Buying international health insurance means handing over the most sensitive category of information most people possess, to a company that may be regulated in a country they have never visited, which will then share it with several others in the ordinary course of doing its job. That is the practical reason a policy application can feel more intrusive than anything else in a relocation — and the reason people occasionally decline to answer a question they should have answered.
This guide sets out what is actually disclosed, where it goes, what rights you generally have, and — most usefully — which questions to ask before you sign. It is deliberately general on the law: obligations differ between jurisdictions and depend on the role each entity plays, so read the privacy notice attached to your own policy rather than relying on a summary of principles.
What an application actually discloses
A full medical underwriting application is not a short form. Applications currently in the market run to dozens of separate health questions, organised by body system and by lookback period. A representative structure asks about physical impairment, recurring illness or injury, regular prescribed medication and recent medical attention, then works through neurological, mental health, cardiovascular, respiratory, digestive, skin, urinary, reproductive, musculoskeletal, endocrine, sensory and immune conditions, fertility treatment, alcohol and substance use, implants and prostheses, time off work through illness, significant weight change, pending treatment, current symptoms, tobacco use, any previous decline or loading on other insurance, hospitalisation over a ten-year window, pregnancy and major dental work.
Applications also commonly ask for the name, address and contact details of the doctor most familiar with your medical history, and how long you have been known to them. That single field converts a self-declaration into a potential route to your underlying records.
The consent section that follows can be a substantial document in its own right, signed separately by every dependant aged eighteen or over, with a parent or guardian signing for minors.
Moratorium and full underwriting: a real privacy trade-off
The choice of underwriting basis is usually discussed in terms of exclusions and premium. It is also a privacy decision, and the trade-off runs in opposite directions at the two ends of the policy.
Under full medical underwriting, you disclose comprehensively at the outset. The insurer issues terms — full cover, cover with a condition excluded, cover with an additional premium, or a decline. The burden is heavy and front-loaded, but the outcome is known before you rely on the policy. One current wording notes that an applied condition exclusion is permanent, though it may be reviewed after a minimum period on documented evidence of improved health.
Under a moratorium, you disclose very little at application. That is the attraction. But eligibility for any given condition is then determined at the point of claim, by reference to your history in a defined lookback window — so the enquiry into your records happens later, when you are unwell, and is directed at exactly the condition you are claiming for.
Neither route reduces the total medical information the insurer eventually sees on a claimed condition. Full underwriting front-loads it; moratorium defers it into the claim. If you find the application intrusive, a moratorium moves the intrusion rather than removing it. The mechanics are in how the moratorium clock actually works and moratorium versus full medical underwriting.
The corollary is underestimated: incomplete disclosure at application is discovered at claim, and current wordings are explicit that failing to provide required information can mean claims rejected or not paid in full, or the policy cancelled. See disclosure, non-disclosure and voided cover.
Health data as a special category
Under the UK and EU General Data Protection Regulation, data concerning health sits within a category subject to a general prohibition on processing, lifted only where one of a defined set of conditions applies. The practical consequence for insurance is that insurers must identify and state a basis, and typically rely on some combination of explicit consent, necessity for performance of the contract, compliance with legal obligations, and grounds relating to insurance and substantial public interest. Which basis applies to which activity varies between insurers, jurisdictions and processing purposes within the same policy — which is why the privacy notice is worth reading rather than assuming.
Consent wording is broader than most applicants realise. Current application forms include permission for the insurer to obtain health and other data from physicians, hospital staff, medical institutions, care homes, statutory health insurance funds, the plan sponsor, professional associations and public authorities — with an agreement to release those parties from their confidentiality obligations, and in one case an express waiver of rights of "medical secrecy" for the purposes of the application.
Two balancing points. Consent of this kind can normally be withdrawn, though documentation notes, correctly, that withdrawal may prevent claims being processed. And published purposes are usually specific — underwriting and administration, claims, fraud prevention, legal and regulatory compliance, research and statistical analysis, and communication — with marketing separated out and requiring its own explicit consent.
Where the data actually goes
The multi-jurisdiction chains described in insurer solvency ratings and due diligence are also data chains, and this is where an international policy differs sharply from a domestic one.
