OpenAI began rolling out Health in ChatGPT to eligible logged-in U.S. users on July 23, 2026. The experience lets people connect medical records and Apple Health information so ChatGPT can help them understand trends, prepare questions, and compare new results with prior information. OpenAI says the feature supports—not replaces—professional care.
The immediate audience is consumers, but the launch matters to every organization considering AI around sensitive data. The competitive question is no longer simply whether a model can summarize complex records. It is whether the product has a credible permission model, a limited purpose, understandable controls, and an escalation path when the AI should not be the final decision-maker.
What OpenAI launched
Health in ChatGPT is available on web and iOS for U.S. users aged 18 and over across Free, Go, Plus, and Pro plans. With user permission, ChatGPT can use connected health context to help explain changes, identify missing context, and help users prepare for appointments. OpenAI says connected medical-record and Apple Health data, along with conversations that use it, are not used to train foundation models or target ads.
Those specifics matter because connected-data AI is materially different from a one-off prompt. A system that can retain or retrieve context can reduce repetitive uploads and explanations, but it also creates a higher bar for identity, authorization, data minimization, and user understanding.
The enterprise lesson is consent architecture, not chatbot polish
Teams often begin an AI project by selecting a model and designing a friendly interface. For workflows involving employee, customer, financial, legal, or health-related information, the stronger starting point is a consent architecture. Define precisely which data may be connected, which actions the agent may take, who can revoke access, what is excluded from training or secondary use, and how access is audited.
That approach prevents a common failure mode: adding sensitive systems to a general-purpose assistant first and attempting to retrofit governance afterward. A business AI worker should have the narrowest data scope and action permissions needed for its assigned job. It should also make it clear when it is summarizing information, when it is making an inference, and when a qualified person must review the output.
A practical rollout pattern for sensitive-data agents
Start with a bounded, assistive workflow rather than a high-consequence autonomous one. Good early candidates include assembling case information, drafting an appointment or intake summary, flagging missing documents, or answering approved policy questions from a controlled knowledge base. Keep final clinical, legal, financial, or employment decisions with an authorized human.
Next, test the workflow against realistic edge cases: incomplete records, conflicting data, unclear user intent, revoked permissions, and requests outside the approved scope. Document who owns the workflow, which systems are connected, the retention policy, and the escalation route. This turns “AI privacy” from a broad promise into operational controls that can be reviewed and improved.
What to watch next
ChatGPT Health will be judged less by its ability to explain a single result than by whether users trust its boundaries over time. That same standard applies to enterprise agents. As AI becomes more connected to systems of record, trust will increasingly depend on visible choices about permission, provenance, handoffs, and accountability—not just model intelligence.
For organizations, the actionable takeaway is straightforward: treat a sensitive-data AI deployment as a governed workflow, not a generic assistant rollout. The companies that do that well can move from experimentation to useful automation without asking users or employees to take an unreasonable leap of faith.