"Is this private?" is really two separate questions: is it legally protected the way a conversation with your doctor is, and does the company on the other end use what you type to improve its models? The answers are "no" and "sometimes, depending on your settings," and neither is obvious from the chat window itself.
Why HIPAA doesn't cover this
The Health Insurance Portability and Accountability Act protects "protected health information" specifically when it's handled by a covered entity — a hospital, clinic, insurer, or a vendor working on their behalf under a signed Business Associate Agreement. When you personally open a consumer chatbot and describe a symptom, you aren't a covered entity and the AI company isn't acting as your provider's business associate, so HIPAA's rules simply don't attach to that conversation. This is confirmed directly by HIPAA compliance analyses of products like OpenAI's consumer-facing ChatGPT Health service, which is explicitly built and marketed as a wellness tool operating under ordinary consumer terms, not HIPAA-covered clinical terms.
What actually governs your data instead
Absent HIPAA, your protection comes down to each company's own consumer terms of service and privacy settings — and these differ, and have shifted recently:
1. Anthropic (Claude): In August 2025, Anthropic changed its consumer policy so that Free, Pro, and Max chat and coding sessions can be used for model training, with data retained for up to five years for users who don't opt out (versus 30 days for those who do). Independent reporting at the time (TechCrunch) documented the in-app toggle presented to existing users as defaulted to "on." This does not apply to Claude for Work or API usage, which exclude training by default.
2. OpenAI (ChatGPT): Consumer ChatGPT conversations, including on paid individual plans, are used to train models unless you manually turn this off under Settings > Data Controls. Team and Enterprise plans are excluded from training by default.
3. Deleting a conversation generally stops future training use going forward (per Anthropic's own policy statement), but does not retroactively un-train a model that may have already learned from it in a prior cycle.
What to actually do about it
1. Check your specific provider's data-controls settings before describing anything sensitive — don't assume "private by default."
2. If you want to keep the convenience of a chatbot for symptom research, opt out of training in settings and avoid including your name or other directly identifying details in the prompt.
3. For anything that needs real HIPAA protection — sharing symptoms as part of actual care — use your provider's patient portal or a tool your clinic has a signed Business Associate Agreement for, not a general consumer chatbot.
# Before describing symptoms to a consumer AI assistant
[ ] Confirm this is a consumer/personal account, not a
clinic-provided tool covered by a BAA
[ ] Open account settings and check the training/data-use
toggle (do not assume the default protects you)
[ ] Avoid entering your full name or other directly
identifying details in the prompt itself
[ ] Treat the output as general information, not a
diagnosis -- it did not review your medical history
[ ] For anything tied to actual care, use your provider's
HIPAA-covered patient portal instead
| Context | Is HIPAA involved? | Is your chat used for training? |
|---|---|---|
| You, personally, asking a consumer chatbot about symptoms | No — you aren't a covered entity | Possibly, depending on provider defaults and your settings |
| Your clinic using an AI tool under a signed BAA | Yes — the vendor is a business associate | No — HIPAA-covered products are contractually excluded from training use |
The practical takeaway isn't "never use a chatbot for health questions" — it's that privacy here is a settings problem, not a legal guarantee. Check your specific provider's current policy (these change; Anthropic's shifted meaningfully in 2025), opt out of training if you'd rather your conversations not be used that way, and reserve anything that needs real legal protection for a tool your healthcare provider has actually vetted.
Practical Challenge
Open the account settings of whichever AI assistant you use most and find the data-training toggle. Confirm whether it's currently on or off for your account — most people have never checked.
Concept Check
Sources & Further Reading
- HIPAA Journal: Is ChatGPT HIPAA Compliant? (Updated for 2026) — explains why consumer chatbot use falls outside HIPAA's covered-entity framework, and how healthcare-specific products differ.
- Anthropic: Updates to Consumer Terms and Privacy Policy — Anthropic's own announcement of the August 2025 training opt-in/out change and five-year retention period for Free/Pro/Max users.
- TechCrunch: Anthropic users face a new choice — independent reporting documenting the training toggle's default "on" state for existing users.
AI