Here is the verdict: the ChatGPT Health privacy story is stronger than the alarmed headlines suggest. If you connect medical records to ChatGPT, OpenAI keeps that data out of model training and ad targeting, adds extra encryption, and lets you disconnect a source and have the synced data deleted within 30 days. But a general-purpose chatbot holding your lab results is still a different decision from a purpose-built store, and a health detail in your chat history is permanent by default: disconnecting the source does not remove it, only deleting the chat does.
The week of July 23, 2026, OpenAI opened Health in ChatGPT to all logged-in US users 18 and older, on Free, Go, Plus, and Pro plans, on web and iOS. The feature lets you connect Apple Health and health records from providers on Epic and Oracle Health systems, plus apps including Function, MyFitnessPal, and One Medical, so ChatGPT can answer questions using your medications, lab results, recent visits, sleep, and activity.
What is ChatGPT Health, and what did OpenAI launch on July 23, 2026?
ChatGPT Health is a feature that lets you connect Apple Health, Epic and Oracle Health medical records, and apps like Function and One Medical so ChatGPT can answer questions using your labs, medications, and visits. On July 23, 2026, OpenAI made it a nationwide US feature rather than a limited pilot. Any logged-in US adult on a Free, Go, Plus, or Pro plan can now turn it on through the web or the iOS app. There was no Android timeline in the announcement.
The point of the feature is connection. Instead of pasting numbers from a lab printout, you link a source once and ChatGPT can pull that information into any conversation. The same connected sources, from Apple Health to Epic and Oracle records, let ChatGPT compare a new lab result against your past baselines, summarize what changed since your last visit, and relate sleep and activity to how you feel.
OpenAI is clear that this is not a doctor. The company says the feature is not intended for diagnosing or treating any condition and that users should verify information and make medical decisions with a professional. That caution is not boilerplate: the rollout landed the same week a former Florida pastor sued OpenAI, alleging ChatGPT discouraged him from seeking care before a massive pulmonary embolism. The lesson for privacy is the same as the lesson for safety. Read the fine print and keep a human in the loop.
What OpenAI says it does to protect your health data
OpenAI built specific protections around Health data. These are the company's own commitments, taken directly from its help documentation:
- Excluded from model training: connected medical records, Apple Health information, and the conversations that use them are not used to train OpenAI's foundation models, regardless of the training setting on your account.
- Excluded from ads: that same connected health data is kept out of ad targeting, again independent of your model-training setting.
- Extra encryption: all ChatGPT chats are encrypted in transit and at rest, and information connected in Health receives additional encryption on top of that baseline.
- Deletion on disconnect: when you disconnect a source, the data synced from it is deleted from OpenAI's systems within 30 days.
- Permission before personalizing: by default, ChatGPT asks permission before using connected records to personalize a response, and you can approve each time or choose to always allow.
The one detail that trips people up: disconnecting a source deletes the imported data within 30 days, but anything ChatGPT already wrote into a conversation stays in that chat until you delete the chat itself. Deletion of the source is not deletion of your history.
The training and ad carve-outs are the notable ones: they hold regardless of the setting you picked elsewhere in your account, which removes a common way people opt themselves in by accident. OpenAI has done real work here, and the open questions are about product category and long-term trust, not a single missing safeguard.
Where your health data can end up: three paths compared
Your health data can take one of three paths: a record you formally connect through Health, a detail you type into an ordinary chat, or a purpose-built store, and each is governed by different rules. The safest way to reason about this is to stop asking whether ChatGPT is good or bad and start asking which path your data takes. A record you formally connect through Health is governed by the Health rules above. A sentence you type into an ordinary chat is not. And a purpose-built store is a different product built for a different job. Here is how the three compare on the questions that matter.
| What happens to it | Connected record in ChatGPT Health | Health detail typed into a normal chat | Purpose-built store (e.g. MemX) |
|---|---|---|---|
| Model training | Excluded from foundation-model training, regardless of your training setting | Follows your standard Data Controls setting; can be used for training unless you opt out | MemX states content is never used to train AI models |
| Ad targeting | Kept out of ad targeting | Governed by general product terms, not the Health carve-out | Not an ad-supported product |
| Encryption | Extra encryption on top of in-transit and at-rest | Standard encryption in transit and at rest | Encryption at rest with customer-managed keys and per-user data isolation |
| Deleting the data | Disconnect a source and synced data is deleted within 30 days, but text already in your chat history stays until you delete the chat | Stays in your chat history until you delete that conversation | You delete documents you added, and can export everything anytime |
| HIPAA | Not HIPAA-covered once records land in a consumer app you use directly | Not HIPAA-covered | Not HIPAA-covered; privacy comes from architecture, not from that statute |
Is typing health info into ChatGPT the same as connecting a record?
