Fact-check
Rand Paul's Fauci Diary Release Exposed Private Medical Records. Now Who's Legally Exposed?
True: Paul exposed 20+ individuals' medical records in Fauci's diary. HIPAA doesn't apply to Congress. Speech or Debate Clause is the key protection; HHS carries the greatest statutory risk.
By The Crosscheck Desk · 2026-08-07
Sen. Rand Paul's Senate committee published Dr. Anthony Fauci's diaries without redacting personal medical information belonging to more than 20 named individuals (diagnoses, symptoms, and test results for conditions including cancer, Ebola, and HIV, some involving children), including private individuals who had never been public figures. A NOTUS report (2026-08-04) found that even after Paul's office pulled and reposted a partially redacted version, some personal medical information remained exposed.
| Party | HIPAA | Speech or Debate | Privacy Act | Civil Tort |
|---|---|---|---|---|
| Sen. Paul | None (not a covered entity) | Protected for legislative decision; less clear for website distribution | Not an "agency" — not subject to Act | Member likely protected; staff less certain |
| HHS / RFK Jr. | Covered entity, but authorized by Privacy Act §552a(b)(9) | Does not apply — executive agency, not Congress | Most exposed: if diaries were not "records," §552a(b)(9) may not cover | Possible Privacy Act civil suit if disclosure was unauthorized |
| Adelman / HIV individual | No remedy against Paul; no HIPAA claim | May sue non-member distributors under Doe v. McMillan | Civil suit against HHS is the viable statutory path | Common-law tort of public disclosure of private facts; damages difficult |
| Senate / HSGAC | No exposure | Legislative acts protected; distribution mechanism uncertain | Not an agency; not subject to Act | No specific PHI redaction rule found in committee rules |
The Factual Record
On July 26–27, 2026, Sen. Rand Paul, chairman of the Senate Committee on Homeland Security and Governmental Affairs (HSGAC), published over 1,600 pages of Dr. Anthony Fauci's personal diary entries spanning December 2019 through December 2022.[1] The documents were released days before Fauci's July 29 testimony before the committee — where Fauci invoked his Fifth Amendment rights throughout.
The diaries had been obtained from the Department of Health and Human Services. HHS Secretary Robert F. Kennedy Jr. stated publicly that his department spent approximately eight months locating the files across eleven different government servers, then handed them to Paul and Sen. Ron Johnson (R-Wis.) in response to Paul's oversight request.[2] An HHS spokesperson characterized the documents as "government records maintained on a government server," produced under applicable law. Neither HHS nor Paul's committee informed Fauci before publication that his diaries had been found and would be released publicly.
As Fauci director of the National Institute of Allergy and Infectious Diseases, he regularly documented medical situations involving colleagues, administration officials, patients, and members of the public who sought his assistance. The published diaries included the names, diagnoses, symptoms, and test results of those individuals without redaction.[3]
The core factual elements of the claim are confirmed:
- More than 20 individuals named with medical information exposed (confirmed by NOTUS).[1]
- Conditions included cancer, Ebola, and HIV (confirmed across multiple outlets).[1][3]
- Children's medical information included: at minimum, the infant child of Trump administration staffer Stephen Miller and his wife Katie Miller.[4]
- Private individuals who had never been public figures: Leslie Adelman and the unnamed HIV-positive individuals were not public figures.[1]
- Paul's office pulled and reposted with partial redactions, but some medical information remained (confirmed, with specific details below).[1]
Redaction Failures That Remained
NOTUS's August 4 report documented the specific gaps that survived Paul's office's corrective repost.[1] Two are named in detail:
Of two HIV-positive individuals Fauci described meeting in the early 2000s, one person's name was redacted in the updated documents. The other was not — leaving that individual's HIV status tied to their name in the publicly accessible version.
Leslie Adelman, who Fauci's diary identified as having Von Hippel-Lindau disease (a rare genetic condition), was not redacted in the updated versions. Adelman told NOTUS: "Pretty offended that my name and public health information have been shared to the world."[1]
By contrast, Craig Spencer, the Ebola survivor whose treatment details spanned more than 30 pages of diary entries, was redacted in the corrected version. Katie Miller's infant child's medical information was also reportedly redacted after the family objected.[4] The pattern of what was and was not redacted in the repost does not appear to follow any consistent rule; some high-profile names were protected while lower-profile private individuals were not.
HIPAA Is the Wrong Framework
Much of the public commentary on this incident invoked HIPAA as the applicable law. That framing is wrong, and the error matters because it leads to incorrect conclusions about who faces liability.
