Is It Safe to Upload Medical Records to ChatGPT? The 2026 Answer

Is it safe to upload medical records to ChatGPT: a doctor at a bedside in Luke Fildes's 1891 painting The Doctor
Luke Fildes, The Doctor (1891) — public domain. For a century your medical file sat in one room with one person who was legally bound to keep it. The question in 2026 is what happens the moment you carry a copy out of that room.

Yes, you are allowed to, and the newest way of doing it is safer than the way most people did it last year — but HIPAA protects none of it. On September 1, 2026 we read the four documents that actually decide this question, 19,988 words in all, and the single most useful sentence is eleven words long, in OpenAI’s own help center: Health in ChatGPT “does not offer a Business Associate Agreement.”

That sentence is the whole answer. The law you are counting on is not in the room.

Here is how the question usually arrives. You come home with a lab printout covered in numbers and abbreviations. Your next appointment is in three weeks. You have a phone in your hand that will explain the whole page in ten seconds, and somewhere in the back of your mind a voice says: should I be putting this into a computer owned by a company in California?

It is a good instinct. It is also answerable, and the answer is more specific than “be careful.”

The short answer, in five lines.

  1. It is legal. HIPAA restricts your doctor and your insurer. It does not restrict you, and it does not follow the copy you carry away.
  2. The box matters more than the app. Health, an ordinary chat and a Temporary Chat are governed by three different rules inside the same product.
  3. Health is the safest box OpenAI offers. Records connected there are excluded from model training and from ads “regardless of the model-training setting you choose.”
  4. Disconnecting is not deleting. Synced data goes within 30 days; anything already sitting in a chat stays until you delete the chat.
  5. Take your name off first. The AI needs the numbers, not your member ID.

What changed in 2026: the app started asking for your records

Until this year, uploading a medical record to a chatbot meant photographing a page and dropping it into a normal conversation. That is no longer the main path.

OpenAI announced ChatGPT Health on January 7, 2026, and on July 23, 2026 opened it to United States users. It is a separate space inside ChatGPT that connects directly to Apple Health, to supported U.S. hospital portals, and to One Medical and Function Health.

The scale is the reason it exists. In January OpenAI said its own de-identified analysis found over 230 million people a week asking health and wellness questions. By the July announcement the figure it published was more than 300 million a week.

So the honest framing is not “should anyone do this.” Hundreds of millions already are. The useful question is which door you walk through.

Diagram: HIPAA covers health plans, clearinghouses and providers; the FTC Health Breach Notification Rule covers everyone else
Two rules, one file. Which one applies depends entirely on who is holding the copy at that moment. Definitions read from 45 CFR 160.103 and 16 CFR 318 on September 1, 2026.

Why HIPAA does not follow your file

Almost everyone believes HIPAA is a rule about health information. It is not. It is a rule about certain organizations.

The federal regulation is one sentence long and worth reading exactly as written. Under 45 CFR 160.103: “Covered entity means: (1) A health plan. (2) A health care clearinghouse. (3) A health care provider who transmits any health information in electronic form in connection with a transaction covered by this subchapter.”

Three items. A hospital. An insurer. A clearinghouse that shuttles claims between them. A chatbot is none of those things, and neither is a fitness app, a pill reminder or a symptom checker.

OpenAI does not dispute this. Its help center answers the question directly: Health in ChatGPT “is not intended for clinical or covered-entity use and does not offer a Business Associate Agreement.” A Business Associate Agreement is the contract that pulls an outside company inside HIPAA’s fence. Without one, there is no fence.

The company does sell HIPAA-supporting products — ChatGPT for Healthcare and ChatGPT for Clinicians — but those are for the hospital, not for you.

The sentence to remember. HIPAA protects your record while your doctor holds it. The moment you make a copy and hand it to a company you chose yourself, HIPAA is finished and something else takes over. That is not a loophole. That is how the rule was written in 1996, before anyone had a phone that could read a blood panel.

The Hubert H. Humphrey Building in Washington, D.C., headquarters of the U.S. Department of Health and Human Services
The Hubert H. Humphrey Building in Washington, D.C. — headquarters of the department that writes and enforces HIPAA. Its authority reaches your hospital and your insurer. It does not reach the app on your phone. Photo: Carol M. Highsmith, Library of Congress (public domain).

So what does cover it? A rule most people have never heard of

Health data outside HIPAA is not lawless. It falls to the Federal Trade Commission under the Health Breach Notification Rule, 16 CFR Part 318, first issued in 2009 and rewritten on May 30, 2024 specifically to catch health apps.

The scope section says it applies to “vendors of personal health records, PHR related entities, and third party service providers,” and then draws the line from the other side: “This part does not apply to HIPAA-covered entities.”

Read those two rules together and the picture is complete. HIPAA covers the hospital. The FTC rule covers everyone the hospital is not. Nothing is unregulated — but the protections are different, and the FTC rule is mostly about telling you after something has gone wrong.