Two current examples make the point. Under one international personal health plan, the product is arranged and administered by an entity registered in Belgium with a UK branch, and underwritten by a French insurer. Its privacy section states that data is primarily stored in the UK or the EEA, with routine transfers to insurers in the UK and France to manage policies, underwriting and claims, and transfers beyond the UK and EEA in limited circumstances — where the member or their broker sits elsewhere, or where a treating provider in another country needs information to support a claim. Named safeguards include standard contractual clauses, binding agreements and secure transmission, with reliance on explicit consent for sensitive data where required. Retention continues after the policy ends, for fraud prevention and to satisfy Belgian, French or UK legal requirements.
Under a second international plan, the data controller is a German-based managing general agent, the insurer is a French mutual or its Portuguese subsidiary depending on the certificate, and the data protection officer is at a Paris address. Listed recipients include insurers, brokers, managing general agents, reinsurers, claims handlers, loss adjusters, credit reference agencies, service providers, professional advisers, regulators, police and government agencies, and fraud prevention agencies.
Read either list and the reality is clear: one policy, four countries, a dozen categories of recipient. That is not a defect; cross-border insurance cannot function otherwise. But "who can see my medical history" has a longer answer than most buyers assume, and the answer changes if your policy is transferred — a scenario dealt with in when your insurer is acquired or rebranded.
Your own records, and moving them between countries
Separate from what the insurer holds is the practical problem of getting your medical history to follow you, and access rights help without solving it. You generally have a right to request a copy of the personal data an insurer holds about you, to have inaccuracies corrected, and in some circumstances to restrict or object to processing; some documentation adds rights of deletion, portability and, under French-influenced wording, the right to give instructions about your data after death. One limitation appears explicitly in current wordings: where information came from a medical practitioner, the insurer may need that practitioner's consent before releasing it to you, and may direct you to the practitioner instead.
The obstacles when you move are mundane and persistent. Records sit with individual practices rather than centrally. Release procedures, fees and formats differ. Clinical documents arrive as scanned images rather than structured data. Translation is your problem, and a translated record is not always accepted as authoritative. Results are reported against local reference ranges, and vaccination and screening histories — the things a new treating doctor most wants — are often hardest to reconstruct.
Build your own file before you need it: a current medication list with doses, a dated summary of significant diagnoses and procedures, key imaging and pathology reports, and vaccination records — requested while you are still your existing doctors' patient, rather than by email from another continent two years later.
Disclosure at claim time, and services built to sit outside it
Claims involve a second round of disclosure, more targeted than the first. Pre-authorisation is where this bites. International plans routinely require pre-authorisation for inpatient and day-patient treatment, and the process involves the insurer obtaining clinical information directly from the treating hospital. Current documentation describes asking the member to complete a pre-authorisation form and a consent form permitting the hospital to release the necessary medical information to the insurer. Your insurer and your hospital therefore exchange your clinical details directly, on your authority, while you are being admitted. That is how direct settlement works; no version of it avoids the exchange. The sequence is set out in how an IPMI claim works.
Two smaller mechanisms are easy to miss. Where the same costs are covered by another policy, insurers commonly reserve the right to share data with that insurer to apportion the claim. And on a family policy, claims correspondence is usually addressed to the policyholder by default — though at least one current wording gives an insured dependant over sixteen a right of confidentiality over their own claims and data, exercisable by contacting the insurer.
There is a design response to all of this, and it is worth recognising when you see it. AXA Global Healthcare operates a 24-hour medical help and information line staffed by nurses, midwives, pharmacists and counsellors, which its own material describes as completely separate from its claims service, and which can be used anonymously.
The separation is the feature. A member weighing up whether a symptom is worth investigating, or whether to seek help for a mental health difficulty, is making a decision a claim record would document. Where the information service is architecturally separate from claims and can be used without identifying yourself, that consideration drops out. Whether any given service is genuinely separated is worth asking directly, because "confidential" and "not connected to your claims file" are different promises. See virtual GP and second medical opinion services, and on the sensitivities of mental health cover, mental health coverage in international health insurance.
What to ask, and what to check
- Who is the data controller for your policy, and is it the same entity as the insurer?
