Vidaya
VIDAYA
PricingDemoAboutPartnersTeamIntegrationsFAQContact
Vidaya
VIDAYA
Vidaya
VIDAYA
Sign InGet Started
  1. Home
  2. Health Data Privacy

Sharing Your Health Data With AI: What's Safe, What's Not, and How to Tell the Difference

Millions of people now turn to AI chatbots for health guidance: asking about symptoms, uploading lab results, or seeking second opinions on diagnoses. The appeal is obvious. AI is available at 2 a.m., it does not judge, and it can synthesize complex medical language into plain English. But the question almost nobody asks before pasting their bloodwork into a chat window is: where does this information actually go, and who controls it?

AI health data privacy is not a hypothetical concern. The rules that govern your data vary dramatically depending on which tool you use, which pricing tier you are on, and whether the company has signed a specific legal agreement. This guide explains the key distinctions, gives you a practical framework for evaluating any AI health tool, and is direct about what "safe" actually means in this context.


Is ChatGPT HIPAA Compliant? The Honest Answer

The short answer: it depends entirely on which version of ChatGPT you use, and whether a specific legal agreement is in place.

What HIPAA actually requires

HIPAA (the Health Insurance Portability and Accountability Act) sets federal rules for protected health information (PHI). It applies to covered entities (hospitals, clinics, insurers, clearinghouses) and their business associates, the vendors that handle PHI on their behalf.

When a covered entity engages a technology vendor to process PHI, HIPAA requires that vendor to sign a Business Associate Agreement (BAA). A BAA legally obligates the vendor to protect PHI, limits its use, and requires breach notification. Without a signed BAA, transmitting PHI to that vendor is a HIPAA violation.

Consumer ChatGPT: not HIPAA eligible

Consumer ChatGPT plans (Free, Plus, Pro, and Team) are not HIPAA eligible, and OpenAI does not offer a BAA for these tiers. OpenAI's privacy policy indicates that content from consumer accounts may be used to improve models unless users opt out. As the HIPAA Journal explains, entering PHI into consumer ChatGPT risks a HIPAA violation because no BAA is in place. Dr. Genevieve Kanter of USC stated: "Once you enter something into ChatGPT, it is on OpenAI servers and they are not HIPAA compliant. That's, technically, a data breach."

ChatGPT Enterprise and OpenAI for Healthcare: a conditional yes

OpenAI does offer BAA-eligible products. According to OpenAI's help center, BAAs are available for the API platform (on zero-data-retention eligible endpoints) and for sales-managed ChatGPT Enterprise or Edu accounts. OpenAI's Healthcare Addendum identifies the "Eligible Services" for PHI processing, and OpenAI launched ChatGPT for Healthcare in early 2026 as an enterprise product with role-based access controls, audit logs, and model training disabled by default.

A signed BAA covers OpenAI's obligations, not yours. An organization must still configure the eligible service correctly, restrict access to appropriate users, and maintain its own HIPAA risk analysis. As compliance analysts at WitnessAI note, buying ChatGPT Enterprise does not flip a "HIPAA compliant" switch. It is a starting point.

For individual consumers, none of these enterprise pathways apply. If you share your medical records with ChatGPT on a consumer account, you are not protected by HIPAA.


What Happens When You Paste Medical Records Into ChatGPT

Even setting aside the HIPAA question, pasting raw medical records into a consumer AI chatbot carries several concrete risks worth understanding before you do it.

Training data exposure

OpenAI's privacy policy states that content submitted through consumer products "may" be used to improve services, including model training, unless you opt out. Even with opt-out enabled, your data passes through OpenAI's infrastructure. Time Magazine's January 2026 investigation quoted Bradley Malin of Vanderbilt's biomedical informatics department: "If you are providing data directly to a technology company that is not providing any health care services, then it is buyer beware." There is no professional duty of confidentiality equivalent to the one your physician carries.

