What to Know Before Uploading Your Medical Records to an AI App
More than 300 million people turn to ChatGPT alone each week with health-related questions. Now, several of the world’s largest AI companies have gone further — offering programs that connect directly to users’ medical records, wearable devices, and wellness apps to provide more personalized health guidance. Experts say the capabilities are genuinely useful, but the privacy landscape is far less straightforward than the companies’ marketing suggests.
What These Programs Do
In less than three months at the start of 2026, five major AI companies launched dedicated health products in rapid succession. OpenAI introduced ChatGPT Health in January, allowing users to connect medical records from providers using Epic and Oracle Health systems, along with data from Apple Health, MyFitnessPal, and other wellness platforms. Anthropic offers similar features for some users of its Claude chatbot. Microsoft launched Copilot Health in March. Google announced its AI Health Coach through the updated Fitbit app in May. Perplexity has also entered the space.
Each product follows a similar model. Users can sync electronic health records through third-party intermediaries such as b.well or HealthEx, connecting prescription data, lab results, doctor’s notes, and wearable device metrics directly to an AI chatbot. The AI can then answer health questions with context drawn from a user’s own medical history — tracking what has changed in their health over time, offering personalized nutrition suggestions based on lab results, or helping them prepare more informed questions for a doctor’s appointment.
A March poll from health policy organization KFF found that one in three American adults say they have consulted AI about their health. Of those who asked health questions, 41% uploaded personal medical information.
The Core Privacy Problem: HIPAA Does Not Apply
The most significant concern experts raise is one that many users do not realize. HIPAA — the Health Insurance Portability and Accountability Act, which governs the privacy of medical records held by doctors, hospitals, and insurers — does not apply to AI companies. There are no federal fines or criminal penalties for a chatbot company that mishandles your health data the way there would be for a hospital.
“Consumers need to understand that there are completely different privacy standards,” said one privacy researcher who has analyzed all five products. Each company says it keeps health information separate from other chat data and does not use it to train foundational AI models. But those are voluntary commitments, not legal obligations.
What the Medical Records AI Apps Privacy Risks Look Like in Practice
A detailed analysis of all five products found that while the companies’ stated policies are broadly similar — promising purpose-built encryption, data isolation, and user control — the enforcement mechanisms, audit rights, and third-party sharing arrangements vary significantly and are often described in vague terms.
One important distinction: users connect to medical records through third-party intermediaries, meaning their health data passes through at least one additional company before reaching the AI system. Each intermediary has its own privacy policy and data security standards, which users rarely read before clicking “connect.”
OpenAI says health conversations are stored separately from general chat, protected with additional layers of encryption, and never used to train its models. Anthropic makes similar commitments for Claude for Healthcare. Both companies say users can remove access to their health data at any time. None of the five companies have yet been subject to an independent security audit of their health-specific products.
What Experts Recommend Before Connecting Your Data
Medical and privacy experts say the technology can be genuinely valuable — particularly for patients managing complex conditions who want help making sense of lab results or tracking changes across multiple visits. But they urge deliberate caution rather than reflexive adoption.
Dr. Lloyd Minor of Stanford University recommends approaching AI health programs with “a degree of healthy skepticism,” even during non-emergency situations. He and others stress that the chatbots are not substitutes for clinical care and should not be used to make treatment decisions.
Dr. Robert Wachter, a physician and health technology researcher, advises giving AI chatbots as much medical context as possible when asking health questions — including age, conditions, and medications — to improve the relevance of responses, even if users choose not to connect full medical records. He and others note that connecting records does improve accuracy but also meaningfully increases privacy exposure.
Experts advise users to read the privacy policy of both the AI company and any third-party health data intermediary before connecting records. They also recommend enabling multi-factor authentication on any account containing health data, and checking settings regularly to confirm which apps retain access.
When Not to Use AI for Health Concerns
Regardless of which AI platform a user chooses, experts are unanimous that certain symptoms require bypassing AI entirely and seeking immediate medical attention. These include shortness of breath, chest pain, severe headache, sudden confusion, or any symptom that could indicate a medical emergency. AI chatbots are not designed or equipped to triage emergencies in real time.
Author: Staff Writer | Edited for WTFwire.com | SOURCE: CNN
: 21