privacy

Health AI in 2026: What Happens to Your Medical Data

Five major health AI products launched in early 2026. Here's what each does with your medical records, and how to keep sensitive health data private.

Between January 7 and March 19 of this year, five companies released health-specific AI products: OpenAI with ChatGPT Health, Anthropic with Claude for Healthcare, Amazon through its One Medical acquisition, Microsoft with Copilot Health, and Perplexity with Perplexity Health.

Five major launches in roughly ten weeks isn’t a coincidence. It marks the moment health AI became strategically important enough that no major AI company could afford to be absent. Every major player in AI now has a product that can access, read, and respond to questions about your personal health records.

What happens to that data is the question most users haven’t had time to ask.


The Five Products and What They Connect To

Understanding what each product accesses is a prerequisite for evaluating the privacy implications.

ChatGPT Health (OpenAI, January 7) connects to electronic health records through b.well, a health data aggregation platform. It can pull in records from health systems that have partnered with b.well, alongside wearable data from Apple Health and compatible fitness trackers.

Claude for Healthcare (Anthropic, January 11) connects through HealthEx, another health data intermediary. Anthropic has emphasized its Constitutional AI safety framework as a foundation for health-specific deployments, and offers stronger privacy commitments for healthcare accounts than its consumer product.

Amazon Health AI (January 22, expanded March) operates through One Medical, which Amazon acquired in 2023. One Medical is a primary care provider and functions as a HIPAA-covered entity, which changes the legal structure of how health data is handled — more on this below.

Copilot Health (Microsoft, March 12) integrates with Microsoft 365 and, through partner health systems, electronic health record (EHR) systems that use Microsoft’s Azure health cloud infrastructure. Microsoft has extensive relationships with hospital systems through Azure Health Data Services.

Perplexity Health (Perplexity, March 19) was the most recent launch and the most limited at initial release — primarily a health-focused search interface that could reference public medical information rather than a full personal health record integration. Perplexity has been expanding this capability since launch.


What All Five Promise — and the Limits of Those Promises

Every one of these products includes some version of the same statement: they don’t train their core AI models on your personal health data, and health conversations are stored separately from ordinary chat history.

These are meaningful distinctions from the default behavior of general-purpose AI assistants, where conversations often are used to improve models. The commitments are real.

But health privacy is more complex than a single policy sentence, and three structural issues apply across all five products.

The training/storage distinction. “Not training on your health data” and “not retaining your health data” are different claims. Some products retain health conversation history for defined periods — for safety, debugging, and service improvement — even when they don’t use it as AI training data. The retention period and who can access it during that period are separate from the training question.

The memory overlap problem. General-purpose AI assistants have memory features that persist information across conversations. If a user asks ChatGPT Health about their blood pressure medication and then asks a general ChatGPT question, can the health context carry over? OpenAI’s documentation doesn’t give a definitive answer on how health-specific features interact with account-wide memory. This is an active gap in the public record.

The jurisdiction question. HIPAA protections don’t apply to all health data storage — they apply to “covered entities” (hospitals, health plans, certain healthcare providers) and their “business associates” (vendors with Business Associate Agreements). An AI company becomes a business associate under HIPAA only when it has signed a BAA with a covered entity. Without that agreement, health data stored with the AI company isn’t governed by HIPAA when held by that company.


HIPAA: When It Applies and When It Doesn’t

This distinction matters significantly for how you think about each product.

Amazon Health AI through One Medical operates with the clearest HIPAA coverage. One Medical is itself a covered entity — a primary care provider operating under HIPAA. Amazon Health AI as delivered through One Medical inherits that coverage, because One Medical is the covered entity and Amazon is functioning as its business associate. If you’re a One Medical patient using Health AI through that relationship, HIPAA protections apply.

The others depend on the access path. Anthropic, OpenAI, and Microsoft become HIPAA business associates when health systems execute BAAs with them as part of an enterprise healthcare deployment. If your hospital uses Claude for Healthcare as part of its patient portal, your hospital is the covered entity and Anthropic is the business associate — HIPAA applies. If you as an individual consumer sign up for Claude for Healthcare directly, without a covered healthcare entity in the chain, the HIPAA protections for business associates may not apply to your personal account.

This is a significant legal distinction that none of the five companies’ consumer-facing materials explain prominently. The products may look similar in the interface. The legal coverage depends on the relationship structure.


Amazon’s Privacy Story Is the Most Complex

Amazon merits additional attention because of the breadth of its connected data businesses.

Amazon operates One Medical (primary care), Amazon Pharmacy, Amazon Clinic (telehealth), and Amazon Comprehend Medical (a tool that helps healthcare organizations extract structured data from medical notes). It also runs one of the world’s largest targeted advertising businesses.

Amazon’s explicit policy is that health data is separated from advertising data. This is a stated policy commitment, and there’s no evidence it has been violated. But it’s a policy choice, not a technical architecture — the firewall is maintained by corporate rules, not by structural impossibility.

