TL;DR
OpenAI's new "Health in ChatGPT" feature allows users to upload and share medical records directly within the AI platform, but health privacy experts warn that current data protections may not be sufficient for sensitive health information under existing regulations. The launch matters right now because it opens a major new front in the debate over how AI companies handle protected health data, with implications for millions of potential users.
What Happened
OpenAI announced on July 25, 2026, the launch of "Health in ChatGPT", a dedicated space within its flagship product that lets users upload, store, and discuss their medical records directly with the AI. The feature, reported by CBS News, promises to help patients understand lab results, summarize clinical notes, and track health conditions — but health and AI experts immediately flagged significant privacy, accuracy, and regulatory concerns.
Key Facts
- OpenAI launched "Health in ChatGPT" on July 25, 2026, creating a separate, labeled section for users to upload and store medical records within the existing ChatGPT interface.
- The feature allows users to ask the AI to summarize medical reports, explain lab values in plain language, and track changes in health data over time.
- Health and AI experts cited by CBS News highlighted that medical records contain Protected Health Information (PHI) under U.S. federal law, which carries specific data handling requirements under HIPAA.
- OpenAI has not publicly stated whether "Health in ChatGPT" complies with HIPAA data security and privacy rules, which generally require entities handling PHI to implement strict access controls and breach notification procedures.
- Existing privacy policies for ChatGPT allow OpenAI to use data submitted by users to train its models — a practice experts say creates an unacceptable risk for sensitive medical information.
- AI error rates in summarizing complex medical information remain a concern, with studies showing even advanced models can misinterpret lab values or miss critical context.
- The CBS News report noted that competing technology firms, including Google and Microsoft, have already established HIPAA-compliant versions of their AI tools for healthcare enterprise use, raising questions about OpenAI's consumer-facing approach.
Breaking It Down
"Health in ChatGPT" represents a significant departure from previous consumer AI health tools. Prior offerings from major tech companies — such as Google's Med-PaLM or Microsoft's Nuance-powered clinical AI — were designed for healthcare providers in regulated environments. OpenAI's decision to bring medical record analysis directly to consumers skirts the complex web of healthcare regulations and instead positions the feature as a utility for personal understanding, not clinical decision-making. That distinction matters because regulations like HIPAA apply based on the entity and purpose of data use, not the tool itself.
The core tension lies in the fact that OpenAI has not committed to treating medical records differently from other user data under its current terms of service — meaning anything you upload could potentially be used to train future versions of GPT.
Without a clear, legally binding commitment to either delete uploaded medical records from training datasets or apply HIPAA-level encryption and access controls, users who share their health data are effectively consenting to its use in ways they may not fully understand. The CBS News report noted that health privacy advocates are particularly concerned about inference risks — the possibility that AI models could reconstruct identifiable health information from aggregated training data, even if direct identifiers are removed.
The feature's practical utility should also be scrutinized. While ChatGPT can indeed summarize a lab report or explain a diagnosis in simpler language, medical records contain nuanced information — contextual clues about disease severity, medication interactions, and patient history — that current AI models are known to misinterpret. A 2024 Stanford study found that leading large language models produced clinically significant errors in up to 15% of medical summarization tasks, and those errors