The Cures Act right that lets OpenAI's data partner b.well pull electronic records into the chatbot is the same right that ends HIPAA's coverage of them — and no in-app setting reverses it.
Health in ChatGPT is now open to logged-in users 18 and older in the US, on web and iOS: people can enter lab results and medications and link Apple Health. With the user's permission, OpenAI said in its announcement, the chatbot can draw on that connected material to set a new result against earlier tests, sum up what has changed since the last appointment, or see how sleep, activity and workouts fit a person's routine. The moment those records leave a provider for the chatbot, HIPAA stops covering them.
The law reaches only covered entities such as hospitals, health plans and doctors' practices, plus the business associates working for them; consumer AI products sit outside that group.
By default the chatbot asks for approval each time it reaches linked records; Settings allows standing access instead, or shuts access down completely. What those settings govern is access inside the app. What carries the records in is the 21st Century Cures Act, which gives patients the right to move their digital medical files into applications built by third-party firms.
That right is what lets b.well Connected Health, OpenAI's data-linking partner, pull records into ChatGPT, across a network taking in roughly 2.2 million US healthcare providers; fitness and wearable readings come from Apple Health on iOS. After the handoff, nothing inside the app puts the protection back: records stay under the law only through a HIPAA-covered arrangement, such as ChatGPT for Healthcare and ChatGPT Enterprise with Regulated Workspace, which OpenAI sells separately to clinical and business customers. The consumer tool is not one of them.
Company policy is what applies in HIPAA's place. OpenAI says the records a person hands to ChatGPT Health will neither feed the training of its models nor be used to aim advertising, and that doctors took part in building and trying out health scenarios ahead of launch. Unlinking a health account sets off erasure of the synced data inside 30 days — the record of conversations, by contrast, stays put until the user removes it by hand. The company also says Health is not a substitute for the care and judgment that qualified medical professionals provide.
Sara Geoghegan, senior counsel at the Electronic Privacy Information Center, said those disclosures and pledges are all that hold OpenAI to account. Feeding digital medical files to ChatGPT Health would leave them without HIPAA's protections, she said, and she described that as dangerous; absent a real constraint such as a regulation or a statute, ChatGPT is free to rewrite the terms of its service whenever it likes. AI firms have revised their service terms without fanfare before, and the FTC has cautioned the public that handing information to such firms carries risk precisely because those terms can shift.
By OpenAI's account, 300 million people are putting health questions to ChatGPT in a typical week.
The same b.well plumbing sits underneath Perplexity Health, Samsung's Kill the Clipboard initiative and Google's health AI efforts. Protection falling away at the handoff to a third party has become the standard design in consumer AI's handling of medical data, not one firm's isolated choice.