The short version
Health information has never been easier to access. Patients can check lab results in MyChart, collect records from different doctors, track health data on a phone, or ask an AI tool to explain something confusing. This is by design. Federal rules under the 21st Century Cures Act protect patients’ electronic access to their health information and support sending it to apps of their choice.1 AI has quickly become part of that picture: OpenAI reports that more than 300 million people ask ChatGPT health-related questions every week,2 and a 2026 YouGov survey found that 8% of Americans now turn to AI tools first for health information — ahead of social media and online forums.3
That convenience is valuable, but it points one direction: more records flowing to more apps, more AI services holding health context, more copies in more places. In our recent informal survey of patients and caregivers (not designed to be nationally representative), MyChart dominated the responses, but people also reported using Healow, Guava, Apple Health, ChatGPT, spreadsheets, paper notes, recordings, laboratory apps, and genetics websites.
“I have 15 different portals.”·“Patient portals also don’t tell me what I need to do next.”
For many patients, access is only the first problem. The next is understanding where that information goes once we start moving it between apps. This article focuses on the tools patients use directly — health AI is also spreading through clinical settings, from AI note-takers in the exam room to diagnostic tools, but those typically operate within your healthcare organization’s HIPAA-covered relationships, and they are a topic of their own.
Hospital
Portal
Family
How common health tools differ
The point is not that one tool is “safe” and another is “unsafe.” They solve different problems. The better question is: What information am I giving this tool, and does it need all of it?
| Tool | What it helps with | What to watch for | Safer use |
|---|---|---|---|
| Patient portalsMyChart, Healow | See your test results, medications, and messages from your doctor | A stranger who gets your password sees everything your doctor sees | Use a unique password and turn on two-step login |
| Record-organizing appsGuava, PicnicHealth | Pull records from all your doctors into one place | One account now holds your whole health history | Guard that account like a bank account; check what the app shares before signing up |
| AI assistantsChatGPT, Gemini, Copilot, Claude, Perplexity | Explain confusing results and help you prepare questions for your doctor | It’s easy to share more than the question needs; some services can keep or learn from what you type2 | Leave out your name and ID numbers; check the privacy settings in each one you use |
| Health & fitness apps, wearablesApple Health, Whoop, Oura, mood and symptom apps | Track sleep, activity, symptoms, mood, and cycles | HIPAA usually doesn’t apply here — protection depends on each app’s own policy; some share data with advertisers, and apps can shut down4 | Only grant the data categories an app needs; delete your account if you stop using it |
| DNA testing services23andMe, Ancestry | Ancestry and genetic health reports | DNA can never be changed, and it reveals your relatives too; 23andMe’s customer data was exposed in 2023 and changed owners in its 2025 bankruptcy5 | Read the retention and deletion policy before you send a sample; delete data you no longer want held |
Scroll the table sideways →
The 23andMe lesson. If any category shows why this matters, it is DNA. A 2023 credential-stuffing attack on 23andMe — reused passwords, not a broken database — ultimately exposed information associated with roughly 7 million customers. Two years later, bankruptcy proceedings transferred substantially all of the company’s assets, including its customer genetic data, to a new owner; several state attorneys general urged customers to delete their data first.5 DNA is uniquely permanent: it cannot be changed the way a password can, and because relatives share portions of your genome, your test can reveal things about family members — biological relationships, disease risk — that they never chose to share.
Why AI deserves extra attention
AI is especially useful because patients can ask questions in everyday language: “What does this mean?”, “What are the important parts?”, or “What should I ask my doctor?” And it is not only ChatGPT: patients also turn to Google’s Gemini, Microsoft Copilot, Meta AI, Anthropic’s Claude, and Perplexity. Each service has different defaults for training, retention, and temporary chats — the advice below applies to all of them.
