On July 23, 2026, OpenAI announced it is rolling out ChatGPT Health to individual users in the US who are 18 or older. The rollout covers all four plans, from Free to Pro, and will reach Web and iOS over the coming weeks. Beyond expanding the user base, this change lets users reference connected medical records and Apple Health data—based on user permission—within ordinary ChatGPT conversations, not just a dedicated space. The initial version, launched in January, kept health information isolated in a dedicated space, but the July version instead uses permission settings and memory management as the boundary.

AD

According to OpenAI, more than 300 million people worldwide ask ChatGPT health-related questions every week. This figure refers to weekly users across ChatGPT generally—not the number of questions or the number of ChatGPT Health users specifically. As Health opens up to all four individual plans in the US, a portion of these users will be able to connect their own records.

In the initial rollout, users had to switch to Health in the sidebar to benefit from connected data. But more than 70% of health-related conversations among early users arose in the middle of other topics—like discussing meals or planning trips—and continued outside the dedicated space. In situations like choosing a restaurant based on allergies, or planning a family's weekend activities around a recent injury, the act of switching conversations broke the flow.

The new Health remains available as a management hub in the sidebar, where users can check their connections, synced records, and recent trends. But questions can now be asked from anywhere in ChatGPT. Even users in the US who meet the requirements won't all get access simultaneously; OpenAI's help page states that the rollout to all eligible users may take several weeks. Connecting Apple Health requires an iPhone, and the feature isn't supported in Codex.

The path data takes—from medical records to everyday conversation

Supported connections include Apple Health, participating US hospital systems, One Medical, and Function Health. Data that services like Whoop, Oura, and Garmin write to Apple Health can also be read by ChatGPT, within the scope allowed by iOS permissions. However, service-specific metrics such as proprietary sleep scores may not be passed to Apple Health, so what's displayed in the original app and in ChatGPT may not always match.

ChatGPT can reference medications, test results, and recent visits. Sleep and activity data are also included. Access is read-only—ChatGPT cannot modify records at the hospital's system or in Apple Health. Because synced medication information can sometimes persist even after a medication is discontinued, OpenAI recommends that users cross-check against the original records and update information themselves.

When health information is used in a general conversation, a permission prompt appears by default each time. Users can choose to allow it just once or to always allow it. To explicitly invoke health context in a specific conversation, users can type "@Health". Switching to "always allow" removes the confirmation prompt, so it's up to each user to decide how far they want to let health information surface in unrelated conversations.

AD

From isolation to permission management: how the privacy boundary has changed

In January, OpenAI explained that Health conversations and files were separated from regular conversations, and that information within Health—including the app and its memory—would never flow back out. In the July version, connected information can now be carried into general conversations. Existing Health conversations and files remain in projects that retain their isolation settings, but under the new approach, it's not "which screen you're in" that determines information use—it's the permissions granted to the Health plugin.

Connected medical records, Apple Health data, and conversations that use them are not used to train the foundation model or for ad targeting. If connected data isn't used in a regular ChatGPT conversation, the account's standard training settings apply as usual—not every conversation is treated as a Health conversation. In addition to encryption at rest and in transit, connected data receives an extra layer of encryption protection.

Memory needs to be considered separately. While synced medical records and Apple Health metrics themselves are not directly used to create memories, the content of conversations that use Health can still become material for personalizing future conversations if memory is enabled. Users who want to keep health-related memories separate from other conversations can use a separate project and select project-specific memory. Using Temporary Chat or disabling memory prevents new memories from being created at all.

Deletion, too, isn't a single-step process. Disconnecting a data source deletes the synced data from OpenAI's systems within 30 days, but information already incorporated into conversations remains until the chat history itself is deleted. Additionally, the Health Privacy Notice states that unless users opt out, a limited set of personnel and trusted vendors may access Health data for the purpose of improving model safety. "Not used for training" and "never touched during safety reviews involving humans" are not the same thing.

Gains on HealthBench don't equal diagnostic accuracy

OpenAI uses a network of more than 260 physicians to evaluate its health-related capabilities. Participants span 60 countries, covering 49 languages and 26 medical specialties. As of June 2026, OpenAI says it has evaluated more than 700,000 response samples. On HealthBench Professional, physician-authored rubrics score responses not just for accuracy and safety, but also for explanation quality, contextual understanding, and appropriate recommendations to seek care.

According to GPT-5.6's System Card, length-adjusted HealthBench Professional scores are 60.5 for Sol, 57.7 for Terra, and 55.7 for Luna—all above GPT-5.5's 51.8. However, the same System Card shows that Sol's scores on the standard HealthBench and HealthBench Consensus were nearly flat compared to GPT-5.5, with improvements concentrated in Professional and Hard. Collapsing health performance into a single score obscures which scenarios improved and which didn't.

External evaluation revealed a different kind of weakness. A study published in Nature Medicine expanded 60 physician-created case scenarios into 16 conditions each, generating 960 responses from ChatGPT Health. The conditions varied patient race and gender, the presence of reassurance or warnings from those around the patient, and barriers to accessing care. Among the 30 cases with a single, clearly correct urgency level, 33 of 64 cases requiring emergency care—51.6%—were underestimated as needing only a visit within 24 to 48 hours. For non-urgent cases, 83 of 128—64.8%—were overestimated in urgency.

These results cannot be directly mapped onto the current version of ChatGPT Health. The study used gpt-5-mini thinking from January 9–11, testing synthetic cases rather than real patients, with each scenario measured only once using a single fixed prompt. The emergency cases were also limited to just four scenarios drawn from two original clinical situations, and 28 of the 33 underestimated cases were concentrated in asthma exacerbations. Even so, apart from the rise in aggregate benchmark scores, there remains a need for external validation of the current version's behavior at both clinical extremes.

AD

What to check outside the boundaries of HIPAA

OpenAI's terms of use state that its services are not intended to be used for diagnosing or treating health conditions. Consumer-facing ChatGPT Health is not intended for clinical use and is not built for HIPAA-covered entities; OpenAI does not offer a Business Associate Agreement (BAA) for it. This differs in both contract and purpose from ChatGPT for Healthcare, which is designed for healthcare organizations.

The US Department of Health and Human Services has explained that when a patient directs a healthcare provider to send electronically protected health information to an app, and that app is neither a HIPAA-covered entity nor a business associate, the information is no longer protected under HIPAA once received. That said, this doesn't mean consumer health apps are entirely unregulated. The US Federal Trade Commission's Health Breach Notification Rule requires personal health record vendors operating outside HIPAA to notify users in the event of a breach involving unsecured, identifiable health data. OpenAI's Health Privacy Notice also explicitly states that it may handle information potentially covered under Washington State's and Nevada's consumer health data laws.

What matters most about this rollout isn't the growth in user numbers—it's whether the permission prompts reliably control the flow of health information, whether users can correct outdated medication or test data, and whether the current model behaves safely at both extremes of medical urgency. The convenience of bringing health data into everyday conversation is only justified if permissions, memory, and deletion procedures remain consistent—and if safety has been confirmed through external evaluation as well.