OpenAI launched Health in ChatGPT to all US users 18 and older this week, letting people connect medical records and Apple Health data to the chatbot, but once that data leaves a patient's provider, HIPAA no longer protects it.

 

What happened

OpenAI rolled out Health in ChatGPT on Thursday, July 23, 2026, to users on the Free, Go, Plus, and Pro plans. The feature lets users upload lab results and medications and connect Apple Health so ChatGPT can access fitness and health data. OpenAI says ChatGPT can then compare new results with prior tests, summarize changes since a user's last appointment, and relate sleep and activity data to a user's routine. OpenAI reports that 300 million people already ask ChatGPT health-related questions every week. The company says physicians helped develop and test health scenarios before release, and that records shared with ChatGPT will not train its models or target ads. Disconnecting a health account triggers deletion of synced data within 30 days, though conversation history persists until a user deletes it manually.

 

The backstory

The 21st Century Cures Act gives patients the right to move their electronic health records into third-party apps, and this right is what allows b.well Connected Health, OpenAI's data connectivity partner, to pull records into ChatGPT. But HIPAA only governs "covered entities" which include hospitals, health plans, and physician practices and their business associates. Consumer AI products do not fall under covered entities. So the same law that lets patients move their data into ChatGPT is also what removes HIPAA's protection from that data. An earlier, smaller pilot of health features ran in January 2026 through a dedicated Health tab, OpenAI found that more than 70% of health-related conversations happened outside that tab, prompting the wider rollout.

 

Going deeper

  • b.well pulls data across several channels at once: Patient Access APIs under the Cures Act (which include unstructured clinical notes), TEFCA's national health network, regional health information exchanges, CMS Blue Button for Medicare, VA records, and pharmacy/lab networks.
  • The network reaches roughly 2.2 million US healthcare providers, plus Apple Health on iOS for wearable and fitness data.
  • Once connected, ChatGPT can draw on medications, lab results, visit notes, sleep, and activity data across any conversation, or users can invoke it directly with @Health.
  • ChatGPT asks permission by default before accessing connected records in a given conversation; users can set it to always-allow or turn it off in Settings.
  • Memory is not created directly from connected medical records, though broader conversation memory can be disabled or avoided with Temporary Chat.
  • OpenAI offers separate HIPAA-eligible products, ChatGPT for Healthcare and ChatGPT Enterprise with Regulated Workspace, for clinical and enterprise settings, but the consumer Health feature is not one of them.
  • b.well also supplies data infrastructure to Google's health AI work, Samsung's "Kill the Clipboard" initiative, and Perplexity Health.

What was said

OpenAI described the feature's purpose in its Thursday release, "With your permission, ChatGPT can now draw on relevant information you've connected in Health to help you compare a new result with prior tests, summarize changes since your last appointment, or explore how sleep, activity, and workouts relate to your routine." OpenAI also said Health "does not replace the care and judgment of qualified medical professionals."

Sara Geoghegan, senior counsel at the Electronic Privacy Information Center, said sharing electronic medical records with ChatGPT Health "would remove the HIPAA protection from those records, which is dangerous." She added that OpenAI "is only bound by its own disclosures and promises, so without any meaningful limitation on that, like regulation or a law, ChatGPT can change the terms of its service at any time.

 

In the know

HIPAA protection is jurisdictional, not technical, it attaches to the entity holding data, not the data itself. Once a patient exercises their Cures Act right to move records into a third-party app, the records exit HIPAA's jurisdiction because HIPAA only binds covered entities like hospitals and insurers, not the consumer apps receiving the data. No setting inside ChatGPT can restore that protection once the transfer happens; only a HIPAA-covered arrangement, like OpenAI's separate enterprise products, keeps records inside HIPAA's reach.

 

Why it matters

Every one of the 300 million people asking ChatGPT health questions weekly can now feed it real medical records, and the instant they do, those records fall outside the legal framework built to protect medical privacy. What replaces it is a company's own terms of service, promises that are real today but, as Geoghegan noted, changeable at any time without regulatory approval. That gap matters most for the people with reproductive health history, mental health records, or diagnoses carrying social or professional risk. Since b.well's infrastructure now also feeds Google, Samsung, and Perplexity's health products, this isn't a single-company decision, it's becoming the default architecture for how consumer AI touches medical data industry-wide.

 

The bottom line

Patients who connect their records are relying on a company's voluntary word, not federal law, to keep that data safe. Anyone weighing that tradeoff should understand it's permanent from the moment the data moves, regardless of what settings they choose afterward.

 

FAQs

Are all health apps required to follow HIPAA?

No, HIPAA only applies to covered entities and their business associates.

 

Does any law protect health data once it's outside HIPAA's reach?

State consumer privacy laws and general FTC consumer protection authority can still apply, but these protections differ and are less strict than HIPAA's federal standards.

 

Can a company change its privacy policy after data has already been shared?

Generally yes, since privacy policies and terms of service are not fixed contracts and companies can revise them, subject to whatever legal limits apply in their jurisdiction.

 

What happens to health data if a company is acquired or goes bankrupt?

Data held by a company that is acquired or enters bankruptcy can become an asset that transfers to a new owner, potentially under different privacy commitments than the original.