In July 2026, OpenAI launched Health in ChatGPT to all U.S. users 18 and older, letting people connect Apple Health and medical records from systems such as Epic and Oracle Health so that ChatGPT can answer questions in the context of their real labs, medications, and visits.2 OpenAI says this connected health data gets stronger protection than a normal chat: it is never used to train models or target ads, no matter what your settings say.2 Two things are still worth knowing. First, once connected, your health records don’t stay in the Health section — with your permission, they can inform any conversation you have. Second, these protections are OpenAI’s own promises, not independently audited.
Conversation also makes it very easy to overshare. If you only want help understanding an LDL cholesterol result, the AI may need something as simple as “My LDL was 142 mg/dL. What does that mean?” It probably does not need your full name, address, date of birth, medical-record number, insurance information, and every other diagnosis on the same report.
Before uploading a medical document, ask: Does the AI actually need everything on this page?
Tips for using public AI more securely
Going further
Some services offer stronger, opt-in protections. In ChatGPT, advanced account security requires stronger sign-in methods and disables weaker recovery paths, and Lockdown Mode limits web and connected-app access for a sensitive chat — an advanced defense against data-theft tricks, not a private-chat feature. Look for equivalents in whichever service you use.
Screens shown are ChatGPT’s settings, verified August 21, 2026; other AI services have equivalents under different names. Options also vary by subscription: the basic training opt-out is available on free plans, but free tiers are typically enrolled in training by default and offer the fewest controls, while business and enterprise plans are excluded from training automatically.6
Private is not the same as accurate
One more caution belongs in any honest discussion of health AI: you can follow every privacy tip above and still be harmed by a confidently wrong answer. In a 2026 physician-led study in npj Digital Medicine, doctors evaluated 888 responses to patient-style medical questions across four major chatbots and found problematic answers from all of them, with unsafe-response rates between 5% and 13%.7
A simple rule: use AI to explain, organize, summarize, compare, and prepare questions. Be much more cautious when an answer would lead you to start or stop a medication, change a dose, conclude you have a diagnosis, or decide whether you need urgent care. For decisions that could change your care, verify with a clinician, pharmacist, or authoritative medical source.
AI accuracy deserves more than a caution box — a future article in this series will cover the risks in depth, with a guide to safer use.
What about HIPAA?
A common assumption is: “It is health information, so HIPAA protects it.” That is not always true. HIPAA generally applies to healthcare organizations and to companies working on their behalf, called “business associates.”8 That chain is why your patient portal is protected: the portal company (Epic’s MyChart, Healow) handles your record as a business associate of your doctor. If you download your own medical record and voluntarily upload it to an independent consumer app, HIPAA generally does not apply to that copy. That does not mean the app is careless — many consumer health apps have strong privacy practices, and some voluntarily follow HIPAA-level safeguards. It means the legal floor is different: what happens to your data is governed by the app’s own privacy policy and consumer-protection law, not by HIPAA’s rules.
There is a consumer-side backstop: the FTC’s Health Breach Notification Rule covers health apps that HIPAA does not, and the FTC has used it — first against GoodRx, which paid a $1.5 million penalty in 2023 for sharing users’ health data with advertisers including Facebook and Google, then against the fertility app Premom; the strengthened rule took effect in July 2024.9,10 But notification after a breach is not prevention.
“HIPAA compliant” and “everything I put into this app is protected by HIPAA” are not the same statement.
What can someone actually do with health data?
It is fair to ask why any of this matters — a lab result is not a credit card number. But health data is durable and personal in ways financial data is not: a stolen card can be cancelled and reissued; a diagnosis, a genome, or a therapy transcript cannot. In practice, exposed health information gets used in a few concrete ways:
- Medical identity theft. Someone uses your name, insurance ID, or Medicare number to obtain care, prescriptions, or equipment, or to file fraudulent claims — leaving errors in your medical record and bills in your name that can take months to untangle.11
- Convincing, targeted scams. A phisher who knows your real provider, medication, or recent visit can write a fake portal or billing message that looks entirely legitimate — the reused-password and fake-email risks described below become much more effective with real health details behind them.