It has teeth, though. In February 2023 the FTC brought its first case under the rule against GoodRx, the prescription discount service, for sharing users’ medications and health conditions with Facebook, Google and Criteo after promising it never would. GoodRx agreed to a $1.5 million civil penalty and a ban on sharing health data for advertising. The FTC noted that more than 55 million consumers had visited or used GoodRx since January 2017.

That case is the reason the word “ads” matters so much in the next section.

Table comparing what happens to health information typed into ChatGPT Health, an ordinary ChatGPT chat, a Temporary Chat, Gemini and Claude
The same sentence, typed into six different boxes, is governed by six different rules. Every entry was read from the company’s own documentation on September 1, 2026.

The box you type into matters more than the app you choose

This is the part almost nobody explains, and it is the part that actually changes your risk.

Inside ChatGPT there are three different boxes, and they are not governed the same way.

Where you type it Used to train the model? How long it is kept What the company itself says
ChatGPT Health (connected records) No — and no ads Deleted within 30 days of disconnecting Excluded “regardless of the model-training setting you choose”
ChatGPT, ordinary chat Yes, unless you switch it off In your history until you delete it The switch is Settings → Data Controls → “Improve the model for everyone”
ChatGPT, Temporary Chat No Deleted after 30 days Not in history, makes no memories, “may be reviewed only to monitor for abuse”
Gemini, Keep Activity on Yes, and people read some of it Reviewed conversations up to 3 years “Please don’t enter confidential information that you wouldn’t want a reviewer to see”
Gemini, temporary chat No 72 hours Still used to respond to you and to protect users
Claude, ordinary chat Only if you allow it Feedback conversations up to 5 years Incognito chats are never used to improve Claude

Read the fourth row twice. Google’s own privacy hub, updated August 10, 2026, tells you in plain language not to type confidential information into Gemini while Keep Activity is on, because human reviewers see some of it. Nothing in this article is a stronger warning than the one Google prints itself.

And read the first row twice as well, because it is unusually good. OpenAI did not say “we will honor your setting.” It said records connected in Health are excluded from training and from ads no matter what your setting is. That is a promise that survives you forgetting to flip a switch.

A sailor speaks with a clinician over a video call at a Navy medical facility
A telehealth appointment at a U.S. Navy medical facility. The record created inside a visit like this one is protected by HIPAA. The copy you paste into a chatbot afterwards is not the same file in the eyes of the law. Photo: Navy Medicine (public domain).

The 30-day catch nobody mentions

Here is the detail buried three-quarters of the way down OpenAI’s help page, and it is the one that will surprise people.

When you disconnect a medical record account, “data synced from that source is deleted from OpenAI’s systems within 30 days.” Good. But the very next sentence says: “Information already included in your ChatGPT conversation history remains until you delete those conversations.”

In other words, disconnecting closes the pipe. It does not empty the bucket. If you spent an evening asking about your cholesterol numbers and those numbers are written in the chat, removing the account leaves every one of them sitting in your history.

Two clicks, two different jobs. Most people do the first and believe they have done both.

Two-step diagram: disconnecting an account stops the sync, deleting the conversations removes what is already written
Disconnecting and deleting are two separate actions with two separate effects. Steps and wording taken from OpenAI’s Health help article, read September 1, 2026.

What is actually on the other end

It helps to picture where the file goes. “The cloud” is a room with a floor and a ceiling and a great deal of noise, in a building owned by a company, staffed by people who have jobs and managers and, occasionally, bad days.

Encryption is real and it matters — OpenAI says all chats are encrypted at rest and in transit, with additional encryption for information connected in Health. But encryption protects the file from outsiders. It does not decide what the company may do with it. That is what the policies decide, and policies can change with a version number.

This is the practical reason for the advice in the next section: reduce what you hand over, rather than trying to predict a company’s next ten years.

Rows of server racks in a research data center
Server racks at the NERSC computing facility. Every file you upload ends its journey on machines like these, inside a building that belongs to somebody. Photo: Derrick Coetzee (CC0).

Why the answers you find are so contradictory. Of the first ten web results we pulled for this question on September 1, 2026, three were news organizations, four were companies with a product to sell in this exact area, and three were independent blogs. That is not a conspiracy — it is just a reminder to check whether the page telling you something is unsafe also sells the thing that makes it safe.

What to do with this

Eight steps. None of them takes longer than a minute, and you do not need to do all eight.

