On July 23, OpenAI rolled out ChatGPT Health to all US users over 18, free tier included (MacRumors). Users can now connect their electronic medical records directly: through a partnership with the aggregation platform b.well, the integration reaches Epic, Oracle Health, and other major EHR systems, across a network b.well says covers about 2.2 million providers (Fierce Healthcare, TechCrunch). Add Apple Health and MyFitnessPal, and ChatGPT can now answer questions against your actual lab results, medication list, and sleep data.

Let me state the central fact up front: as long as OpenAI doesn’t fall within the set of entities HIPAA regulates — and on the public record it doesn’t, more on that below — this entire pipeline violates not one provision of HIPAA.

That’s not because OpenAI found a loophole. My first project in Responsible AI was a collaboration with Nuance, the healthcare AI company, building hallucination detection for automated summaries of doctor-patient conversations. In this field, “compliant” and “protected” get used as synonyms all the time. ChatGPT Health is the cleanest case study I’ve seen for why they’re different words: a product can be compliant end to end while your medical records sit outside the dedicated privacy statute the whole way through.

The gap wasn’t exploited. It’s how the law is built

The common mental model of HIPAA is that it protects a category of data — “health information.” It doesn’t. It regulates a list of entities: healthcare providers, health plans, and clearinghouses (covered entities), plus the contractors that handle data on their behalf (business associates). A company that isn’t on the list and isn’t processing data for someone on the list can hold the exact same medical record free of HIPAA obligations. The Center for Democracy and Technology put it plainly in its comments on this launch: AI companies are typically not covered by HIPAA at all (Fierce Healthcare).

The more consequential piece is the exit ramp. HIPAA grants patients a right of access: you can direct your hospital to send your records to any third-party app you choose, and the hospital generally cannot refuse. HHS’s 2019 guidance draws the liability line explicitly: once records are delivered to an app the patient selected — one not provided by the covered entity — the hospital bears no responsibility for what the app does with them, and HIPAA imposes no restrictions on the recipient’s use or disclosure.

So the protection isn’t being circumvented. It terminates, by design, at the handoff. The hospital can’t block the transfer — deliberately obstructing it could itself violate the information blocking rules. The moment your records cross that API boundary, the regime switches from “a dedicated statute, a federal enforcement agency, and statutory patient rights” to “whatever the terms of service say.” The far side isn’t lawless — FTC authority and some state laws still apply, as I’ll get to — but the purpose-built medical privacy architecture stops there.

When promises replace law, what exactly is missing?

OpenAI’s privacy commitments are not vague. Connected records and Apple Health data, and the conversations that use them, are not used to train foundation models and not used for ad targeting; health data gets additional encryption and isolation; by default ChatGPT asks permission before each access to your records (users can switch to “always allow”); disconnecting triggers deletion within 30 days (MacRumors, Glitchwire). I don’t doubt the sincerity. The comparison worth making isn’t about intent — it’s about what a promise and a statute do differently as constraint mechanisms. Three concrete places to look.

First, the isolation promise and the product direction are pulling in opposite directions. OpenAI’s own disclosure: during the January pilot, more than 70% of health conversations happened outside the dedicated Health space — users asked about allergies while planning meals, mentioned dietary restrictions while looking up recipes (Glitchwire). The headline feature of the July redesign is precisely that health context can now, with user authorization, flow into everyday conversations rather than staying quarantined. That’s a sensible product call. But it means the wall implied by “health data is isolated from other conversations” is the very wall the product is dismantling. Once a lab result has entered ordinary conversations as context, and related content has settled into cross-conversation memory via health chats (OpenAI says memories aren’t created directly from connected records, but can be generated from health conversations), “disconnect and delete within 30 days” removes the source. How the derived traces scattered elsewhere get cleaned up, the public materials don’t say.