- Extortion. Sensitive records can be used as leverage directly. In the 2020 breach of Vastaamo, a Finnish psychotherapy provider, attackers emailed individual patients and demanded ransom against publication of their therapy notes — a widely reported case precisely because the harm fell on patients, not just the institution.12
- Profiling and targeted advertising. Health details that escape into data-broker and advertising ecosystems can feed decisions you never see — the FTC’s actions against GoodRx and BetterHelp both involved health information flowing to advertisers without consent.10
None of this means you should panic — but it does mean the problem will grow. The trend this article opened with — more records, more apps, more copies — means the raw material for these harms is growing faster than the protections around it, which is exactly why the small habits here matter now. Each identifier you withhold and each old copy you delete reduces your exposure — and the damage any future compromise can do.
The biggest risk may be the whole workflow
People often imagine health-data theft as someone hacking a hospital. But an easier path might be a reused password, a fake portal email, an unlocked phone, an old laptop, a downloaded PDF, an email attachment, or a caregiver’s compromised account.
Excellent hospital security does not protect a medical record that was downloaded years ago and is still sitting in an email inbox. That is why the whole journey of your information matters.
What better digital healthcare should look like
Patients should not have to become cybersecurity experts to manage their healthcare. A useful test for any patient-facing health tool — including AI — is whether it can clearly answer questions like these:
- Does my data train your models, and can I turn that off?
- How long do you keep my data, and what does deleting my account actually delete?
- Is my information used for advertising, or shared with third parties?
- What can connected apps see, and can I revoke them?
- Can I export everything and leave?
- Can a caregiver get appropriate access without sharing my password?
- When do HIPAA protections apply to my data here — and when do they not?
A tool that answers these plainly is showing you respect. A tool that buries them is telling you something too.
The goal is not to stop using health technology. It is to use it with enough awareness that convenience does not come at the cost of control.
Protect the account receiving it·Review who still has access
Sources
- ONC / ASTP — Information blocking under the 21st Century Cures Act — federal rules protecting patients’ electronic access to their health information, including through apps of their choice
- OpenAI — Launching Health in ChatGPT (Jul 23, 2026) — availability, connected records, and OpenAI’s stated training/ads exclusions; vendor representations, not an independent audit
- YouGov (2026) — Americans turning to AI for health information — nationally representative weighted survey of 2,494 U.S. adults, July 15–17, 2026; 8% turned to AI first
- EFF (2026) — Wearables transparency report — advocacy analysis: most wearable vendors are not HIPAA covered; only Apple and Google publish transparency reports
- NPR (2025) — Judge approves 23andMe bankruptcy sale — the 2023 credential-stuffing breach (~7M customers) and court-approved transfer of customer data to TTAM; state attorneys general urged deletion
- OpenAI Help Center — Data Controls FAQ — training opt-out on consumer accounts; business plans excluded from training by default; accessed August 21, 2026
- npj Digital Medicine (2026) — Large language models provide unsafe answers to patient-posed medical questions — physician evaluation of 888 responses across four chatbots; unsafe-response rates 5–13%
- HHS — HIPAA guidance on health apps — HIPAA applies to covered entities and business associates, not consumer apps generally
- FTC (2023) — GoodRx enforcement action — first Health Breach Notification Rule enforcement; $1.5M penalty for sharing health data with advertisers
- FTC — Health Breach Notification Rule: the basics — the rule covers non-HIPAA health apps; strengthened amendments effective July 2024
- FTC — What to know about medical identity theft — consumer guidance on fraudulent care, claims, and record errors in the victim’s name
- BBC News (2020) — Therapy patients blackmailed after clinic data breach — Vastaamo attackers individually extorted patients, threatening publication of therapy notes
This article is intended for general educational purposes and is not legal, medical, or cybersecurity advice. Product features, privacy policies, and security controls change quickly — the Health in ChatGPT and wearable sections describe these services as of August 2026; review the current policies and settings of any service before sharing sensitive health information. Privacy settings shown were verified August 21, 2026.