HIPAA's Privacy Rule applies only to "covered entities": health care providers, health plans, and health care clearinghouses, along with their "business associates."[5] Sen. Paul's office is none of these. HSGAC is none of these. A Senate oversight committee publishing documents it received from an executive agency is not performing a health care function and has never been treated as a covered entity under HIPAA. No HIPAA penalty framework reaches congressional action here.
The same logic applies to the question of whether HHS violated HIPAA by disclosing the diaries to Paul. HHS is a covered entity for its clinical and administrative health functions, but disclosure to Congress under the Privacy Act's oversight exception (addressed below) is explicitly authorized and governed by a separate statute. HIPAA's Privacy Rule carves out disclosures required or authorized by law.[6]
One privacy expert quoted by NOTUS put it plainly: the disclosure "doesn't fit squarely into any of the privacy laws."[1] That is a more accurate starting point than invoking HIPAA as the governing framework.
The Speech or Debate Clause: Protection, Not Immunity
Article I, Section 6 of the Constitution provides that members of Congress "shall not be questioned in any other Place" for "any Speech or Debate in either House." This is the most important legal barrier, and its scope is more limited than most commentary suggests.
The clause protects "legislative acts": compiling a report, entering documents into the committee record, voting for their publication, holding hearings where materials are presented.[7] These are activities at the core of the legislative function, and they receive absolute immunity from civil or criminal process.
The clause does not protect external public distribution beyond the legitimate legislative task. Two Supreme Court cases define this boundary.
In Gravel v. United States (1972), the Court held that Senator Gravel's arrangement to publish the Pentagon Papers through Beacon Press (a private publishing house) fell outside the clause's protection. The majority held that private publication "was in no way essential to the deliberations of the Senate; nor does questioning as to private publication threaten the integrity or independence of the Senate."[8] The protection for legislative aides, the Court held, runs only as far as activities "that would be immune legislative conduct if performed by the Senator himself."
In Doe v. McMillan (1973), parents of D.C. schoolchildren sued after a congressional committee report named their children in derogatory contexts and was distributed publicly by the Superintendent of Documents.[9] The Court drew a sharp line. Committee members, staff, and investigators were fully protected for the legislative acts of compiling the report and voting for its publication. The Superintendent of Documents and Public Printer were not protected for distributing the material publicly: the Court held that officials who "participate in distribution of actionable material beyond the reasonable bounds of the legislative task enjoy no Speech or Debate Clause immunity." Private individuals could bring suit against the distributors.
Applied here, the question is where posting documents on a Senate committee's public website falls on this spectrum. Entering the diaries into the committee record and voting to make them public almost certainly constitutes protected legislative activity. But publicly posting the documents on paul.senate.gov for anyone to download is structurally closer to the Superintendent of Documents function in Doe v. McMillan: distributing actionable material beyond the "reasonable bounds of the legislative task." That parallel has not been litigated in an analogous modern context, and any court would need to resolve it.
Importantly, the senator himself may be better protected than his staff. Gravel drew a distinction between the senator's direction to publish and the aides who physically executed the external distribution. Staff who carried out the posting could, in principle, face suits that the senator does not — though such actions would face enormous practical hurdles in practice.
The Privacy Act and HHS's Exposure
The Privacy Act of 1974 (5 U.S.C. §552a) prohibits federal agencies from disclosing records about individuals without their written consent, subject to twelve enumerated exceptions.[6] One of those exceptions is §552a(b)(9), which permits disclosure to "either House of Congress, or, to the extent of matter within its jurisdiction, any committee or subcommittee thereof."
This is an affirmative statutory authorization, not a waiver. Congress receives agency records by statutory right. HHS's production of the diary files to Paul's committee under an oversight request was, on its face, authorized under this provision.
The more difficult question is whether the diary entries constituted "government records" or Fauci's personal files that happened to reside on a government server. HHS described them as "government records maintained on a government server," which favors the former reading. Fauci and his lawyers took the opposite view. If a court were to find that the personal diary entries were not "records" in the system-of-records sense (i.e., were not maintained in a retrievable system used to make determinations about individuals), the §552a(b)(9) authorization might not have applied, and HHS's disclosure to the committee could face scrutiny.
The Privacy Act's civil remedy provisions allow individuals to sue agencies for unlawful disclosures. Congress itself is not an "agency" under the statute's definitions, which reference 5 U.S.C. §552(e). That matters: the affected individuals' most viable statutory claim runs against HHS, not Paul's office, because Paul's committee is not subject to the Privacy Act as a principal target. HHS is.
Civil Tort Claims: Narrow but Real
Setting aside statutory frameworks, common law offers a potential path: the tort of public disclosure of private facts, recognized in most states, penalizes the disclosure of highly personal information that would be offensive to a reasonable person and that is not of legitimate public concern.
