ChatGPT Health went live for all US users on July 23, 2026, letting anyone connect Apple Health data and hospital records directly to the AI chatbot. The moment they do, those records lose their federal privacy protections.
The product is genuinely useful. Connect your Apple Health data, your records from Epic or Oracle Health systems, your One Medical visits, your Function Health labs, and ChatGPT can pull it all into context without you having to paste a thing. Ask about your last blood panel, and it will compare it to the one before. Ask how your sleep is tracking against your workout load, and it has the numbers. OpenAI says none of this is used to train its models or serve you ads. The feature rolled out July 23 to all logged-in US users aged 18 and older, Free through Pro, on web and iOS, after a January pilot that went badly enough to require a full relaunch.
But here's what the product page doesn't lead with: the moment you upload those records to ChatGPT, they stop being HIPAA-protected data. Permanently.
HIPAA applies to covered entities, meaning hospitals, insurers, and their business associates. OpenAI is none of those things. As Sara Geoghegan, senior counsel at the Electronic Privacy Information Center, told The Record, sharing your electronic medical records with ChatGPT Health "would remove the HIPAA protection from those records, which is dangerous." The data becomes governed entirely by OpenAI's terms of service, which the company can update at any time. Your hospital cannot sell your diagnosis to an advertiser. OpenAI, operating outside HIPAA, faces no such federal constraint today. And unlike medical records held by your provider, data shared with ChatGPT can potentially be subpoenaed in civil litigation with far fewer procedural hurdles.
This is not a fringe concern from privacy advocates who distrust all technology. The US has no comprehensive consumer privacy law. There is no federal backstop protecting health data once it leaves a HIPAA-covered institution and lands with a consumer tech company. OpenAI's promise not to train on your records is a contractual commitment, not a legal one. Those are different things, and anyone who has watched a tech company revise its terms knows the difference matters.
According to reporting by The Record, b.well, the health data connectivity startup, powers ChatGPT Health's medical record pipeline. That same company powers Google's health AI efforts (signed October 2025) and Perplexity Health (March 2026). So when you authorize ChatGPT to pull your hospital records, you're also handing an intermediary company your medical history. OpenAI gets named in the product; b.well gets the data relationship.
What this means for the health data stack #
For the founders and investors building in digital health, the competitive picture shifted overnight. OpenAI didn't build an app, a portal, or a dashboard. It inserted itself as an ambient layer inside the most-used AI product in the country. Every EHR incumbent, from Epic to Oracle Health, now has its data flowing into a conversation interface it doesn't control. Every healthtech startup that has spent years building patient-facing record retrieval has just been undercut by a feature bundled into a free tier. Epic's position here is genuinely awkward. Its hospital customers are the very source that makes ChatGPT Health useful. But Epic has spent decades building MyChart as the canonical way patients engage with their own records, and ChatGPT is now a credible replacement for that interface. Epic doesn't have a seat at that table. Neither do the dozens of startups that raised money to solve exactly this problem.
Frankly, the regulatory gray zone is where this gets most dangerous for founders pricing risk into their roadmaps. OpenAI has effectively launched a product that sits in a gap the current legal framework wasn't designed for. HIPAA was written for a world where health data stayed inside the healthcare system. ChatGPT Health is a consumer product that pulls clinical records into a general-purpose AI assistant, and no federal agency currently has clear authority to regulate what OpenAI does with that data. The FTC can act on deceptive practices, but that requires OpenAI to break its own stated promises, which it hasn't done. State privacy laws vary widely. The gap is real and, for now, intentionally unaddressed.
OpenAI will argue, correctly, that users consent to this. Every connection requires explicit permission, and users can delete their data. That consent framework is real. But consent in an asymmetric information environment is doing a lot of work. Most users connecting their Apple Health data to ChatGPT don't know they're stepping outside federal health privacy law. They see a useful feature from a company they already trust with their conversations. They tap connect.
The product launched. The data is flowing. Congress hasn't acted on a consumer privacy law in decades. That's where things stand.
Also read: An AI data center that promised to spare the Colorado River is now suing for 260 million gallons a year • Nearly 200 startups tell Washington that banning Chinese AI models would hand OpenAI and Anthropic a monopoly • Uncle Bob Martin says he no longer reads AI-generated code and the developer world is split