient or to the next provider arrives at the destination in a condition of immediate use, and portability stops being a formality fulfilled on paper to become the real continuity of care the law intended to guarantee.

Learn how your institution can transform the data portability obligation into real portability, with structured data immediately usable by the patient and the next provider.