Back to Blog

ChatGPT Wants Your Medical Records. Here Is What It Actually Does With Them.

5 min read

300 Million Health Questions Weekly

Over 300 million people every week are already asking ChatGPT about their health. Not a projected number, not a ceiling — that is the current usage figure OpenAI cited when it announced the July 23, 2026 rollout of Health in ChatGPT. The behavior existed long before the feature did. People were typing in their lab results, describing symptoms, asking what a diagnosis actually means in plain language. The only thing missing was context. ChatGPT was answering health questions with no idea who was asking.

That is what the July 23 update changes. Health in ChatGPT is an optional layer that lets U.S. users 18 and older connect their actual medical records and wellness apps — Apple Health, MyFitnessPal, Function, and electronic health records from roughly 2.2 million U.S. providers through a partnership with b.well — so that the AI's responses are grounded in their specific data rather than a generic population average.

The practical difference is significant. Instead of asking "what does a high creatinine level mean," you can ask what your creatinine level means — and get an explanation that accounts for your age, your medication history, your trend over the last three tests. The feature launched initially in January 2026 and has now expanded beyond a standalone tab, integrating health context directly into regular conversations based on what early testers said they actually wanted.

How the Data Connection Works

The b.well partnership is doing the actual infrastructure work here. When you authorize a connection, b.well acts as the intermediary between ChatGPT and your provider's electronic health record system — pulling from a network that covers roughly 2.2 million U.S. providers, including One Medical. You are not uploading files or copy-pasting discharge summaries. The connection is authenticated through the same kind of OAuth flow you would use to link a bank account to a budgeting app. You authorize it, b.well handles the handshake, and your records become available to the model.

On the wellness side, Apple Health, MyFitnessPal, and Function are the supported apps at launch. If you track sleep, activity, nutrition, or biomarkers through any of those, that data can feed into the same context layer as your clinical records.

The design decision that early testers pushed for — and that OpenAI built into the July 23 rollout — is that this context travels with you into regular conversations rather than staying locked inside a separate Health tab. You do not have to switch modes. If you are mid-conversation and ask something that touches your records, the model can draw on that data directly. The health layer is aware of the conversation; the conversation is aware of the health layer. That integration is the part that actually changes how the tool gets used day to day.

What the Privacy Guarantees Actually Say

So what does OpenAI actually promise, and what does that promise cover?

The privacy architecture has four concrete pieces. Health data is stored in a separate, isolated space with layered encryption — it does not commingle with your standard conversation history. Conversations you have inside the Health context do not flow into your non-Health chats. You control which connections are active and can revoke them at any time. If you disconnect a data source, OpenAI states your health data is deleted within 30 days.

The most important guarantee, and the one most people get wrong: OpenAI explicitly states that health data is not used to train its models. This applies regardless of your general data-sharing settings. It is not a toggle you have to find and switch off. It is the default and only state. Your lab results are not becoming training signal for a future model update.

Two misconceptions deserve direct correction.

First, that this feature is HIPAA-compliant for clinical use. It is not. OpenAI has separate enterprise offerings aimed at healthcare providers operating under HIPAA requirements. Health in ChatGPT is a consumer product. Those are categorically different things, and conflating them creates real misunderstanding about what the privacy protections actually cover.

Second, that connecting your records means ChatGPT is now acting as your physician. OpenAI is explicit: the feature supports, it does not replace, clinical judgment. Every response comes with disclaimers directing users to consult a professional for diagnosis or treatment decisions.

The Question Worth Asking

The real decision is not whether health data and AI should ever intersect. That question is already settled by behavior — 300 million weekly users made it settled before OpenAI built a single privacy control. The actual decision in front of any user who sees Health in ChatGPT in their account is narrower and more specific: has OpenAI built enough structural accountability to make the tradeoff rational for you, given your specific risk tolerance and use case?

For most people using ChatGPT to understand a lab result or prepare questions before an appointment, the architecture OpenAI has described — isolated storage, no training use, 30-day deletion on disconnect — is a reasonable tradeoff for meaningfully better answers. The privacy protections are concrete, not aspirational.

For marketers and content professionals watching this rollout, the more relevant question is what it signals about AI's trajectory in sensitive domains. OpenAI is not the last platform to build this kind of integration. Every major AI company is working on the same problem: how to ground general-purpose models in personal data without destroying the trust that makes adoption possible. The structural decisions OpenAI made here — separate context, user-controlled permissions, explicit no-training guarantees — are becoming the baseline expectation users will bring to every platform that asks for sensitive data access. Understanding how that bar gets set is worth paying attention to.

Share:PostShare
ChatGPT Wants Your Medical Records. Here Is What It Actually Does With Them. — PostMimic Blog