ChatGPT Health privacy comes down to one fact that surprises most people: once you move your medical records out of your doctor's system and into a consumer app, HIPAA generally stops protecting that copy. HIPAA covers hospitals, clinics, insurers and their contractors, not the AI product on your phone. So the honest answer to "is ChatGPT Health safe" is that your data is guarded by OpenAI's own policies, not by the federal law you may assume follows your records everywhere.
That distinction matters because OpenAI launched Health in ChatGPT on July 23, 2026, letting US adults connect their medical records and Apple Health data for personalized health answers. This piece explains what the feature actually does, what HIPAA does and does not cover, what OpenAI has promised about training and ads, the risks that remain, and how to use it without handing over more than you need.
What ChatGPT Health actually does
ChatGPT Health is a feature that lets you connect health information so ChatGPT can answer questions about your own body, not just general medicine. It rolled out on July 23, 2026 to US users who are 18 or older, on web and iOS, across the Free, Go, Plus and Pro plans.
Once connected, it can draw on your medical records, things like lab results, medications and visit notes, and on Apple Health data such as fitness and activity. According to the launch reporting, it can compare lab test data over time, summarize what changed since a prior appointment, track medications, and explore how sleep, activity and workouts relate to your health.
OpenAI says ChatGPT will ask for permission before using connected medical records and Apple Health information to personalize a response. That consent step is useful, but it is a control over how the data is used inside the product, not a promise about who can reach the data later.
What HIPAA covers, and what it does not
HIPAA does not cover ChatGPT. The law applies to "covered entities" and their business associates: hospitals, health plans, physician practices, insurers and the vendors they hire to handle protected health information. A consumer AI app you sign up for yourself is none of those things.
Here is the part that trips people up. While your records sit in your doctor's or hospital's system, HIPAA governs how they are shared and disclosed. The same law gives you the right to get a copy of those records. But once you exercise that right and load the copy into a consumer app, HIPAA's protection does not travel with it. Privacy advocates have flagged this directly: Sara Geoghegan of the Electronic Privacy Information Center warned that moving records into ChatGPT "would remove the HIPAA protection from those records, which is dangerous."
HIPAA protects your records inside the healthcare system. It generally does not protect the copy you move into a consumer app. After that, you are relying on the app's terms, not federal health-privacy law.
This is not a knock specific to ChatGPT. It is true of most consumer health apps, symptom checkers and wellness trackers. The rules that feel like a safety net at the doctor's office simply have a different scope than people expect.
What OpenAI says about training and ads
OpenAI has made specific commitments about health data, and they are worth reading precisely. Per the launch coverage, connected medical records and Apple Health information are not used to train OpenAI's models or target ads, and neither are the conversations that use that health data. OpenAI has also stated more broadly that records shared with ChatGPT will not train its models or target ads.
Read the boundary carefully. There is a difference between a chat where you have connected records and one where you simply type a health question. Reporting notes that a health question typed into an ordinary chat, without invoking connected records, follows your standard model-training setting, the one you control under Settings, then Data Controls. So the strong no-training promise attaches to the connected health feature, not automatically to everything health-related you ever type.
These are policy commitments, and they are meaningful. They are also not the same thing as a legal guarantee. A policy is a promise a company makes and can revise. HIPAA is a law with enforcement and penalties behind it. When your protection is a policy rather than a statute, the questions that matter are: can the policy change, and what happens to your data if it does.
The risks that remain even with good policies
Good privacy policies reduce risk. They do not remove it. Once a copy of your health history lives in a consumer account, a handful of real exposures come with it regardless of what the marketing says.
- Data breach: any company holding data can be breached. A copy of your labs and medications sitting in a consumer account is a target that would not exist if you had never uploaded it.
- Legal process: consumer data can be subject to subpoenas, court orders or law-enforcement requests. HIPAA has its own carve-outs, but data held under consumer terms is reached through a different and often broader door.
- Account access: if someone gets into your account through a weak password, reused credentials or a shared device, they can read whatever health context you connected.
- Future policy change: today's no-training, no-ads commitment is a current promise. Terms can be updated, companies get acquired, and products get retired. What binds the company next year is whatever the terms say then.
- Scope creep on your side: the more you connect, the larger the single place that now holds a map of your health. Convenience and concentration of risk grow together.
None of this means the feature is reckless to use. It means the sensible mental model is data minimization: connect what genuinely helps you and leave out what does not, because every record you add is a record someone else might one day reach.