Second, the deletion promise yields to legal process. This isn’t hypothetical. In the 2025 New York Times copyright litigation, a court ordered OpenAI to preserve all user chat logs — including ones users had deleted. OpenAI objected publicly, but had to comply until the order was narrowed. That case had nothing to do with health; the mechanical lesson transfers directly. Chat logs are, legally, ordinary business records — subject to litigation holds and discovery. While your records sit with a hospital, HIPAA has specific rules and minimization requirements for disclosures in judicial proceedings. The same content in a chat history is just another pile of electronic evidence. “We will delete your data” always carries an implicit footnote: unless a court says otherwise.

Third, the advertising promise has a precedent, and the precedent ended badly. OpenAI is exploring advertising revenue, which is why experts are warning that the separation between health data and any ad system must remain airtight (Fierce Healthcare). OpenAI’s current ads documentation does list personal health among the sensitive contexts where ads won’t appear — but that, too, is a product policy that can be revised. And “promised not to use health data for ads, then did” has a case on file: prescription discount platform GoodRx assured users their health information wouldn’t be shared, then sent medication data to Facebook and other ad platforms. In 2023 the FTC fined it $1.5 million under the Health Breach Notification Rule — the rule’s first enforcement action in the fourteen years it had been on the books. That is the enforcement landscape outside HIPAA: the FTC polices deception and unfairness under the FTC Act and requires after-the-fact notification under the breach rule. It punishes retroactively; it doesn’t prescribe, as HIPAA does, what you may do with the data in the first place. And terms of service can be amended unilaterally — today’s promise doesn’t bind tomorrow’s version.

One contrast worth filing away: this launch covers US users only, records integration is limited to US health systems, and the EEA, Switzerland, and the UK are explicitly excluded (Fierce Healthcare). Europe’s GDPR takes the opposite architectural approach from HIPAA: it protects by data category. Health data is special category personal data, and whoever ends up processing it inherits the corresponding legal obligations. The protection follows the data wherever it goes. HIPAA watches institutions; GDPR watches data. The regulatory gap ChatGPT Health exposes is a product of the first architecture.

The same data on the inside of HIPAA: the Nuance precedent

Nuance, which I mentioned at the top, happens to sit on the other side of exactly this boundary, and its track record deserves its own section. The company spent decades in medical speech: Dragon Medical for clinician dictation, eScription for medical transcription, and its flagship DAX Copilot, which records doctor-patient conversations in the exam room, drafts the clinical note automatically, and embeds directly into Epic (official press release) — the hallucination detection work I contributed to served this product line. Since 2022 Nuance has been a subsidiary of Microsoft, my employer; everything in this section comes from public reporting and public filings.

By the data it handles, Nuance overlaps heavily with ChatGPT Health: medical records, lab results, every word spoken between doctor and patient. By legal position, the two sit on opposite sides of the HIPAA line. Nuance sells to hospitals, which makes it a business associate of covered entities — it signs business associate agreements and carries HIPAA’s statutory obligations at every step of data handling. ChatGPT Health faces the patient directly and receives the same data through the right of access — the hospitals and EHR systems upstream stay inside HIPAA, but the moment the data reaches OpenAI, HIPAA stops following it. Which makes Nuance a ready-made reference case: park the same data on the most heavily regulated side of the line, and see what happens — and what the aftermath looks like.

The answer is that things went wrong anyway — three major incidents in a decade. In 2017, NotPetya (the malware that tore through global enterprises that year) breached Nuance’s network and took eScription, the flagship transcription platform, down for weeks; hospitals reverted to pen and paper. Healthcare IT News put the cumulative financial impact at about $98 million; Nuance’s SEC 10-Q breaks that into roughly $68 million in lost revenue plus about $24 million in remediation-related costs. In 2023, the zero-day in MOVEit, a third-party file transfer tool, swept Nuance up along with hundreds of other companies; data on about 1.22 million people was exposed, and the class action settled for $8.5 million (HIPAA Journal). The same year, a former employee — terminated two days earlier — went back in and stole information on roughly 1.2 million patients of Nuance’s client Geisinger; the two companies jointly paid $5 million to settle (TechTarget). Three incidents, three distinct failure modes — external attack, supply chain, insider — and in the public record, none was attributed by regulators to a HIPAA violation. As far as the known facts go, Nuance was operating in compliance when it got breached. This essay keeps repeating that compliance is not protection; the proposition holds on the inside of HIPAA too.