OpenAI retains conversation data per its own policies. For the API, data submitted without a BAA may be retained up to 30 days for abuse monitoring before deletion. For consumer accounts, retention depends on your settings. Temporary chats are kept up to 30 days; standard chat history is kept longer. Vendors and service providers to OpenAI may receive data as part of normal operations, per the privacy policy's third-party sharing disclosures.

You may believe that removing your name before pasting records protects you. It rarely does. HIPAA defines 18 categories of identifiers, including dates, geographic data smaller than a state, account numbers, and device identifiers, any of which can contribute to re-identification. A 2025 review of 464 studies on LLMs and patient data, published in the Journal of Medical Internet Research, found that pretrained LLMs can infer personal attributes such as location and income from seemingly innocuous text with high accuracy.

Any data stored in your ChatGPT account is subject to the same breach risks as any cloud account. If your credentials are compromised, your entire chat history (including any health information you have shared) is exposed. Unlike a HIPAA-covered breach at a hospital, you would have no statutory notification rights as an individual ChatGPT user.


The 7 Questions to Ask Any AI Health App

When we were evaluating infrastructure vendors and third-party integrations for Vidaya, I went through a privacy audit of five finalist platforms. Three of the five had data-sharing language that would allow them to pass health context to advertising partners. One had no health-specific privacy policy at all, just a generic terms page last updated in 2019. We disqualified that one on the spot. The other two required legal back-and-forth before they could clarify what "improving our services" actually meant for PHI. That experience shaped the list below.

Before sharing health information with any AI product, get answers to these seven questions. A transparent, privacy-first app will answer all of them clearly in its documentation.

1. Does the company offer a HIPAA Business Associate Agreement, and have they signed one? A BAA is the legal foundation for any HIPAA-compliant data processing. If the company cannot point you to BAA documentation, they are not operating in a HIPAA-eligible framework. Note that a BAA must be signed before any PHI is transmitted, not after.

2. Is your data used to train AI models? Ask specifically whether your inputs, queries, or health data are used as training examples for any model, whether the company's own or a third-party provider's. "We may use data to improve services" is not an acceptable answer to this question. Look for an explicit "no training on user data" commitment in writing.

3. Is data encrypted at rest and in transit? At-rest encryption (ideally AES-256) protects stored data from unauthorized access. In-transit encryption (TLS 1.2 or higher, preferably TLS 1.3) protects data in motion. Both are minimum requirements, not differentiating features.

4. Where is your data stored? Data residency matters. Data stored on US-based servers is subject to US law, including HIPAA enforcement by the HHS Office for Civil Rights. Data stored in foreign jurisdictions may be subject to foreign government access requests. Ask whether data can leave the country.

5. Can you delete your data, and how? A trustworthy platform provides a clear, user-controlled deletion mechanism and honors requests promptly. Vague language like "we may retain data for legitimate business purposes" without specifying a timeframe is a red flag.

6. Is your data shared with third parties, and who are they? Advertising networks, data brokers, analytics vendors, and sub-processors all represent potential exposure. Ask whether any third party is permitted to use your data for its own purposes. If the app is free and shows ads, your data is part of the revenue model.

7. What is the company's breach history? The FTC's Health Breach Notification Rule requires vendors of personal health records to notify consumers and the FTC following a breach. Undisclosed incidents or a pattern of breaches signals poor security culture.


How Regulated AI Health Platforms Differ

Consumer AI tools are built for general-purpose use and retrofitted for sensitive data use cases. Purpose-built, regulated AI health platforms start from a different design premise.

HIPAA-eligible architecture

A HIPAA-eligible architecture means the system was designed from the ground up to handle PHI within the constraints of the Privacy Rule and Security Rule. This includes formal risk analyses, documented policies and procedures, physical and technical safeguards, and workforce training, rather than encryption and access controls bolted on after the fact.

Audit logs

HIPAA's Security Rule requires covered entities and their business associates to implement mechanisms that record and examine activity in systems containing PHI. Audit logs create an accountable trail: who accessed what data, when, and from where. Consumer apps rarely provide this.