  1. Check whether Health exists on your account. Open ChatGPT, look in the sidebar, and if you do not see it, check under the “More” menu. It is available to logged-in Free, Go, Plus and Pro users in the U.S. who are 18 or older, on the web and on iPhone, running app version 1.2026.188 or later. Android is not on the list.
  2. Decide which door you want. Connecting a portal gives better answers because ChatGPT can compare a new result against old ones. Pasting one page at a time gives you tighter control. Both are defensible. Doing it half-consciously is not.
  3. If you are going to use an ordinary chat, turn training off first. Settings → Data Controls → switch off “Improve the model for everyone.” It applies to your whole account on every device.
  4. For a one-off question, use Temporary Chat. It is not saved to your history, creates no memories, and is deleted after 30 days.
  5. Take your name off. Cover the name, date of birth, member number and address before you photograph a page. The AI needs the values, the units and the doctor’s wording. It has never needed to know who you are.
  6. Ask ChatGPT to prepare questions, not verdicts. “Explain what each number on this page measures, and list five questions I should ask at my appointment” is a good use. “Do I have a problem” is not, and OpenAI says the same: Health is designed to support, not replace, medical care and is not intended for diagnosis or treatment.
  7. To undo it: Health → Accounts → the “…” menu → Remove account. Then, separately, delete the conversations themselves. Both, or you have only done half.
  8. Keep the appointment. Whatever the screen says, the person who can order a test is still the person in the office.

If you want to go deeper

  • “Can it write anything back into my chart?” No. OpenAI states plainly that ChatGPT can only read from connected records and Apple Health, and cannot update them. Nothing you say to it reaches your doctor.
  • “What about the memory feature?” Health conversations can create memories, but memories are not built directly from your synced records. You can view or delete them under Personalization in Settings, or avoid them entirely with Temporary Chat. We walk through the same controls in are deleted ChatGPT chats really deleted.
  • “Is my email being read the same way?” Different product, different setting, same instinct. See how to stop AI from reading my Gmail and does Copilot have access to my emails.
  • “What does all this cost me?” Health is included on the free plan. If you are weighing the paid tier for other reasons, we keep the numbers in the AI price tracker and the argument in is ChatGPT Plus still worth it.

Watch: two reports on what this actually looks like

10 News (1.14M subscribers), January 16, 2026 — 1,578 views when we checked on September 1, 2026. A broadcast summary of the privacy questions raised when Health was announced.
ABC13 Houston (1.52M subscribers), August 23, 2026 — 787 views when we checked on September 1, 2026. A useful reminder that AI is already inside the record before you ever touch it.

Frequently asked questions

Is it safe to upload medical records to ChatGPT?

Safe enough for most people, if you use the Health space and understand what it does not do. Records connected in Health are excluded from model training and from advertising, are encrypted, and can be disconnected at any time. What you do not get is HIPAA: OpenAI states that Health “does not offer a Business Associate Agreement.” If a leak of your specific diagnosis would cause you real harm, keep it out of any consumer chatbot and ask your doctor’s office instead.

Is ChatGPT HIPAA compliant?

The consumer version is not, and does not claim to be. HIPAA applies to health plans, clearinghouses and providers under 45 CFR 160.103, and it reaches an outside company only through a Business Associate Agreement, which Health does not offer. OpenAI sells separate products, ChatGPT for Healthcare and ChatGPT for Clinicians, for organizations that need HIPAA support.

How do I upload medical records to ChatGPT?

Open Health from the ChatGPT sidebar, or from the “More” menu, and choose Get started. You can connect Apple Health on an iPhone, a supported U.S. hospital portal, One Medical or Function Health. Sign in at your provider, approve the permission screen, and wait for the sync, which can take several minutes for a long history. You can also skip all of it and simply attach a photograph of one page to a chat.

Can ChatGPT read my lab results?

Yes, and that is one of the uses OpenAI names itself: comparing a new result with prior tests and summarizing what has changed since your last appointment. Treat the output as preparation for a conversation with a clinician. OpenAI states that Health is not intended for diagnosis or treatment.

Does OpenAI use my medical records to train its AI?

Not the ones connected in Health. OpenAI says connected medical records and Apple Health information, and conversations that use them, are not used to train its foundation models or to target ads, regardless of the model-training setting on your account. An ordinary chat is different: that one follows your Data Controls setting, so switch off “Improve the model for everyone” if you plan to paste health details into a normal conversation.

How do I delete medical records from ChatGPT?

Two separate actions. Go to Health, open the Accounts tab, use the “…” menu next to the account and choose Remove account; the synced data is deleted within 30 days. Then delete the conversations themselves, because OpenAI states that information already included in your chat history remains until you delete those chats.

Is it safe to upload medical reports to Gemini or Claude instead?

Google’s Gemini Apps Privacy Hub, updated August 10, 2026, asks you not to enter confidential information while Keep Activity is on, because human reviewers see some of it and reviewed conversations can be retained for up to three years. A Gemini temporary chat is kept 72 hours and is not used for training. Anthropic says Claude consumer chats are used to improve models only if you choose to allow it, and Incognito chats never are. Of the three, ChatGPT Health is the only one with a purpose-built space for health data.

Should I remove my name before uploading a medical record?

Yes, and it costs you nothing. Cover the name, date of birth, address and member or record number, and leave the values, units, ranges and the doctor’s notes. Those are the parts the model needs to explain the page. A result with no name attached is far less useful to anyone who should not have it.

Sources

Keep reading

Written by Prof. H. Every figure in this article was read from its primary source on September 1, 2026, and the four policy documents were downloaded and counted the same day. Our method is described on how we count; corrections go to contact.

Similar Posts