CURRENT TREND INSIGHT
Is my data private when I ask an AI assistant about health symptoms? Illustration

Is my data private when I ask an AI assistant about health symptoms?

Direct Summary:

No — asking a consumer AI assistant about your symptoms is not covered by HIPAA, and by default several major providers can use that conversation to train future models. HIPAA only applies when a "covered entity" (a healthcare provider, insurer, or their business associate) handles your data — a person typing into ChatGPT, Claude, or Gemini on their own behalf isn't covered by it at all. Whether your specific chat gets used for training instead depends on the product and your account settings, which is exactly what this lesson walks through.

"The expert in anything was once a beginner."

— Helen Hayes

Key Insights

  • HIPAA doesn't apply to your own personal chatbot use: it governs covered entities (providers, insurers, their business associates) — a consumer typing symptoms into a general-purpose chatbot isn't a covered transaction at all, per HIPAA Journal's 2026 analysis.
  • Training defaults vary by provider and have changed recently: as of Anthropic's August 2025 policy update, Claude Free/Pro/Max conversations can be used for training unless you opt out by a set deadline, with retention extended to five years for users who don't opt out (TechCrunch reported the in-app toggle was defaulted to "on"). OpenAI's ChatGPT similarly trains on consumer conversations unless you disable it in Settings > Data Controls, even on paid plans.
  • Business/enterprise tiers are different by design: Anthropic's Claude for Work and API access, and OpenAI's Team/Enterprise plans, are excluded from training by default — the privacy gap is specifically a consumer-tier issue.

"Is this private?" is really two separate questions: is it legally protected the way a conversation with your doctor is, and does the company on the other end use what you type to improve its models? The answers are "no" and "sometimes, depending on your settings," and neither is obvious from the chat window itself.

Why HIPAA doesn't cover this

The Health Insurance Portability and Accountability Act protects "protected health information" specifically when it's handled by a covered entity — a hospital, clinic, insurer, or a vendor working on their behalf under a signed Business Associate Agreement. When you personally open a consumer chatbot and describe a symptom, you aren't a covered entity and the AI company isn't acting as your provider's business associate, so HIPAA's rules simply don't attach to that conversation. This is confirmed directly by HIPAA compliance analyses of products like OpenAI's consumer-facing ChatGPT Health service, which is explicitly built and marketed as a wellness tool operating under ordinary consumer terms, not HIPAA-covered clinical terms.

What actually governs your data instead

Absent HIPAA, your protection comes down to each company's own consumer terms of service and privacy settings — and these differ, and have shifted recently:

1. Anthropic (Claude): In August 2025, Anthropic changed its consumer policy so that Free, Pro, and Max chat and coding sessions can be used for model training, with data retained for up to five years for users who don't opt out (versus 30 days for those who do). Independent reporting at the time (TechCrunch) documented the in-app toggle presented to existing users as defaulted to "on." This does not apply to Claude for Work or API usage, which exclude training by default.

2. OpenAI (ChatGPT): Consumer ChatGPT conversations, including on paid individual plans, are used to train models unless you manually turn this off under Settings > Data Controls. Team and Enterprise plans are excluded from training by default.

3. Deleting a conversation generally stops future training use going forward (per Anthropic's own policy statement), but does not retroactively un-train a model that may have already learned from it in a prior cycle.

What to actually do about it

1. Check your specific provider's data-controls settings before describing anything sensitive — don't assume "private by default."

2. If you want to keep the convenience of a chatbot for symptom research, opt out of training in settings and avoid including your name or other directly identifying details in the prompt.

3. For anything that needs real HIPAA protection — sharing symptoms as part of actual care — use your provider's patient portal or a tool your clinic has a signed Business Associate Agreement for, not a general consumer chatbot.

privacy_checklist.md
# Before describing symptoms to a consumer AI assistant

[ ] Confirm this is a consumer/personal account, not a
    clinic-provided tool covered by a BAA
[ ] Open account settings and check the training/data-use
    toggle (do not assume the default protects you)
[ ] Avoid entering your full name or other directly
    identifying details in the prompt itself
[ ] Treat the output as general information, not a
    diagnosis -- it did not review your medical history
[ ] For anything tied to actual care, use your provider's
    HIPAA-covered patient portal instead
Context Is HIPAA involved? Is your chat used for training?
You, personally, asking a consumer chatbot about symptoms No — you aren't a covered entity Possibly, depending on provider defaults and your settings
Your clinic using an AI tool under a signed BAA Yes — the vendor is a business associate No — HIPAA-covered products are contractually excluded from training use

The practical takeaway isn't "never use a chatbot for health questions" — it's that privacy here is a settings problem, not a legal guarantee. Check your specific provider's current policy (these change; Anthropic's shifted meaningfully in 2025), opt out of training if you'd rather your conversations not be used that way, and reserve anything that needs real legal protection for a tool your healthcare provider has actually vetted.

Practical Challenge

Open the account settings of whichever AI assistant you use most and find the data-training toggle. Confirm whether it's currently on or off for your account — most people have never checked.

Concept Check

Why doesn't HIPAA protect a conversation where you personally ask a consumer chatbot about your symptoms?
Correct! HIPAA's protections attach to covered entities and their business associates, not to an individual's personal use of a general-purpose consumer product.
Incorrect. Try again! HIPAA governs covered entities (providers, insurers) and their business associates — your own personal chatbot conversation isn't a HIPAA-covered transaction at all.

Sources & Further Reading

Previous Guide Dashboard Next Guide