Role-based access controls (RBAC)

In a regulated platform, access to PHI is governed by role. Only users with a documented need can access specific data. This limits the blast radius of an account compromise and enforces the HIPAA minimum-necessary standard.

Signed BAAs and subprocessor chains

A regulated platform not only signs a BAA with its customers but also ensures that any subprocessors (cloud infrastructure providers, AI API vendors, analytics tools) are themselves under BAA or equivalent contractual data protection obligations. An unprotected subprocessor breaks the chain of accountability.

SOC 2 Type 2 certification paths

SOC 2 Type 2 reports, issued by independent auditors, verify that a company's security controls operated effectively over an audit period (typically 12 months). Ask any AI health app whether they hold a current SOC 2 Type 2 report and whether it is available for review under NDA.


How Vidaya Handles Your Data

Vidaya built its platform on the premise that useful AI health insights and control over your own data are not a trade-off.

The platform is built on a HIPAA-eligible architecture, meaning the infrastructure, policies, and contractual chain are designed to meet HIPAA Privacy and Security Rule requirements for platforms that handle protected health information.

Your health data is never used to train AI models. Queries you submit to Vaya Chat are processed to generate your response; they are not retained as training examples or shared with AI providers for model improvement.

All user data is processed and stored by BAA-bound infrastructure providers. Vidaya selects cloud and AI subprocessors that operate under signed Business Associate Agreements, keeping your information within a contractually protected chain of custody.

Data is encrypted at rest using AES-256.

Data in transit between your device and Vidaya's servers is protected by TLS 1.3.

Authenticated and sensitive pages do not load third-party advertising trackers. Marketing pixels are restricted to public marketing pages and do not receive health-context data.

You can delete your account and all associated data from your account settings or by contacting [email protected]. Deletion requests are processed within 30 calendar days. Vidaya does not sell user data to insurers, employers, data brokers, or any other third party.

Vaya Chat is designed to answer your health questions without sending raw PHI to general-purpose consumer LLMs, keeping sensitive data within the platform's controlled environment.

For full legal detail on data handling, our Privacy Policy and Terms of Service are attorney-drafted documents that govern the relationship between you and Vidaya.

Vidaya membership is $10 per month or $89 per year. You can also explore how Vidaya connects to your wearable data or calculates your biological age. Start your Vidaya membership.


Red Flags: How to Spot an AI Health App You Should Not Trust

Not every app that collects health data deserves your trust. These warning signs suggest a platform that has not made privacy a design priority.

No privacy policy, or a policy that does not address health data specifically. A generic "we respect your privacy" statement is not a privacy policy. A legitimate health platform will specify what data is collected, how it is used, who it is shared with, how long it is retained, and how you can exercise your rights.

Vague language about data use. Phrases like "we may share data with partners to improve your experience" or "we use data to provide and improve our services" are legally permissive enough to cover almost anything. Look for explicit prohibitions: "we do not sell your data," "we do not use your data for advertising," "we do not train models on your data."

The platform sells your data or profits from data partnerships. Free apps frequently monetize health data through advertising, data brokerages, or research partnerships. Review the revenue model before sharing sensitive information. If the app is free with no subscription, your data is almost certainly generating revenue somewhere.

No disclosed business model. An app with no subscription fee, no advertising, and no visible revenue source has an opaque business model. In the health space, opacity often resolves to data monetization.

Foreign data residency without clear protections. Data stored abroad may be subject to government access requests outside the reach of US law. If a privacy policy does not specify where data is stored, or discloses foreign server locations without explaining what protections apply, that is a material gap.

No breach notification process described. Trustworthy platforms explain what they will do if a breach occurs. Silence on breach notification means the company has not committed to telling you.


Frequently Asked Questions

Can I use ChatGPT for general health questions? Yes, for general questions that do not include your name, date of birth, diagnosis codes, or any identifying information, free ChatGPT presents lower risk. Once you combine a condition with a date, a location, or a name, you have created a potential privacy exposure. Keep general queries genuinely general.

