The medical record is moving into the ordinary chat

ChatGPT no longer needs a pasted lab result to know that the result exists.

OpenAI has started rolling out Health in ChatGPT to adults in the United States. With permission, the service can connect to Apple Health and supported medical records. One Medical and Function Health are named as available sources, alongside records from participating US hospital systems.

The connected information can include medications, conditions, lab results, recent visits, sleep and activity. ChatGPT can use it to compare results over time, prepare questions for an appointment or take an injury into account while suggesting an exercise plan.

The important product change is not a new medical chatbot tucked away in a separate tab. Health information can now follow a person into ordinary ChatGPT conversations. OpenAI says more than 70% of health-related chats among its early users already happened outside the dedicated health area.

That may make the feature more useful. It also means the boundary around sensitive information has to work in many more contexts.

Permission is visible, but it can become permanent

By default, ChatGPT asks before using connected health information in a response. A person can approve access once, choose to always allow it or call the source directly by adding @Health to a message.

The continuing-access option removes later prompts. That is convenient, and easy to forget. The setting can be changed under Plugins > Health, while connected accounts can be removed from the Health area.

OpenAI says data synced from a disconnected source is deleted from its systems within 30 days. Information already copied into conversation history remains there until those chats are deleted.

The company also says memories may be created from health conversations, although not directly from the connected medical record or Apple Health feed. Temporary Chat or a disabled memory setting can prevent new memories from being created.

These details matter more than a broad promise to keep data safe. They tell a user when information can enter a conversation, where a copy may remain and which action actually removes it.

More context can produce a better answer and a more convincing mistake

OpenAI says connected health data is not used to train its foundation models or target ads. It also says conversations are encrypted in transit and at rest, with additional protection for connected information.

The company has trained and tested its recent models with input from physicians. Its HealthBench Professional benchmark uses real clinician tasks and physician-written scoring rules. OpenAI says every GPT-5.6 model beat GPT-5.5 on that evaluation.

The benchmark is useful evidence about model responses. It is not a clinical trial of ChatGPT Health. The paper deliberately includes difficult examples, and roughly a third involve doctors trying to expose model failures. It measures performance on selected conversations, not what happens when millions of people use incomplete or outdated records at home.

OpenAI acknowledges that the connected record may be wrong or stale. A medication can remain listed after someone stops taking it. The product therefore lets users correct or remove details, and tells them to check important information against the original source.

A system with more personal context may give a more relevant answer. It may also sound more authoritative when it is mistaken. The extra data does not remove the need to check.

Health privacy does not fit under one familiar label

It is tempting to reduce the privacy question to one word: HIPAA. US health-data law is not that simple.

The Department of Health and Human Services says information sent, at a person's direction, from a covered healthcare provider to an app that is neither a covered entity nor a business associate may no longer be protected by the HIPAA rules. Whether those rules apply depends on the relationship between the app, the provider and the service being delivered.

Health apps outside HIPAA are not outside the law. The Federal Trade Commission's Health Breach Notification Rule covers many personal health-record services and connected apps. It can require notices to users, the FTC and sometimes the media after certain breaches or unauthorised disclosures.

OpenAI's launch page does not give one blanket legal classification for every record connection. That would be difficult because different integrations may involve different relationships. Users should read the product's specific privacy terms rather than treating a familiar healthcare logo as a complete answer.

What is confirmed, what is claimed and what remains open

The confirmed product is fairly specific. Health is rolling out to logged-in ChatGPT users aged 18 and over in the US, on web and iOS, across Free, Go, Plus and Pro plans. Apple Health and selected record sources can be connected. Access is permissioned, and synced-source data can be disconnected.

The privacy and performance statements come from OpenAI. The company says connected data is not used for foundation-model training or targeted ads, and says its recent models perform better on physician-led evaluations. Those claims are supported by published product details and a public benchmark, but Model Current has not independently audited the deployed system or its deletion process.

Several practical questions remain. OpenAI has not published a complete list of supported hospital systems on the launch page. Real-world error rates with incomplete records are unknown. The effect of always-on permission across unrelated chats has not been measured publicly, and the benchmark does not establish better patient outcomes.

The feature could make a scattered medical history much easier to understand. It also asks people to place unusually sensitive context inside a general-purpose assistant. The right first move is a small one: connect only what is useful, leave per-use permission on and keep the original record close.

Sources

  1. OpenAI — Launching Health in ChatGPTPrimary product announcement published 23 July 2026. Source for availability, connected sources, permissions, retention statements, privacy commitments and product limitations.
  2. OpenAI — Improving health intelligence in ChatGPTPrimary company report published 18 June 2026. Source for physician involvement, internal evaluation claims and production-monitoring claims.
  3. HealthBench Professional — arXivPrimary research paper submitted 30 April 2026. Source for benchmark construction, task selection, physician rubrics and stated scope.
  4. US HHS — The access right, health apps and APIsPrimary federal guidance on when health information transferred to a consumer app may fall outside HIPAA protections.
  5. US FTC — Health Breach Notification Rule for appsPrimary regulator guidance explaining breach-notification duties for personal health-record services and health apps not covered by HIPAA.