When Walmart Health closed its clinics in 2024, patients learned firsthand that health data from a retail-adjacent healthcare provider can become complicated when the business changes. Amazon’s healthcare ambitions are large and its position is evolving. The relevant question isn’t “what is Amazon doing with health data today” — it’s “what policy choices are available to them, and what happens if those choices change.”


The Data That Doesn’t Get Protected

Beyond the covered entity/HIPAA question, several categories of health-related data fall outside standard protections that most users assume apply.

Wearable and fitness data. Apple Health, Fitbit, and Oura ring data that users share with health AI products is not automatically covered by HIPAA. The wearable manufacturers themselves are not HIPAA-covered entities unless they partner with a healthcare provider. Health AI products that ingest this data are handling it under their own privacy policies, not HIPAA.

Mental health conversations. Users who discuss mental health symptoms, medications, or therapy with an AI health assistant are sharing information that can be particularly sensitive in insurance, employment, and legal contexts. Mental health data from consumer AI products is not uniformly protected by mental health-specific privacy laws, which vary significantly by state.

Symptom and search data. The act of asking a health AI product about specific symptoms generates data about what health issues you’re concerned about. Even if the health record integration is fully HIPAA-compliant, the query patterns themselves — what you search for, what you ask — may be handled under general terms of service rather than health-specific privacy protections.


Questions to Ask Before Connecting Health Records to Any AI

Before linking health records to any of these products, a few questions are worth finding answers to.

Is there a BAA in place? If you’re accessing the product through a health system (your hospital’s patient portal, your employer’s health benefit), there likely is. If you’re signing up as an individual consumer, ask explicitly whether the company will execute a HIPAA BAA for your account, and what protections apply if not.

Where does data go after you disconnect? All five products allow users to disconnect from health record access. What happens to data already cached or processed after disconnection isn’t uniformly disclosed. Look for explicit documentation of post-disconnection data handling.

How long are health conversations retained? Some products have specific retention periods for health data (separate from general conversation history). Others haven’t published explicit figures. This matters for the risk of a future breach exposing older records.

What state law applies? Health AI privacy protections vary by state. Texas’s Responsible AI Governance Act (effective January 2026) requires patients to be informed when AI supports their healthcare. California has additional constraints. The state where you live and the state where the AI company’s servers are located may both have relevant rules.


What daftei Offers: Storage Without AI Processing

daftei isn’t a health AI product. It doesn’t analyze symptoms, answer medical questions, or connect to electronic health records. But in the context of health data privacy, it’s worth describing what daftei does offer: a place to store health records privately, without AI processing.

Lab results, doctor’s notes, scan images, insurance explanation of benefits, medical history documents — these are files that benefit from being accessible across devices, but that many people don’t want fed into an AI system that analyzes them.

Files stored in daftei are encrypted in transit with TLS 1.3 and at rest with AES-256. daftei doesn’t use stored content to train AI models, for its own systems or for any third party. The files exist as storage — accessible to you, not processed by an AI analyzing what health conditions your records suggest you have.

This is a different function than health AI — it doesn’t produce insights or answer questions. It’s the function that makes sense for documents you want available but not processed: your records, your control.


The Gap the Industry Hasn’t Solved

Five major health AI products launched in ten weeks, and all five include genuine privacy commitments. But the underlying tension in this space hasn’t been resolved.

The value proposition of health AI depends on the AI having access to personal health context — the more it knows about you, the more useful it can be. That access is, by definition, a form of health data processing. The privacy question isn’t whether health AI processes your health data — it does, by design — but which company processes it, under what legal framework, with what retention policies, and with what safeguards against breach and misuse.

These aren’t unanswerable questions. They have answers — different answers for different products, different deployment contexts, and different states. But they require more than reading the headline of a privacy policy. They require finding the specific BAA documentation, the data retention period, and the state-specific disclosures.

Most users who connect health records to an AI product this year will do so based on the headline promise (“we don’t train on your health data”) without reading the details. That’s understandable — the details are dense and often require legal interpretation. But health data is also the category of personal information that creates the most concrete, lasting harm when it ends up in the wrong hands: insurance denials, employment discrimination, reputational exposure.

A few hours of reading before connecting health records to an AI system is a reasonable investment relative to that risk.


What to Do With This Information

The practical takeaway isn’t “don’t use health AI.” These products offer genuine utility — clearer access to your own records, better-informed conversations with providers, more context-aware health tracking.

The practical takeaway is: understand what you’re connecting, to what company, under what legal framework, and with what data retention before you connect it.

For the health records you want private storage for rather than AI analysis — scan results, diagnosis letters, medication histories, insurance records — a separate encrypted storage approach keeps those documents accessible without feeding them into an AI processing pipeline.

For the health AI products themselves: read the BAA documentation, not just the headline. Ask your healthcare provider whether they’ve executed a HIPAA BAA with the AI company before connecting through a health system portal. And know which state you’re in — because health AI privacy protections in 2026 vary more by jurisdiction than by product.

Your memories deserve better than an ad platform.

Try daftei free →
← All posts