ChatGPT Health Launches for US Users: HIPAA Doesn't Apply Here | The Classroom
Explore state by state cost analysis of US colleges in an interactive article

ChatGPT Health Launches for US Users: HIPAA Doesn't Apply Here

Jul 24, 2026
6 minute read

ChatGPT Health Launches for US Users: HIPAA Doesn't Apply Here

OpenAI this week rolled out Health in ChatGPT to all logged-in US users aged 18 and older across Free, Go, Plus, and Pro plans on web and iOS. The ChatGPT Health launch for US users means anyone with a supported account can now choose to connect Apple Health data and medical records from select hospital systems, allowing ChatGPT to draw on that information when answering health questions. The privacy protections governing what happens next are company policy, not federal law and outside experts say no regulatory framework currently fills that gap.

More than 300 million people ask ChatGPT health-related questions each week, up from 230 million when limited testing began in January, TechCrunch reported this week. The feature is opt-in: by default, ChatGPT asks for permission before drawing on connected records in any given conversation, OpenAI confirmed. What it is not, however, is covered by HIPAA.

What the ChatGPT Apple Health integration and medical records support actually does

Users can connect Apple Health, medical records from Epic and Oracle Health hospital systems, One Medical, and Function Health. Once connected, ChatGPT can consider medications, lab results, recent clinical visits, sleep, and activity data alongside whatever else a user shares in conversation. Users can also invoke health context explicitly by typing "@Health" anywhere in the app, per OpenAI.

That design choice embedding health context across all conversations rather than confining it to a dedicated hub came directly from testing data. During the earlier limited rollout, more than 70% of health-related conversations happened outside the dedicated Health hub, OpenAI noted. So the hub became optional; the context travels with the user.

After connecting, users can review synced conditions and medications, remove anything outdated, and add details the records don't capture, including family health history. OpenAI warns that connected data may not always be current: a medication can remain listed well after a patient stops taking it, according to OpenAI. Responses built on stale records carry that staleness forward.

Advertisement

The use cases OpenAI describes are concrete and practical: comparing a new lab result against a prior baseline, summarizing what changed since the last appointment, understanding how sleep tracks against activity levels. That framing appointment preparation, record comprehension, better-informed conversations with clinicians is where the tool has a plausible case for genuine value. It works poorly as a substitute for clinical judgment on symptoms, a distinction that matters a great deal given what follows.

On benchmarks, OpenAI reports every GPT-5.6 model outperformed GPT-5.5 on HealthBench Professional, and that physicians tested the feature before release, per the launch announcement. HealthBench is a benchmark OpenAI developed itself, not a third-party standard. No peer-reviewed research on real-world medical record interpretation was published alongside the launch. Harvard Law School professor I. Glenn Cohen noted in a paper published nine days ago that no studies yet exist on the specific scenario this feature enables: a user connects their full medical record and receives a personalized AI-generated response, per Harvard Law School. The product is available before the evidence is.

What OpenAI promises on privacy and where the protections end

OpenAI's commitments are specific. Connected records and Apple Health data are not used to train its foundation models or to target advertising. Health data receives additional encryption beyond what applies to standard conversations. Disconnecting a source triggers deletion of synced data from OpenAI's systems within 30 days, per the launch announcement. Users who want to avoid memory creation entirely can use Temporary Chat.

One detail most users will miss: any health information already pulled into a conversation stays in that conversation's history until the user manually deletes it, OpenAI confirmed. Disconnecting a data source does not scrub prior exchanges.

The more consequential limitation is legal, not technical. HIPAA applies to hospitals, insurers, and their direct business partners. When a user exports records from a covered hospital system into a consumer chatbot, those records leave the HIPAA framework because AI chatbot companies are not covered entities under the statute. Cohen, writing with co-authors Ifeoma Ajunwa and Ravi B. Parikh in JAMA, explained the mechanism: the user is the one moving the information to a third party, which means federal medical privacy law no longer governs what happens to it, per Harvard Law School. The Journal of Medical Internet Research reached the same conclusion in an analysis published last month.

Advertisement

In practice, once records move into a consumer chatbot, a user's rights are governed by the company's terms of service and general consumer law. Cohen pointed to 23andMe's attempt to apply retroactive changes to its terms governing genetic data as a useful illustration of how that can go, per Harvard Law School. OpenAI's current terms are more explicit than many consumer apps. They can also change.

Cohen flagged a second risk that is harder to see from the outside. Clinical records carry biased documentation. A triage note that labels an undertreated patient as "drug-seeking" gets fed directly into AI responses without the contextual judgment a clinician would apply. LLMs, Cohen's group argued, can carry existing disparities forward rather than correct for them, per Harvard Law School.

Who regulates this and what happens when something goes wrong

About one in four Americans already uses an AI chatbot for medical advice, according to survey data cited by Harvard Law School. No federal agency currently exercises meaningful oversight over consumer health chatbots at that scale.

Harvard's Petrie-Flom Center argued two months ago that health AI chatbots meet the statutory definition of a medical device under the Federal Food, Drug, and Cosmetic Act and should fall under FDA jurisdiction. The FDA has not acted on that basis, per the Petrie-Flom Center. That is an advocacy position, not settled law but the regulatory absence it describes is real.

State legislatures have moved to fill the gap. More than 200 AI-related statutes exist across 48 states, many taking effect this year. A December 2025 executive order directed the Justice Department to challenge state AI laws deemed burdensome to innovation, adding uncertainty about where durable consumer protections will actually come from, per Petrie-Flom.

The lawsuit filed the day before OpenAI's rollout sharpens all of this. A Florida pastor alleged ChatGPT advised him against seeing a doctor, with nearly fatal results, per TechCrunch. OpenAI's terms describe its service as "not intended for diagnosis or treatment." The lawsuit is a reminder that disclaimers and user behavior are different things. When a tool is capable enough and personalized enough, people treat it like clinical guidance regardless of what the fine print says.

What to know before connecting your records

The case for ChatGPT Health is not hard to make. US primary care is expensive and scarce, and a tool that can explain lab results or help a patient arrive at an appointment with better questions has genuine utility. Cohen frames the strongest version: AI as an adjunct to the physician, helping users engage more effectively with their own care rather than replacing the visit, per Harvard Law School.

Advertisement

That framing also sets the boundary. Use the tool to understand terminology, track changes across visits, and prepare for appointments. Don't use it to decide whether symptoms are serious enough to warrant care. Verify specific details, especially medications and dosing, against original source records OpenAI's own guidance says as much, per the launch announcement.

Before connecting records, users should be clear on what they are agreeing to. OpenAI's controls permission-based data use, no ad targeting, 30-day deletion after disconnecting are more explicit than most consumer apps. They are still policy, not law. Any health information already pulled into a conversation stays in that history until manually deleted. No independent research yet exists on how accurately the system handles full, real-world medical records, per Harvard Law School.

The question this launch puts on the table, without answering it, is the accountability question: when a consumer AI health tool operating on actual clinical records gives wrong advice at scale, who is responsible? Neither HIPAA, nor the FDA, nor any framework with real enforcement authority currently provides a clear answer, per JMIR and Petrie-Flom. That gap predates OpenAI. Scaling Health in ChatGPT to hundreds of millions of users makes it harder to ignore.

Sponsored
The Classroom Logo

The Classroom provides honest, relatable, step-by-step guidance for high schoolers applying to college and first-time undergraduate students.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.