ChatGPT Health Can Use Medical Records In Regular Chats. What Happens To Your Data?
ChatGPT Health can use connected medical records and Apple Health data across chats. Here is what OpenAI confirms about permission, training, memory, and deletion.
Yes. OpenAI's July 23 U.S. rollout allows ChatGPT to use connected medical records and Apple Health data in regular conversations, not only inside the Health tab, when the information is relevant and you permit access. OpenAI says that connected data and conversations using it are not used to train foundation models or target ads. That does not mean the data is never stored, accessed, remembered, or copied into chat history.
Watch The 30-Second Summary
Updated July 25, 2026: This article reflects OpenAI's U.S. rollout announcement, current Health help documentation, Health Privacy Notice, and the first national privacy-and-safety coverage after launch.
Who This Article Is For
This article is for:
- ChatGPT users considering whether to connect Apple Health or a patient portal
- people who already ask AI about lab results, medications, symptoms, sleep, or exercise
- privacy-conscious users who want to understand where health data can appear
- caregivers and families trying to avoid mixing one person's records with another person's account
- clinicians, insurers, and employers who need to distinguish a consumer feature from a HIPAA-eligible clinical service
The central question is not simply, "Does OpenAI train on my medical records?" A useful privacy review must separate connection, permission, processing, storage, chat history, memory, human access, deletion, and clinical use.
What Is Confirmed
OpenAI's July 23 launch announcement confirms that Health is rolling out to logged-in U.S. users age 18 and older on web and iOS across Free, Go, Plus, and Pro plans. Users can connect supported U.S. medical records, Apple Health, One Medical, and Function Health.
OpenAI says more than 300 million people ask ChatGPT health-related questions each week. That unusually large audience, combined with the sensitivity of medical data, makes the feature's controls worth understanding before connecting anything.
Health Data Can Be Used Outside The Health Tab
The important product change is scope.
OpenAI's Health help page says that, after syncing, you can ask questions using connected Health data anywhere in ChatGPT. When relevant and allowed, ChatGPT may use that data to personalize a response. Examples include explaining labs, preparing appointment questions, analyzing sleep or activity trends, and finding a restaurant that accommodates an allergy.
By default, ChatGPT asks before using connected Health data. A user can approve one request or choose to allow all, which turns off those permission prompts. The setting can be changed under Settings → Plugins → Health.
That means "available across ChatGPT" does not mean "silently inserted into every answer." The documented default is a permission prompt. But choosing always-allow changes the practical boundary because relevant health context may then be used without a new prompt each time.
Connected Health Data Is Not Used To Train Foundation Models
OpenAI says connected medical records, Apple Health information, and conversations that use that data are not used to train its foundation models or target ads, regardless of the user's ordinary model-training setting.
That is a meaningful restriction. It also has a precise scope.
The OpenAI Health Privacy Notice separately says that conversations not using connected Health data follow the user's normal ChatGPT model-training choice. "Not used for foundation-model training" therefore should not be treated as a blanket rule for every health-related sentence typed into any ChatGPT conversation.
Disconnecting A Source Does Not Delete Every Copy
OpenAI says disconnecting a medical-record or Apple Health source schedules synced data from that source for deletion from OpenAI's systems within 30 days.
The same help page adds a critical boundary: information already included in ChatGPT conversation history remains until those conversations are deleted.
Disconnecting stops the source connection and starts deletion of the synced source copy. It is not documented as a one-click eraser for:
- health facts already written into chat messages
- summaries or explanations already generated in a conversation
- memories created from what you discussed
- exports, screenshots, or messages shared elsewhere
- records still held by the original provider or Apple Health
Health Conversations Can Create Memories
OpenAI says memories are not created directly from synced medical records or Apple Health data. However, when memory is on, conversations that use Health can create memories.
For example, discussing a sleep goal and work schedule may create a memory used in later chats. OpenAI recommends Temporary Chat or turning memory off for a conversation that should not create memories. It also suggests a separate project with project-specific memory if a user wants health-related conversation context kept apart.
This distinction matters: a source record, a chat message derived from that record, and a saved memory synthesized from the conversation are three different representations with different controls.
Health Is Not A HIPAA-Eligible Consumer Feature
OpenAI's help page states that Health in ChatGPT is not intended for clinical or covered-entity use and does not offer a Business Associate Agreement. OpenAI directs HIPAA-covered organizations to separate products designed for healthcare and clinician use.