HIPAA-covered records vs a consumer app copy vs a private-by-design store
The clearest way to see the tradeoff is to line up where your health information can live and what actually governs it in each place.
| What governs it | Records at your provider | Copy in a consumer AI app |
|---|---|---|
| Legal protection | HIPAA applies; covered entity rules and penalties | HIPAA generally does not apply once moved into the app |
| Who can reach it | Provider, its business associates, you | The company, its systems, and whoever legal process or a breach exposes |
| Used for ads or training | No; restricted by law | Per OpenAI's stated policy, connected health data is not used to train models or target ads |
| Your control to delete | Retention set by medical-record law | You can delete in-app; verify what is retained and for how long |
| Main risk | Provider-side breach | Breach, subpoena, account access, future policy change |
The point is not that one column is evil and another is safe. It is that the rules change the moment your data crosses from the healthcare system into a consumer product, and knowing which column you are in tells you how carefully to tread.
How to use ChatGPT Health more safely
You can get value from personalized health answers while keeping your exposure small. The habits below cost nothing and cut most of the avoidable risk.
- Share the specific, skip the sensitive: connect the lab trend or medication list you actually want help with, rather than your entire chart by default.
- Keep your own copy: download and store your records yourself so the app is never the only place your health history exists.
- Check Data Controls: review Settings, then Data Controls, so you know which chats follow your training setting and which are covered by the health feature's stronger commitment.
- Lock the account: use a strong, unique password and turn on two-factor authentication, since account access is one of the most common ways private data leaks.
- Delete when done: if you connected records for a one-time question, remove them afterward and confirm what deletion actually clears.
- Do not treat it as medical advice: use it to understand and organize, then confirm anything that affects treatment with a clinician.
Before you connect anything, ask one question: if this exact data leaked tomorrow, would I regret uploading it? If yes, keep it out and paste only the narrow detail you need help with.
Where your personal context lives is the real question
The instant you connect health data to any AI, a different question becomes urgent: where does my personal context live, and who can reach it. That question is not unique to health. It applies to your documents, receipts, photos, voice notes and messages, the everyday record of your life that a memory app holds.
This is the problem MemX is built around. MemX is a consumer memory app: snap or save something now, ask a plain question later, and get the answer with its source. It is private by architecture, meaning per-user isolation so your data is not pooled with other people's, customer-managed encryption keys, encryption at rest, and no training on your data. The design goal is data minimization and isolation: your context stays yours, reachable by you, not repurposed.
Being scrupulous about what that does and does not mean: MemX is not HIPAA-covered, it is not end-to-end encrypted, and it is not zero-knowledge. Private by architecture is an engineering and data-handling stance, not a legal shield and not medical protection. If you have records that need HIPAA coverage, the safest place for that copy is inside the healthcare system that HIPAA governs. What a private-by-design store offers is a smaller, isolated home for your personal context so fewer parties can reach it in the first place.
The safest health record is the one you did not need to copy. When you must, put it somewhere isolated, keep your own backup, and share only the slice that answers your question.
The bottom line
ChatGPT Health can genuinely help you make sense of labs, medications and activity trends, and OpenAI's stated policy of not training on connected health data or using it for ads is a real commitment. Just be clear-eyed that it is a policy, not HIPAA. Once your records enter a consumer app, federal health-privacy law generally no longer covers that copy, and breach, legal process, account access and future policy changes become risks you carry.
Use it deliberately. Connect narrowly, keep your own copy, lock your account, and delete what you no longer need. Treat every health detail you upload as a detail someone else could one day reach, and share accordingly.
01Is ChatGPT Health HIPAA compliant?
No. HIPAA covers healthcare providers, insurers and their contractors, not consumer AI apps. When you move medical records from your provider into ChatGPT, HIPAA generally stops protecting that copy, and you rely on OpenAI's own terms instead of the law.
02Is my medical data private with ChatGPT?
Only as private as OpenAI's policy makes it. OpenAI states that connected medical records and Apple Health data, and the conversations that use them, are not used to train its models or target ads, and ChatGPT asks permission before using them. That is a company commitment, not HIPAA. Once records leave your provider, federal health-privacy law generally stops protecting that copy, so your privacy rests on OpenAI's terms rather than the law. Note too that a plain health question typed without connected records follows your standard Data Controls training setting.
03When did ChatGPT Health launch and who can use it?
OpenAI launched Health in ChatGPT on July 23, 2026 for US users aged 18 and older, on web and iOS, across the Free, Go, Plus and Pro plans. It lets you connect medical records and Apple Health data for personalized answers.
04What are the real risks of connecting my medical records?
The main ones are data breach, legal process such as subpoenas, someone accessing your account, and future changes to the company's policy. A policy can be revised; a law cannot be revised by the company. Connect only what you need.
05How do I delete my health data from ChatGPT?
You can remove connected records and manage your information in Settings under Data Controls, and disconnect health sources you no longer want linked. After deleting, confirm in the current terms what is retained and for how long, since in-app deletion and full removal are not always identical.