- Where is the data protection officer, and what is the address for exercising rights?
- Which complaints authority applies to you? Documentation frequently splits this by member location.
- Which countries does the privacy notice say data is stored in and transferred to, and on what safeguards?
- What is the retention period after the policy ends, and on what basis?
- If you switch insurer, what is transferred? Continuity of underwriting terms means transferring medical information too — see switching IPMI insurer without losing continuity.
- If your policy is transferred to another carrier, who becomes the controller, and are you notified?
These rules change, and you must check them
Data protection law, insurer privacy practice and the corporate structures behind international policies all change, and international transfer mechanisms in particular have been revised repeatedly in recent years. Everything above reflects research current as at July 2026 and is drawn from policy wordings, application forms and provider material rather than from legal advice.
This guide describes general principles and the questions worth asking; it does not state the legal position in any jurisdiction. Read the privacy notice attached to your own policy, ask the insurer in writing where answers are unclear, and take advice from a qualified adviser if the answer matters to a decision you are about to make.
Frequently asked questions
What does an international health insurance application actually disclose?
More than a form-filling exercise suggests. A full medical underwriting application typically runs to dozens of specific health questions covering conditions by body system, medication, hospitalisation, mental health, substance use, pregnancy and sometimes weight change and tobacco use — often looking back five or ten years. Applications commonly also ask for the name and contact details of the doctor most familiar with your history, which converts the form from a self-declaration into a potential route to your records.
Is a moratorium application more private than full underwriting?
At the application stage, yes, and that is a genuine advantage. A moratorium policy is issued without a detailed health declaration, so far less is disclosed up front. The trade-off arrives later: because eligibility is determined when you claim, the insurer investigates history at the point of claim instead, which can mean a broader retrospective enquiry into records precisely when you are unwell. It is a timing difference in disclosure, not a reduction in it.
What is special category data, and why does health information count?
Under the UK and EU General Data Protection Regulation, data concerning health falls within a category subject to a general prohibition on processing, lifted only where a specified condition applies. In practice insurers rely on grounds such as explicit consent and, in some contexts, provisions relating to insurance and substantial public interest. The details vary by jurisdiction and by the entity's role, so the useful step is to read the privacy notice and see which basis is claimed.
Which countries will my medical data pass through?
Potentially several. A single international policy can involve a broker in one country, an administrator or managing general agent in a second, an insurer in a third, and reinsurers, assistance companies and claims handlers elsewhere again. Policy privacy notices often state that data is primarily stored in one region with routine transfers to insurers elsewhere, and further transfers where a broker or a treating provider sits in another jurisdiction.
Can I see the medical information my insurer holds about me?
You generally have a right to request a copy of the personal data an insurer holds about you, along with rights to correct inaccuracies and, in some circumstances, to restrict or object to processing. One practical limitation appears in real policy documentation: where information came from a medical practitioner, the insurer may need that practitioner's consent before passing it to you, and may direct you to request it from the practitioner instead.
What am I agreeing to when I sign the consent section?
Read it rather than assuming. Consent wording in current international applications can authorise the insurer to obtain health data from physicians, hospitals, care institutions, statutory health funds, employers sponsoring the plan and public authorities, and to release those parties from their confidentiality obligations. Some wording asks the applicant to waive rights of medical confidentiality for the purposes of the application. Consent can usually be withdrawn, but withdrawing it may prevent claims being processed.
Do my adult dependants have any privacy from the policyholder?
Sometimes, and it is worth knowing. At least one current international policy states that claims correspondence is addressed to the policyholder by default, but that an insured dependant over the age of 16 has a right to confidentiality in relation to their own claims and personal data, exercisable by contacting the insurer directly. If that matters in your household, raise it at the outset rather than after a claim.
This guide is general information only and does not constitute financial, legal, medical or tax advice. Global Investments is not authorised by the Financial Conduct Authority. Insurance products, benefit schedules and premiums are revised regularly, and mandatory health insurance requirements change frequently — in several jurisdictions they are described differently even between official sources. Nothing here is a recommendation of any product or insurer. Confirm the legal position with the relevant regulator or a locally qualified adviser, and confirm cover terms with the insurer, before acting.