> in any case, HIPAA will protect you
It protects you insofar as it disincentives honest actors from doing sketchy things with your data. It's punishment for orgs, not protection for patients, like how laws against murder punishes the murderer rather than protecting the victim.
The best thing a patient can do to protect their privacy is to be actively avoid of medical practitioners that, for example, use tools like this which send your private medical consultation transcripts to God-knows-where.