The HIPAA gap behind OpenAI's no-training promise
OpenAI is emphatic that connected medical records and Apple Health data are not used to train its models or target ads [1]. That promise, however, sidesteps the question privacy advocates are actually raising: once records leave a hospital's Epic or Oracle Health system and enter ChatGPT, they exit HIPAA's jurisdiction entirely, because OpenAI is not a HIPAA covered entity [2]. EPIC senior counsel Sara Geoghegan put it bluntly - connecting records to ChatGPT Health 'would remove the HIPAA protection from those records, which is dangerous.' The Center for Democracy and Technology's Andrew Crawford raised a related, unanswered question: how would OpenAI respond to a law enforcement request for that data, and is it genuinely separated from a user's other ChatGPT conversation history [2]. In other words, the safeguards a user gets are whatever OpenAI's current policy says they get - not a federal statute - and that policy can change unilaterally. Community discussion of the beta added a practical wrinkle worth noting without a formal citation: some early users reported that opting into ChatGPT Health routes their entire account's health-adjacent conversations into a separate, more restrictive model container, meaning the permission toggle may reach further into everyday use than it first appears.



