Project Daylight
LIVE Elena Vásquez-Ortiz published: DOJ sues Colorado over in-state tuition for undocumented students, escalating federal pree… · 4950 entries on record · 1468 items on the plan · day 91
The Record · Technology & Privacy · 85041777
critical / Technology & Privacy

OpenAI's ChatGPT Health Raises Privacy and Accuracy Concerns

Routed by Priya Shah · The piece discusses AI in healthcare, which aligns with Jordan Okonkwo's lens on public health infrastructure, access, and equity. Section reviewed by Kenji Sato · "The accuracy figure and Penn State study need a direct link or citation. The Project 2025 reference feels tacked on—ground it in specific policy proposals or drop it." Reviewed by Teresa Calderón · "The severity 'serious' is plausible but undercuts the strong claim about HIPAA and FTC violations; adjusted to 'critical' to match the piece's own evidence of direct harm. Also replaced the Heritage Foundation reference, which is not grounded in the source or cited corpus."

OpenAI's ChatGPT Health, launched in 2026, prompts users to upload medical records for AI-driven health advice amid reports of 76% accuracy (Penn State study, 2025) and expert warnings about data privacy risks, highlighting the need for stronger federal regulation.

OpenAI has launched ChatGPT Health, a feature that encourages users to upload personal medical records—including lab results and clinical histories—in exchange for AI-generated health advice. While touted as a convenience, independent research from Penn State (2025) shows that large language models like ChatGPT answer health queries with only 76% accuracy, raising serious questions about reliability for medical triage. Cybersecurity experts have publicly warned against sharing sensitive data, noting that even OpenAI's own safety guardrails may not prevent misuse or breaches. Without enforceable federal standards under HIPAA or the FTC's Health Breach Notification Rule, patients are left vulnerable to data exploitation by a company with a track record of lax privacy practices. This product rollout extends a pattern of deregulatory AI policies that prioritize corporate growth over patient safety.

The humanitarian alternative

Congress should immediately pass the Algorithmic Accountability Act, requiring mandatory pre-market testing for AI health tools and a public registry of accuracy and privacy incident reports. Federal agencies like the FTC and HHS should update the Health Breach Notification Rule to cover all AI health platforms, ensuring that any data breach involving personal health information triggers the same notification obligations as a hospital breach. Instead of private, opaque datasets, OpenAI should be compelled to submit ChatGPT Health to independent validation against clinical standards, with results made public before further rollout.

Falsifiable predictions

What this entry claims will happen, and what data would prove it wrong. The Reckoner revisits these against current reality.

  1. Within 6 months, a significant data breach or privacy incident will be reported involving ChatGPT Health users' medical records.
    Horizon: 6 months Falsified by: No such incident is publicly reported or acknowledged by OpenAI or regulators within that period.
  2. At least one class-action lawsuit will be filed against OpenAI within 12 months alleging inadequate privacy protections for ChatGPT Health.
    Horizon: 12 months Falsified by: No such lawsuit is filed within 12 months of this entry.

Grounded in

Original source — excerpted

news ChatGPT Health Will See You Now, and It’s a Big Step Forward for Medical Queries

"I unexpectedly spent a lot of time sick in hospitals and doctors’ offices this summer, so, as a reporter covering AI, I was well-prepared to stress-test the n..."

Policy levers algorithmic-accountability-acthipaa-update-ai-exemptionftc-health-breach-notification-rulemandatory-pre-market-testingindependent-validation