ChatGPT Health lets a user connect personal health data — Apple Health metrics and hospital medical records from providers like Epic, Oracle Health, and One Medical — directly to their ChatGPT conversations, so the assistant can reference real lab results, medications, and fitness trends when answering health questions. It is built into the main chat interface for logged-in users in the United States who are 18 or older, on every plan from Free up to Pro. The tool is not a substitute for a doctor, and — despite the name — it does not carry the same legal protections as your hospital’s own records system.

What Health Actually Does

Once a user connects a data source — Apple Health on iOS, or a supported hospital system through the guided linking flow — Health can compare lab values across visits, flag trends in vitals or fitness data, help prepare questions before an appointment, and factor a health condition into ordinary chat requests, such as suggesting a restaurant that fits a dietary restriction or recommending lower-impact exercise after an injury. ChatGPT asks permission before using connected records in a given conversation, unless a user has switched that prompt off in settings.

This puts OpenAI alongside Apple, Google, and a wave of digital-health startups building consumer tools around the same idea: personal health data is more useful to an AI system when it can read the records directly, instead of a person retyping numbers off a lab PDF.

How Your Data Is Handled

OpenAI says connected health information is never used to train its underlying models, is encrypted both in transit and at rest, and carries extra access logging beyond a standard ChatGPT conversation. If a user disconnects a data source, OpenAI says the synced records are deleted within 30 days. Those are real, meaningful safeguards — but they are commitments written into OpenAI’s own privacy policy and terms of service, not obligations imposed by a health-privacy law.

The HIPAA Gap

That distinction matters because of how HIPAA actually works. The US health-privacy law binds only “covered entities” — hospitals, clinics, insurers, and the vendors that process data on their behalf under a Business Associate Agreement. A consumer typing their own lab results into a chatbot isn’t a covered transaction, so the data OpenAI receives through Health isn’t protected the way it would be inside a hospital’s electronic record system. OpenAI has said it will not sign a Business Associate Agreement for ChatGPT Health users, because the product is meant for general health literacy rather than regulated clinical care; it offers a separate, HIPAA-eligible product for hospitals and health systems, but that is a different tool with different terms. In practice, this means the main recourse if something goes wrong with consumer health data is OpenAI’s privacy policy and a patchwork of US state privacy laws — protections that vary from state to state and are considerably weaker than HIPAA.

How to Turn It On

Health is currently limited to logged-in, US-based adults on the web and iOS apps. From the ChatGPT sidebar or “More” menu, selecting Health and “Get started” walks through connecting a data source — Apple Health on iOS, or a supported hospital system through the guided linking flow. Permissions can be adjusted or revoked later from Settings. A step-by-step walkthrough of the rollout is available from iClarified. Users outside the US, or under 18, don’t currently have access to the feature.

In the news

OpenAI’s decision to open Health to every eligible US adult was covered in our daily brief — part of a broader push by AI labs into consumer healthcare that also connects to how AI is already used in medicine more generally.