What if I redact my name before pasting medical records into ChatGPT? Removing your name is rarely sufficient. HIPAA defines 18 categories of identifiers, including dates, geographic data smaller than a state, phone numbers, and email addresses. A lab result with a date and a ZIP code can still be re-identifiable. True de-identification requires the HIPAA Safe Harbor method or an expert determination process, not a manual find-and-replace.

Is Apple Health private? Apple Health data is stored on-device and encrypted. Apple does not sell Health data or use it for advertising. However, when you share Apple Health data with a third-party app, that app's own privacy policy governs how the data is used. Review the privacy terms of any app you connect to Apple Health before granting access.

What about Google Gemini and health data? Consumer Google Gemini is not covered by a HIPAA BAA and is not designed for PHI. Google does offer HIPAA-eligible services through Google Cloud under its BAA framework, but the consumer Gemini app carries the same risks as consumer ChatGPT when used with medical records.

Can I delete my data from Vidaya? Yes. You can delete your account and all associated data from your account settings or by emailing [email protected]. Deletion requests are processed within 30 calendar days.

Does Vidaya sell my data to insurers? No. Vidaya does not sell user data to insurers, employers, data brokers, or any third party. The platform is subscription-funded. Your health data is not the product.

Does Vidaya train AI models on my data? No. Your health data is not used to train or fine-tune AI models.

What happens if Vidaya is breached? In the event of a breach involving protected health information, Vidaya would notify affected users per applicable requirements, including the HIPAA Breach Notification Rule and the FTC Health Breach Notification Rule.


Sources: HHS HIPAA Covered Entities guidance | HHS Business Associates guidance | HHS HIPAA Security Rule | OpenAI Privacy Policy | OpenAI BAA Help Center | OpenAI Healthcare Addendum | HIPAA Journal: Is ChatGPT HIPAA Compliant? | FTC Health Breach Notification Rule | FTC Health Privacy guidance | Time: Is Giving ChatGPT Your Medical Records a Good Idea? | PMC: Considerations for Patient Privacy of Large Language Models in Healthcare | PMC: Evaluating privacy leakages in LLM-driven ambient clinical documentation

Ready to see your data?

Connect your wearables, upload your labs, and get AI-powered health insights personalized to you.

Get Started

Related Articles

HIPAA Compliant AI Health Apps: How to Verify and Pick One

What HIPAA compliance actually requires for an AI health app: BAAs, AES-256 encryption, audit logging, and red flags to avoid. A practical verification checklist.

Is ChatGPT Safe for Health Data? An Honest 2026 Answer

ChatGPT is not HIPAA-covered for consumer users. This guide explains what actually happens to health data you paste into it, the real risks, and safer alternatives.

Sharing Medical Records With AI: What's Safe in 2026

What are the real risks of sharing medical records with AI tools? Learn how to assess safety, what to redact, and which platforms offer HIPAA-eligible protections.

Vidaya LogoVIDAYA

Advanced longevity intelligence for proactive health optimization. Transform your metrics into a longer, healthier life.

Download on theApp Store
GET IT ONGoogle Play
4Product Hunt#4 Product of the Day
Vidaya LLC • 5540 Centerview Dr Ste 204
Raleigh, NC, 27606-8012, USA

Product

  • Interactive Demo
  • Health Score (VAI)
  • Blood Test Tracking
  • DNA Analysis
  • Body Composition
  • Device Connections

Learn

  • What Is the VAI Score?
  • Blood Test Tracking
  • DNA Health Insights
  • Body Composition

Resources

  • Blog
  • What's New
  • Compare
  • Social Impact
  • Help Center & FAQ
  • Pricing
  • Community

Company

  • Our Mission
  • Our Team
  • For Employers
  • Get in Touch
  • Privacy Commitment
  • Terms of Service
  • Cookie Policy
© 2026 VidayaPatent Pending — USPTO App. No. 19/389,347PrivacyTermsContact

Built for longevity

HIPAA-COMPLIANT SAFEGUARDS
Pencils of PromisePencils of Promise Partner
Vidaya provides health insights for informational purposes only. This is not medical advice. Consult your healthcare provider for medical decisions.