I understand that businesses can ask customers to provide “proof of vaccination”, by showing a vaccination card.  However, it is my further understanding that C19 vaccination records are “private health records”.  So my question is: Can a business like a gym access customer vaccination records without the customer’s permission to “confirm” that customer has actually been vaccinated?

Seems like the answer is “no” under HIPAA – but I know very little about HIPAA and haven’t seen any legal articles specifically on this.

The articles out there mainly deal with the headline issue of employers being able to ask employees for vaccination proof.  In that case – it is my understanding the employees would still have to give written permission to employers to access their records, just like they would a credit report.  Accessing a person’s credit report w/o their permission is a violation of federal law, under the Fair Debt Collection Practices Act.