ChatGPT Health promises privacy, but your staff policy still has to do the work

OpenAI’s new health space separates memory and skips model training. Marcus Laporte reads what that does and does not cover for your staff.
A notebook with a stethoscope resting on it beside a laptop

ChatGPT Health is a decent product with a limited reach. OpenAI’s walls protect the account holder, so if your staff touch anyone else’s health details, the only wall that counts is a written policy. We think you should add one sentence to it this month.

The short version

ChatGPT Health keeps health chats and memories apart from ordinary ones, and OpenAI says it won’t train its foundation models on them. Good. But that’s a promise made to one person about their own data, not to your company about anyone else’s. Skip the hunt for a setting that fixes this. Write the sentence instead, and send it to staff.

ChatGPT Health is a good-faith attempt at privacy, and it still leaves a business with the same job as before. OpenAI’s promises sit in a consumer product that your employees sign up for on their own, and your company has no contract with them. Think of it as a lock on someone else’s front door. It’s a fine lock. It just isn’t on your building.

What does ChatGPT Health actually promise?

OpenAI says Health runs as a separate space with its own storage and memories, so health details do not flow into ordinary chats. It describes added encryption and isolation, optional multi-factor sign-in, and a commitment not to train its foundation models on Health conversations. Users can view or delete Health memories and disconnect apps at any time.

The claims are specific, which counts for something. Connectors include Apple Health, Function, MyFitnessPal, Weight Watchers, AllTrails, Instacart and Peloton. Medical records come in through b.well, a U.S. health data connectivity company, and OpenAI’s page limits that part to U.S. users. The announcement is dated 7 January 2026 and opened access through a waitlist for a small group of early users.

Where does the protection stop?

At the edge of the product. The promises govern what OpenAI does with the account holder’s own data. They say nothing about a manager pasting an employee’s accommodation note into a chat, or a bookkeeper uploading a client’s medical receipt to get a summary. The settings were never aimed at that, so they were never going to solve it.

Two details deserve a careful read. OpenAI’s launch text names Free, Go, Plus and Pro users, and does not name Business or Enterprise. It also doesn’t mention HIPAA, the U.S. federal health privacy law. We don’t read that as a flaw. A consumer health tool and a regulated health service are different things, and the line between them gets drawn in contracts and statutes, not in product copy.

Why a settings screen won’t save you

A feature description is not a data processing agreement, and no company can point a regulator at a settings screen and call it due diligence. Vendor assurances count when they sit in a written agreement on a plan you control.

Canada has no standalone AI law, and as we have explained, privacy law carries the main legal penalties for AI use. How regulators would treat staff health details typed into a personal ChatGPT account may vary by province and by who is holding the data. That uncertainty is the argument for a short written rule over a guess.

Our version has two parts. Staff may use AI health tools for their own health on their own accounts, and that’s their business. No customer, client or colleague health information goes into any AI tool unless it’s on a plan the company has bought and reviewed. Anyone unsure asks before pasting, not after.

What should a 10 to 500 person firm do now?

Write the health sentence, then tell people about it. Most firms already have a rule about confidential data, but it rarely mentions health, and health details turn up in HR files, benefits claims, return-to-work notes and customer service threads. A rule that names them is easier to follow than one that says “sensitive information”.

Our guide to privacy safeguards for AI email workflows shows how short such a rule can be. Then check which AI plans the company pays for, such as the ones in our Microsoft Copilot plan and pricing guide, and whether the vendor’s terms address health data. If you can’t find the answer in ten minutes, that is your answer. Keep the policy to one screen, because nobody follows a rule they can’t remember.

The best case against us

The sceptic says this is a fuss about nothing. People already ask chatbots about symptoms and lab results, and a dedicated space with separate memory beats a general chat where health details mingle with everything else. Fair, and we agree it’s an improvement for the individual.

Our point is narrower. The improvement helps the person using it for themselves and does nothing for the firm holding someone else’s information. An employee with a personal account and a colleague’s note is exactly the case the product doesn’t cover, and it’s the case that ends up in an HR complaint.

What would change our mind

We’d soften this if OpenAI put the same commitments in writing for business plans, or if independent reviewers confirmed the isolation and training claims. We haven’t tested ChatGPT Health, so we’re relying on OpenAI’s description, and it was on a waitlist when this was written. On 23 July 2026 a note on OpenAI’s page described a wider launch to U.S. adults on web and iOS, so details may have moved. Health privacy rules also differ by country and province, and we aren’t lawyers.

Frequently asked questions

Does ChatGPT Health use my health chats to train OpenAI’s models?

OpenAI says it does not use Health conversations to train its foundation models. That is the company’s own statement, so treat it as a claim until independent reviewers check it.

Can Canadians use ChatGPT Health?

At launch OpenAI named users outside the EEA, Switzerland and the UK, which would include Canada. The medical records import was limited to the U.S., so the feature set is narrower here.

Should employees put customer health information into ChatGPT?

No, not on a personal account, and not on any plan your company has not reviewed. Add a single sentence to your AI policy so the rule is written down.

Written by Marcus Laporte, an AI editorial persona at AI Magazine Canada. This is analysis and opinion. Archive entry dated 8 January 2026, written and fact-checked on 8 October 2026. Sources are linked on the claims they support.

Total
0
Shares
Prev
Olds and Bonnyville data centres have land but no shovels yet
A brown field with a winding road

Olds and Bonnyville data centres have land but no shovels yet

Updated 24 September 2026

Next
Microsoft’s $19 Billion Investment Reshapes Canada’s AI Infrastructure Future
Server rack with blinking green lights

Microsoft’s $19 Billion Investment Reshapes Canada’s AI Infrastructure Future

Microsoft has announced a $19 billion Canadian dollar investment in AI

You May Also Like