OpenAI has begun rolling out Health, a ChatGPT feature that lets adult users in the United States connect Apple Health and records from supported medical providers. Connected users can ask ChatGPT to weigh lab results, medications, and activity data inside ordinary conversations, not just a separate health tab. The rollout covers logged-in users 18 and older across ChatGPT’s Free, Plus, Pro, and Go tiers, on both iOS and the web. Health does not yet work inside Codex, OpenAI’s coding tool.
The feature marks a shift from how OpenAI first tested this territory. A dedicated health space launched earlier this year required users to step outside their normal chat window to get grounded answers. OpenAI found that more than seven in ten health-related exchanges happened elsewhere in the app. So the company folded the same context, medications, recent visits, sleep, and workouts, into the main conversation flow instead. Users can pull it in explicitly with an @Health mention, or let ChatGPT ask permission automatically before it uses the data.
Health is arguably the most commercially valuable and most trust-sensitive category a consumer AI company can enter. A user who lets a chatbot see lab results and prescription history hands over data more sensitive than a search query or a shopping cart. A single misstep, a leaked record, a bad suggestion treated as a diagnosis, carries reputational and legal weight that a bad coding suggestion never will. OpenAI’s answer is a policy pledge: linked Apple Health data and any medical records a user connects, plus conversations that draw on them, will not train its foundation models or feed ad targeting, regardless of a user’s own model-training setting.
That pledge deserves scrutiny alongside credit. It is a company policy, not a finding verified by an outside auditor, a regulator, or an independent security researcher. OpenAI has not published a technical audit of how the training exclusion is enforced. It also has not said how long synced health data sits on its servers while a connection stays active; the company specifies only that disconnecting an account triggers deletion within 30 days. Conversation history that already referenced the data stays until a user deletes those chats separately. The announcement does not mention HIPAA, the federal law governing health data held by providers and insurers. ChatGPT sits outside the regulated health system as a consumer product, which likely puts it outside HIPAA’s reach, but OpenAI does not say so itself.
The Apple Health hook matters more than the privacy language. Apple Health already sits on hundreds of millions of iPhones, pulling in data from wearables and fitness apps without requiring a new account or a new sensor. Building on that existing pipe, rather than a dedicated device or a hospital integration, gives OpenAI a low-friction path into a data category no chatbot has owned at scale. No global rollout accompanied this one. Eligibility stops at US adults, and Europe’s stricter treatment of health data as a special category under GDPR is the more likely explanation than any technical limit.
Operators evaluating ChatGPT for a workflow that touches personal health information should treat OpenAI’s no-training and no-ad-targeting commitments as claims to verify contractually, not as settled facts, before connecting real patient or employee health records.
Announced by OpenAI on July 23, 2026.