No: connecting a record and typing a health detail into a chat are governed by different rules. The Health protections attach to data you formally connect through the Health section. When you paste a symptom, a diagnosis, or a medication into a regular ChatGPT conversation, that text follows your ordinary account settings, not the Health carve-out, and it becomes part of your chat history like any other message.
This is the trap: typing feels safer than connecting, and it is the reverse. Connecting a record is a deliberate, revocable act with a deletion path. Typing a health detail into a chat is casual, easy to forget, and sticky: it lives in that conversation until you go back and delete it. Privacy researchers quoted around the launch put it plainly, advising people to assume that anything uploaded into these tools will not stay private, and to treat trust in OpenAI's word as the real variable.
None of this makes ChatGPT reckless. It makes ChatGPT a general assistant that now has a specialized, better-protected lane for health. The mistake is assuming the whole product behaves like that lane. It does not, and the difference is invisible in the moment you are typing, which is exactly when it matters most.
Is ChatGPT Health HIPAA-covered? That is often the wrong question
For a consumer using ChatGPT Health directly, HIPAA in almost every case does not apply, and that is not the scandal it sounds like. HIPAA governs healthcare providers, insurers, and their business associates. When you exercise your legal right to send your own records to a personal app of your choosing, the data leaves HIPAA's jurisdiction by design, and its handling is then governed by the app's terms and applicable state privacy law.
As one biomedical informatics professor framed it, once you hand data to a company that is not delivering healthcare, the relationship becomes a contract between you and that company, and it is buyer beware. So chasing a HIPAA badge on a direct-to-consumer tool misreads the situation. The better questions are concrete: What does this company do with health data by default? Can I delete it and get it out? Is this the right place for the document at all?
Judged by those questions, ChatGPT Health answers well on defaults and deletion. Where a careful person still hesitates is category: a chat product optimized for conversation and engagement is holding the most sensitive records you own, and its incentives can shift over years in ways a HIPAA form would never capture.
Is it safe to connect medical records to ChatGPT? A checklist before you connect
It is reasonably safe if you connect deliberately and keep a few habits, listed below.
- Connect deliberately rather than typing sensitive details into random chats, so your health data stays in the better-protected lane.
- Keep the permission prompt on instead of choosing always allow, so you see each time ChatGPT reaches for your records.
- Remember that disconnecting a source starts a 30-day deletion of synced data but does not clean your chat history, so delete health conversations you no longer want.
- Decide per document: connecting live activity data is a different risk from parking a lifetime of lab reports and scans in a chat product.
- Keep the professional in the loop, because the tool itself says it is not for diagnosis or treatment.
Before connecting anything, open Settings and read where the Health controls live, including the permission toggle and the disconnect option. Knowing how to turn it off is the fastest way to feel comfortable turning it on.
Keeping your own health documents private and findable
Reasoning about your health and storing the actual documents are two different jobs: the lab report PDF, the photographed prescription, the scan, the discharge summary. That storage job is where MemX fits. You save a photo or PDF, MemX runs OCR to read the text inside it, indexes it, and later answers a plain-English question like what was my vitamin D level in March with the answer cited back to the exact source document.
MemX is private by architecture: per-user data isolation, customer-managed encryption keys, encryption at rest, on-device capture, and a promise that your content is never used to train AI models, with full export whenever you want it. That is not the same claim as end-to-end encryption, and MemX does not make that claim. The practical value is narrower and honest: a searchable, private store for the health paperwork you want to keep, separate from a general chatbot, with every answer pointing back to the document it came from.
01Is ChatGPT Health private?
Data you connect through Health is excluded from model training and ad targeting, gets extra encryption, and can be deleted by disconnecting the source within 30 days. Health details you simply type into a normal chat do not get those protections and stay in your chat history until you delete the conversation.
02Does connecting my medical records to ChatGPT train the AI?
No. OpenAI states that connected medical records, Apple Health information, and the conversations that use them are excluded from foundation-model training, regardless of your account's training setting. Ordinary chats without connected Health data follow your standard Data Controls setting.
03Is ChatGPT Health HIPAA-compliant?
For a consumer using it directly, HIPAA generally does not apply. Sending your own records to a personal app moves them outside HIPAA's scope, and OpenAI's terms and state privacy law govern instead. For a direct-to-consumer tool, HIPAA coverage is often the wrong thing to look for.
04What happens if I disconnect a health source?
OpenAI deletes the data synced from that source within 30 days. Important caveat: anything ChatGPT already wrote into a conversation stays in your chat history until you delete that chat. Disconnecting the source and clearing your history are two separate steps.
05Where should I store my actual lab reports and prescriptions?
Keep the documents in a private store built for it, separate from a general chatbot. MemX saves your PDFs and photos, reads the text with OCR, and answers questions with a citation to the source file. It is private by architecture, not end-to-end encrypted, with full export anytime.