The individuals most clearly situated to pursue such claims are those who were purely private — Leslie Adelman, the unnamed HIV-positive individual whose name survived redaction, and the unnamed individuals without public profiles. The Miller children were private individuals, though their parents (as Trump administration officials) were public figures, complicating the analysis.
Any tort suit faces three layers of difficulty. First, under Doe v. McMillan, plaintiffs could name the staff who executed the distribution rather than the senator himself — but courts would still scrutinize whether the posting qualified as sufficiently "legislative" to extend some immunity. Second, standing requires demonstrable harm beyond the abstract exposure; proving concrete damages from the specific lingering information would be necessary. Third, practically, bringing and sustaining civil litigation against a sitting Senate committee chairman and his staff is an undertaking with few precedents.
A claim against HHS under the Privacy Act's civil remedy provision faces different obstacles: it would require showing that HHS's disclosure to Congress was not authorized under §552a(b)(9). That is a viable but uncertain theory.
Senate Ethics: No Specific Rule Found
Research into HSGAC's published rules of procedure and jurisdictional framework did not surface a specific rule governing the handling, redaction, or protection of personally identifiable information or protected health information obtained through oversight requests.[10] The committee rules address the legislative process and jurisdictional scope, not data handling protocols.
That absence does not mean no rule exists — the Senate Committee on Rules and Administration and the full Senate Rules may contain provisions not surfaced here. However, no documented Senate-wide requirement to redact third-party medical information from publicly released oversight documents was located. The failure to redact may have been an operational oversight without a specific procedural violation to attach to it, even if it was an ethical lapse by ordinary standards of care.
The Case for Paul
Paul's committee was engaged in legitimate, important oversight of a senior public health official whose decisions during the pandemic affected millions. The documents were obtained lawfully from HHS under congressional oversight authority. Fauci's diary, as a record maintained on government servers documenting his official activities as a federal director, was legitimately subject to congressional review. The individuals named in it were referenced in the context of Fauci's official conduct, not as the subjects of a gratuitous privacy invasion. The political target was Fauci; the privacy harm to third parties was an operational failure, not the purpose. Insisting that every set of oversight documents produced to Congress be individually reviewed for third-party PHI before release would impose a burden with no clear legal basis, given that Congress is not subject to HIPAA or the Privacy Act's agency obligations.
Furthermore, the committee did attempt a corrective: files were pulled, partially redacted, and reposted. The incomplete fix reflects careless execution rather than an intent to harm private individuals.
The steelman has real force on the purpose point. Paul's committee was not targeting private individuals; they were collateral in an investigation of a public official. The redaction failure is most accurately characterized as negligence rather than design. That said, negligence that exposes a person's HIV status or rare disease diagnosis to the public is not a minor procedural lapse. The harm is real regardless of intent, and the fix was incomplete.
On the legal question, the steelman's strongest ground is the Speech or Debate Clause applied to the legislative decision to release. Where it weakens is on the distribution mechanism: the careless posting without appropriate review is harder to characterize as a protected legislative judgment.
What to Watch
- Leslie Adelman and the remaining HIV-positive individual. These two are the clearest potential plaintiffs for a civil privacy claim. If either pursues litigation, the central question will be whether posting on paul.senate.gov falls within or outside the "reasonable bounds of the legislative task" under Doe v. McMillan. Watch for any filing in D.C. district court.
- The Fauci contempt proceedings. HSGAC voted on a contempt resolution on August 6, 2026. Whether the Justice Department acts on any referral, and whether the contempt proceedings generate additional document releases with PHI, is the next pressure point on the same underlying conflict.
- Whether HHS faces Privacy Act scrutiny. A Privacy Act complaint to the agency or a civil action in federal court against HHS (not Paul's office) would test whether Fauci's personal diary entries qualified as Privacy Act-protected "records" and whether §552a(b)(9) authorized their disclosure. This is the more legally tractable path than a suit targeting the committee.
- Congressional response. No member has introduced legislation requiring PHI redaction for oversight-obtained documents before public release. If this incident generates political pressure for a formal Senate rule or statute, that would be a structural change worth tracking, as it would also implicitly acknowledge the current gap.
Sources
- Rand Paul's Fauci Diary Dump Exposed People's Medical Histories
- RFK Jr. Says HHS Found Fauci Diaries Across 11 Different Servers
- Rand Paul's Fauci diaries exposed sensitive medical details on 20 individuals: report
- Redacted Fauci Diary Entries Depict Him Personally Helping Katie Miller
- Are You a Covered Entity? — HIPAA Overview
- 5 U.S.C. § 552a — Privacy Act of 1974
- Speech and Debate Clause
- Gravel v. United States (1972)
- Doe v. McMillan, 412 U.S. 306 (1973)
- Jurisdiction and Rules — Senate Homeland Security and Governmental Affairs Committee