That does not determine whether an individual's personal use is lawful or wise. It does mean a clinic, insurer, or other covered organization should not assume that the consumer Health feature is an approved clinical workflow merely because it handles medical records.
What Is Still Unclear
The public documentation answers several important questions, but it does not publish every implementation detail a high-assurance user might want.
What "Additional Encryption Protections" Means Technically
OpenAI says all ChatGPT conversations are encrypted at rest and in transit and that connected Health information receives additional encryption protections. The consumer documentation does not specify the complete key hierarchy, operator-access design, field-level encryption scheme, hardware isolation boundary, or independent verification method behind that phrase.
Encryption is important, but it does not by itself answer who can decrypt data during an authorized service operation. For that broader distinction, see Who Holds The Encryption Keys For An AI Chat?.
How Often Health Context Will Be Judged "Relevant"
OpenAI provides examples, but relevance is contextual. An allergy may be relevant to restaurant planning. A recent injury may be relevant to weekend activities. A medication or diagnosis could potentially influence a wider range of questions.
The default permission prompt creates a visible checkpoint. Users who choose always-allow have less moment-to-moment visibility into when the system decides Health context is relevant. The public material does not provide a complete rule set or user-facing audit log for every retrieval decision.
The Full Scope Of Authorized Human And Provider Access
The Health Privacy Notice says a limited number of authorized OpenAI personnel and trusted service providers might access Health data to improve model safety unless the user has opted out. It also describes processing for customer support, fraud and misuse prevention, security, legal obligations, hosting, cloud services, and safety monitoring.
That is not evidence that people routinely read medical records. It does show why "not used to train foundation models" is narrower than "no one at the provider or its processors can ever access the data."
Independent Proof Of Deletion
OpenAI documents a 30-day deletion window after a source is disconnected, while chat-history copies require separate deletion. The consumer interface does not provide a cryptographic deletion receipt or an externally auditable inventory of every derived copy.
The defensible claim is that OpenAI has stated a deletion policy and user controls. It is not independently verifiable from the user's browser that every covered backend object has been removed.
CBS News' July 25 launch coverage also surfaced expert concern about the privacy and accuracy tradeoffs of sharing deeply personal records with a chatbot. Those concerns establish public attention; they do not prove that OpenAI has broken its stated controls.
Use A Seven-Boundary Health-Data Map
Before connecting medical records to any AI service, map seven separate boundaries:
| Boundary | Question to ask | What OpenAI currently documents |
|---|---|---|
| Source | Which records and apps are connected? | Supported medical records, Apple Health, One Medical, and Function Health; availability varies |
| Permission | When can the assistant read connected data? | Ask first by default; one-time approval or always-allow |
| Processing | Where must the active request go? | ChatGPT processes the request and may use service providers |
| Training and ads | Is connected data used to improve foundation models or target ads? | No, for connected records, Apple Health data, and conversations that use it |
| Retention | What persists after the answer? | Synced source data, chat history, and memory follow distinct controls |
| Access and sharing | Who or what else may receive data? | Authorized personnel, service providers, and connected actions may have bounded access |
| Deletion and exit | What must be removed separately? | Disconnect the source, delete relevant chats, review memories, and remove external copies |
This map prevents two common mistakes:
- assuming a training opt-out means no storage or processing
- assuming disconnecting an account deletes every conversation and memory derived from it
The same distinction appears in other AI products. Turning off AI training does not necessarily stop chat retention, and deleting a chat may not delete every uploaded file or reusable copy.
A Practical Checklist Before Connecting Medical Records
1. Start With The Smallest Useful Source
Do not connect every provider and wearable simply because the option exists. Decide what question you need answered and whether a limited upload, a manually summarized result, or no record connection at all can answer it.
Data minimization reduces the consequences of a mistaken permission, account compromise, product bug, or future policy change.
2. Keep "Ask First" Until You Understand The Behavior
The default prompt is a valuable visibility control. Use one-time approval while learning which ordinary conversations trigger a request for Health context. Switch to always-allow only if the convenience is worth losing that repeated checkpoint.
3. Review What Apple Health Actually Shares
Wearable, fitness, and nutrition apps can feed information into Apple Health. OpenAI says ChatGPT can use the information those apps make available through Apple Health when permitted.
Review categories in iPhone Health data-access settings. Do not assume that connecting "Apple Health" means sharing only steps or workouts.
4. Separate Source Deletion, Chat Deletion, And Memory Deletion
If you want to leave:
- disconnect each medical-record or Apple Health source
- delete chats that contain or summarize the connected information
- review and delete relevant saved memories
- check projects or legacy Health spaces for older chats and files
- remove exports, screenshots, or messages shared through other services
These steps address different copies. One control should not be expected to perform all five.
