A lot of people now describe their symptoms to a chatbot before they describe them to a doctor. That's often a perfectly sensible thing to do. The answers are clear, patient, and available at two in the morning when a clinic isn't.
What almost everyone assumes — and what isn't true — is that the conversation carries some kind of medical confidentiality.
What HIPAA actually covers
HIPAA governs covered entities: doctors, hospitals, insurers, and the business associates handling data for them. It's a rule about particular institutions, not about a type of information.
Consumer AI platforms aren't covered entities. Type your symptoms into a general chatbot and HIPAA's protections — breach notification, minimum-necessary use, your right to see and correct your own records — simply never switch on. What you wrote isn't legally health data in the protected sense. It's user input, governed by a privacy policy the company can rewrite whenever it likes.
Nobody engineered this loophole. HIPAA was written for a healthcare system built around hospitals and insurers. It never imagined software that holds a clinical-sounding conversation, and it says nothing about systems quietly capturing health-adjacent information all day.
The distinction everyone blurs
Coverage of clinical AI has made this more confusing, not less.
Hospitals do deploy AI under real agreements. OpenAI announced an Epic integration for ChatGPT for Healthcare on September 1 — read-only, with UCSF Health as the pilot partner. That's a clinician-facing setup running inside health-system contracts.
It has nothing to do with your personal account. Compliance belongs to the deployment and the contract, not to the model. The same underlying system can be compliant inside a hospital agreement and entirely outside HIPAA on a $20 subscription. Reading about one tells you nothing about the other.
Where the words actually go
With HIPAA out of the picture, the platform's own policy is the only thing governing your data — and those policies usually allow far more than people expect. Health information shared with a non-covered platform can be kept indefinitely, used to improve models depending on your settings, folded into profiling, or exposed in a breach, with nobody obliged to tell you that health content was part of it.
Researchers who've reviewed healthcare chatbot apps found privacy practices across the category inconsistent and often unclear, which makes real consent hard even for the rare person who reads the terms.
What to actually do
You don't have to stop using these tools. You just need an accurate picture of where your words land.
Ask general questions instead of identified ones. "What usually causes this symptom" is a very different message from one containing your name, your employer, your birthday and your diagnosis. The medical part is often the least sensitive thing people paste in.
Turn off training and chat history where the platform lets you, and check the setting now and then — defaults move when products update.
Keep the specifics in the channels built for them. Your patient portal and your doctor's office are covered by HIPAA precisely because that's where medical records are supposed to live.
And treat anything you type into a consumer chatbot the way you'd treat something posted to a service you don't control. Useful, often excellent, and sitting permanently outside the protections most people think they still have.
Image: Gustavo Fring, via Pexels





