HIPAA isn’t really a personal privacy regulation at all ...
Like other privacy regulation, it’s there to protect the industry and their business/commercial interests.
Barriers to access mean less controversy, fewer lawsuits, fewer investigative news stories, fewer insurance disputes.
I’d say it’s also designed to reduce contamination or adulteration of data: if every facility needs to do new testing and new evaluation then they can be sure they got the results they need, instead of taking some rando’s word for it.
HIPAA isn’t the most onerous barrier to personal access to records, but it’s a huge hassle for someone who wants it opened up for family, friends, and other entities because those forms are onerous. With good transparency in patient portals, authorized users can manage a lot on their own.
Also, good luck reading anything but textual notes, because imaging and other medical data is often always distributed in proprietary file formats that don’t simply import into Gimp!