The real difference between the two sides shows up after the breach. The MOVEit and Geisinger incidents both triggered HIPAA’s statutory breach notification obligations (NotPetya mainly caused outages; public reporting doesn’t show it being classified as a notifiable patient-data breach): how many people were affected, when to notify, whom to notify — all backstopped by federal rules. HIPAA itself gives patients no private right of action; the class actions proceeded on state-law claims. But it was the notification machinery that told patients something had happened at all — both settlements came after notification. Outside HIPAA, that machinery thins out to the FTC’s Health Breach Notification Rule (whose coverage of health apps was only clarified in the 2024 update), a handful of state health data laws, and after-the-fact consumer class actions. Not no recourse — but thinner, slower, and with far less precedent.

Three lessons transfer directly to ChatGPT Health. First, don’t ask whether an incident will happen; ask what you’ll hold in your hands afterward. Nuance ran under the full weight of HIPAA obligations and still had three major incidents in ten years. Expecting OpenAI to engineer its way to zero is unrealistic; the real variable is what cards the patient has after the fact. Second, count the hands in the chain. MOVEit became the breach point precisely because it was a link users had never heard of. ChatGPT Health’s chain likewise runs through aggregation intermediaries like b.well — you see ChatGPT’s interface; the data passes through more parties than that. Third, consent only counts if it survives word-by-word scrutiny in court. Exam-room recording as a product category is now drawing eavesdropping class actions: in November 2025, Sharp HealthCare, which uses the AI transcription tool Abridge, was sued for allegedly recording patients without explicit consent (KPBS); in April 2026, Sutter Health and MemorialCare, which also deployed Abridge, were sued as well (TechTarget) — in both cases the defendants are the health systems themselves. ChatGPT Health’s default of asking permission before each records access points the right direction, but these lawsuits are a reminder to everyone: the granularity of consent and the adequacy of disclosure ultimately get tested clause by clause, in front of a judge.

What to take away

I’m not going to tell anyone not to use this. Asking questions against your actual lab report beats making the model guess from a vague description, and health is already one of ChatGPT’s highest-volume use cases — reportedly around 300 million health-related questions a week (TechCrunch, relaying OpenAI’s self-reported figure). OpenAI building this deliberately is more responsible than letting users paste medical records into a general-purpose chat box. And OpenAI’s terms say it outright: the service is not intended for the diagnosis or treatment of any health condition (TechCrunch).

But before you connect, it’s worth deciding with the right mental model: treat this as an effectively irreversible disclosure, not a revocable authorization. The disconnect switch and the delete switch both exist — the disclosure that already happened doesn’t come back. Thirty-day deletion is a product policy, not a legal right (HIPAA gives patients access and amendment rights, not a general right of deletion); a litigation hold can override it, and derived context may not be fully cleanable. Granularity is also in your hands: to interpret one lab report, paste that one report. You don’t have to pipe in your entire chart.

The larger judgment: this gap doesn’t close without legislation. HHS’s guidance states where the protection ends. The FTC updated its breach notification rule in 2024 to more clearly cover health apps, and Washington State and others have begun legislating for health data that escapes HIPAA (the My Health My Data Act). But these are patches: the notification rule governs disclosure after a breach, not everyday use; state laws stop at state residents and business nexus. HIPAA’s entity list was frozen into the healthcare system of 1996; a product of 2026 just piped medical records into the context window of a conversational AI. Until legislation fills the space between those two facts, the sentence “your medical records are protected” should — the moment you tap Connect — switch to the past tense.

References