7 Things to Know Before You Feed ChatGPT Your Medical Records

Johnson / Money Talks News

Your lab results hit your patient portal with a chime. You open them before your doctor’s even seen them. And there it is: a wall of numbers and words like “nonspecific” and “unremarkable” that somehow leave you more anxious, not less.

So you do what millions of people now do. You paste them into ChatGPT and ask the only question that matters: “Is this bad?”

As of July 23, OpenAI opened its ChatGPT Health feature to every U.S. adult. You can connect medical records, lab results and Apple Health data straight to the chatbot, and it’ll translate the jargon and track your numbers over time.

It’s genuinely useful. It’s also where a lot of people are about to hand over something they can’t get back — without realizing it.

Here’s what nobody warns you about when you tap “connect.”

1. The convenience is real — and that’s the trap

Let’s be honest about why this is tempting. More than 300 million people a week already ask ChatGPT health questions, according to OpenAI. Feeding it your actual results is the obvious next step.

Doctors aren’t thrilled. The Wall Street Journal recently reported that many physicians don’t want patients decoding results with a chatbot — yet patients are doing it anyway.

One family-medicine residency director, Dr. Karim Hanna, says patients now show up with conclusions ChatGPT gave them. Sometimes they’re right. Sometimes they need correcting. Either way, the horse has left the barn.

2. The second you upload, HIPAA stops protecting your records

This is the big one. HIPAA — the federal law you assume guards your medical data — protects that data because of who holds it. Your doctor, hospital or insurer.

Move those records into a consumer app and they leave that protected circle. A chatbot isn’t a covered entity, so HIPAA simply stops applying.

From that point on, your records live under OpenAI’s terms of service and a patchwork of state laws — weaker and easier to change. And no toggle inside the app puts HIPAA back. The protection doesn’t follow the data out the door.

3. OpenAI says it won’t sell your data — but that’s a promise, not a law

Credit where it’s due: OpenAI’s health privacy notice says flatly that it does “not sell Personal Data” collected through its health features. It also says health chats don’t train its main models by default and aren’t used to target ads.

Those are real commitments. But they’re voluntary — and the same notice says OpenAI can update it whenever it likes. A rule a company can rewrite on its own isn’t the same as a law it has to obey.

Quick gut-check — if your money advice is coming from random online influencers, you’re playing a dangerous game. I’ve been a CPA since 1981 and writing about money since before the internet existed. Sign up for the free Money Talks Newsletter and get expert advice that’s been tested by time.

4. ‘We don’t sell it’ isn’t the same as ‘we’ll never share it’

Read past the no-sale line and the fine print gets interesting. OpenAI says it may share your data to meet legal obligations, to protect its rights or property, and — the one to watch — when the company is involved in a business transaction.

In plain English: If OpenAI is ever bought or merges, your health data can travel with the deal. And a limited set of staff and vendors can already access some of it to check safety, unless you opt out.

5. Nobody’s answered the law-enforcement question

Here’s a question OpenAI hasn’t publicly settled: What happens when police or prosecutors ask for your health conversations?

A senior counsel at the Center for Democracy and Technology, Andrew Crawford, raised exactly that — does the company just turn the data over, and does it tell you when it does?

Inside your doctor’s system, there are rules for those requests. Inside a consumer chatbot, the answer is a lot murkier.

6. Your health chats don’t disappear when you close the app

Connecting your records isn’t a one-time glance. Those conversations sit in your account until you delete them yourself.

OpenAI does let you wipe chats, and says it removes them from its systems within 30 days. But that’s on you to remember.

So every anxious 2 a.m. question about a lump or a scary number lingers on a server until you go back and clear it — the same kind of sensitive detail that fuels the AI-powered scams we keep warning about.

7. If you’re going to use it anyway, use it with your guard up

I’m not telling you to swear off AI. It’s legitimately good at turning radiology gibberish into plain English. I’m telling you to be deliberate about it.

Don’t connect your entire medical record if you don’t need to. Paste in only the lines you want explained — and strip out your name, birthdate and any ID numbers first.

Lean on it to translate results and build a question list for your doctor, not to diagnose. There are smarter, safer ways to put AI to work on your health.

Then delete the chat when you’re done and switch on multi-factor authentication.

And go in clear-eyed about the trade. Handing over privacy for convenience is an issue we’ve weighed before. This is that same deal, only now it’s your bloodwork on the table.

The real question

The technology is useful. The doctors’ worries are fair. But the headline risk here isn’t a chatbot misreading your bloodwork.

It’s that you’re swapping a federal law built to protect your medical records for a corporate policy page that can change the day a bigger company writes a check.

That’s not your fault. The privacy rules never caught up to the tech. But you still decide what you feed the machine. So read the fine print before you connect a thing.

 

Upgrade to an ad-free experience

As a newsletter subscriber, you're already part of the family. Members enjoy distraction-free reading, PDF downloads, and exclusive perks.

No ads • PDF downloads • 2 free eBooks • Email us questions
Learn more about membership benefits •