5. Use Temporary Chat For One-Off Sensitive Questions
OpenAI says Temporary Chat does not create memories. Temporary Chat still requires active processing and follows its own safety-retention rules; it is not the same as offline computation or a promise that no operational record exists.
6. Be Careful With Connected Actions
OpenAI says additional safeguards apply before another plugin takes an action that could disclose Health information, such as sharing a health-informed training plan. Treat every external action as a new disclosure boundary. Confirm the recipient, content, and destination rather than relying on the assistant's summary.
7. Do Not Use Consumer Health As A Clinical Compliance Shortcut
Health in ChatGPT is designed to support personal understanding, not replace medical care, diagnosis, or treatment. Verify important information with the original record and a qualified professional.
Covered organizations need an approved service, a documented agreement, administrative controls, and a validated workflow. A consumer feature's privacy marketing is not a substitute for that governance.
What This Launch Does Not Mean
The rollout does not prove that:
- connected medical records are used to train OpenAI's foundation models
- Health data is inserted into every ChatGPT response
- disconnecting a source instantly deletes chat history
- turning off memory deletes previous chats or synced records
- encryption prevents every authorized provider-side access
- ChatGPT Health is intended for clinical or HIPAA-covered workflows
- ChatGPT becomes a doctor or can replace professional judgment
- every health-related chat automatically receives the same protection as a conversation that actually uses connected Health data
The strongest privacy analysis preserves both sides: OpenAI has published meaningful training, permission, encryption, and deletion safeguards; users still need to understand the separate copies and access paths those safeguards do not collapse into one switch.
Where OpenVeil Fits
OpenVeil is not a medical-record connector, a diagnostic system, or a HIPAA-compliant clinical product. It should not be presented as a replacement for ChatGPT Health.
OpenVeil is relevant when the need is broader: a paid, privacy-focused AI chat workspace with browser-local history and no server-side chat-history record for normal private chat sessions. OpenVeil does not use prompts, uploads, images, audio, selected local history context, or outputs to train foundation models.
That boundary is narrower than "nothing leaves your device." Active requests may still be processed by OpenVeil and necessary AI, search, upload-processing, hosting, routing, security, billing, and infrastructure providers.
For general private AI work, read the OpenVeil privacy policy and compare the product's history model with the health-data boundaries above. For medical decisions or regulated clinical work, use an appropriately governed healthcare workflow and qualified professional care.
Frequently Asked Questions
Does ChatGPT Health Use Medical Records To Train AI Models?
OpenAI says connected medical records, Apple Health information, and conversations that use that data are not used to train its foundation models or target ads. Conversations that do not use connected Health data follow the user's ordinary ChatGPT training setting.
Can ChatGPT Use Health Data In A Regular Conversation?
Yes. OpenAI says connected Health information can be used anywhere in ChatGPT when relevant and permitted. The default is to ask before using it; users can instead choose always-allow.
Does Disconnecting Apple Health Delete Health Conversations?
No. OpenAI says disconnecting schedules synced source data for deletion within 30 days. Information already included in ChatGPT conversation history remains until the user deletes those conversations.
Can ChatGPT Remember Health Information?
Yes, through conversation memory. OpenAI says memories are not created directly from synced records, but conversations using Health can create memories when memory is enabled. Temporary Chat or disabling memory can prevent new conversation memories.
Is ChatGPT Health HIPAA Compliant?
OpenAI says the consumer Health in ChatGPT feature is not intended for clinical or covered-entity use and does not offer a Business Associate Agreement. OpenAI offers separate healthcare products for eligible clinical settings.
Is ChatGPT Health Available Everywhere?
No. As of July 25, 2026, OpenAI says it is gradually rolling out to eligible logged-in U.S. users age 18 and older on web and iOS. Apple Health connection requires an iPhone, and Health is not currently supported in Voice mode or Codex.
The Bottom Line
ChatGPT Health's new cross-chat access can make connected records more useful, but it also makes the permission boundary more important. Keep ask-first enabled while evaluating the feature, connect only necessary sources, and remember that training, storage, memory, human access, chat history, and deletion are separate controls.
If you want a privacy-focused AI workspace for general use without a normal server-side chat-history record, review OpenVeil's boundaries and create an account. Do not use OpenVeil or any consumer chatbot as a substitute for medical care or an approved clinical system.