OpenAI's new Health in ChatGPT lets U.S. users pipe medical records into the chatbot, with the opt in sitting in the app alongside the privacy and accuracy promises.
OpenAI is asking U.S. users to plug their medical records into ChatGPT. The company rolled out a feature called Health in ChatGPT this week, and the line that should get attention is the one between two things people have already been doing: asking ChatGPT general health questions, and letting a chatbot read a specific patient's chart. The new feature moves ChatGPT across that line.
The feature, announced on OpenAI's site, targets logged-in users 18 and over in the United States on web and iOS, across the Free, Go, Plus, and Pro plans. With user permission, ChatGPT can pull in Apple Health data and supported medical records, including medications, lab results, visits, sleep, and activity, and carry that context across future conversations. OpenAI says more than 300 million people a week ask ChatGPT health questions, and that more than 70 percent of those conversations have historically taken place outside any dedicated health surface, which the company frames as the reason for the rollout.
The handoff happens in the app rather than the clinic. Until now, the decision about which software could read a patient's chart sat with the provider, the hospital's IT team, or an insurer. OpenAI's design moves that decision to the patient: the same person answering the chatbot's questions is the one toggling access on.
OpenAI's announcement says the connected medical records and Apple Health data are not used to train foundation models or target ads, and that conversations carrying that data are encrypted at rest and in transit. The company also says it worked with hundreds of physicians worldwide and ran an evaluation called HealthBench Professional before launch. Those are vendor-stated commitments. The Register, in its framing of the launch, called the chatbot a 'better not-doctor,' a label that captures the company's own claim that the product complements rather than replaces clinical advice.
Last week, a man named Alan Winters filed a complaint against OpenAI alleging that ChatGPT gave him dangerous medical advice that caused him harm. The complaint, available as a PDF via Courthouse News, describes a sustained exchange and a hospitalization the plaintiff attributes to the chatbot's recommendations. The allegations are unproven; OpenAI has not publicly answered the substantive claims in the materials reviewed here. BBC News and CBS News have both reported on the complaint, which puts the question of how confidently a general-purpose model can answer questions about a specific patient on the same page as the privacy promise.
The questions worth asking before flipping the toggle are not the ones OpenAI's blog post answers. What subset of the record is shared by default, and can the user pick it? Is the no-training commitment written into binding terms that survive a policy update? Does deleting a conversation also delete the underlying medical data? Where does the clinician fit: does the chatbot's output go to a doctor, or only to the user? And if the chatbot's answer conflicts with a doctor, which one is the user supposed to follow?
The first test coming is the gap between OpenAI's blog post and its binding terms as the rollout widens, because the two have not always said the same thing. The second is regulatory. Health data in the U.S. is governed by HIPAA when it lives with a covered entity like a hospital; a consumer chatbot pulling the same data from a user's phone lives in a different legal zone, and the FTC and state attorneys general have been the most active enforcers of consumer AI claims so far.
The feature is built around the user's permission. The opt-in, the privacy commitment, the training carve-out, and the accuracy ceiling all live in the same toggle. The patient is the one who gets to flip it.