Sam Altman's company just crossed a line most Americans didn't know existed.
OpenAI launched a product that hoovers up medical records, fitness data, and health information from millions.
And Sam Altman just admitted his AI can't be trusted with one scary detail about your private data.
OpenAI launches ChatGPT Health without key protection
OpenAI unveiled ChatGPT Health on Tuesday, letting users connect electronic medical records, Apple Health, MyFitnessPal, and other apps directly to the chatbot.
More than 40 million people already use ChatGPT daily for health questions.
Now Altman wants them feeding the AI their most private information — blood tests, medical scans, prescription history, the works.
OpenAI claims it won't use health data to train its models.
But here's what they're not telling you.
ChatGPT Health isn't HIPAA compliant.
That's the federal law protecting your medical privacy.
Consumer health apps don't fall under HIPAA protections.
Which means OpenAI faces zero legal consequences if your data gets exposed, stolen, or misused.
The company admits health information "could potentially be made available to litigants or government agencies via a subpoena or other court order."
Translation: prosecutors, divorce lawyers, and federal agents can grab your medical history whenever they want.
Altman's company already got hacked and didn't report it
This isn't theoretical risk.
OpenAI has a track record of security disasters.
In 2024, a hacker broke into OpenAI's systems and stole details about the company's AI technology design.
The company didn't report the breach to the FBI.
Whistleblowers said OpenAI ignored the incident because they assumed the hacker wasn't connected to a foreign government — despite employee warnings that countries like China could steal the technology.
Congressional investigators blasted OpenAI for fostering "a culture of recklessness" while racing to build powerful AI systems.
Then in July 2024, a developer discovered ChatGPT was storing user conversations in plain text in unprotected locations on Apple devices.
OpenAI scrambled to patch the problem after getting caught.
In November 2025, another breach hit when unauthorized actors accessed analytics provider Mixpanel and exported OpenAI user data including names, emails, and location details.
The company took 16 days to detect the breach.
That's three major security incidents in 18 months.
Now Altman wants access to your cancer diagnoses and mental health records.
Altman himself warned AI creates dangerous security holes
Here's the most damning part.
Altman publicly admitted in December 2025 that AI models "are beginning to find critical vulnerabilities" in computer systems.
He announced OpenAI is desperately hiring a "Head of Preparedness" with a $555,000 salary to address security problems.
The ChatGPT maker acknowledged AI agents helped Chinese hackers successfully penetrate multiple organizations in 2025.
Altman said AI security risks are "getting pretty serious" and creating "some real challenges."
So let's get this straight.
Altman admits his own technology discovers security weaknesses and helps hackers break into systems.
His company has been breached multiple times and covered up at least one incident.
And now he wants millions of Americans uploading their medical records to servers that aren't even required to follow health privacy laws.
No protection if reproductive health data gets exposed
The timing couldn't be worse.
With abortion access restricted in multiple states, reproductive health information has become politically explosive.
ChatGPT Health users could ask questions about pregnancy, birth control, or abortion — conversations that prosecutors in red states would love to get their hands on.
Gender-affirming care faces similar political pressure.
Transgender individuals using ChatGPT Health to track hormone therapy or discuss medical transitions create a digital paper trail.
OpenAI's own privacy policy admits government agencies can subpoena that data.
And there's zero legal privilege protecting it like there would be with an actual doctor.
News organizations already obtained millions of ChatGPT logs in copyright lawsuits — including from "temporary chats" users thought were deleted after 30 days.
So much for OpenAI's promises about data protection.
Users uploading blood tests have no idea about the risks
Americans trust ChatGPT with deeply personal health information because they don't understand the dangers.
People upload blood test results asking for interpretation.
They paste medical scans looking for second opinions.
They detail medication histories and family health problems.
Every bit of that data sits on OpenAI's servers in Texas data centers operated by Microsoft.
The European Union forced Italy to ban ChatGPT in 2023 over privacy violations before lifting the ban after OpenAI made changes.
Multiple countries investigated Altman's other company WorldCoin for collecting biometric iris scans from 6.5 million people.
Bavaria is deciding whether to ban WorldCoin from Europe entirely over data collection concerns.
Yet somehow Americans are supposed to trust this guy with their cancer diagnoses.
Altman pitches regulatory wishlist while ignoring current laws
OpenAI's new report on healthcare AI reads like a corporate lobbying document.
The company wants to "open and securely connect the world's medical data" and create a "clearer regulatory pathway" for AI medical devices.
They're urging the FDA to "work with industry" on regulations that "facilitate innovation."
Translation: get out of our way and let us do whatever we want.
Altman already opposed California's AI safety bill that would have set basic standards for large AI models.
The guy who previously supported AI regulation suddenly fights it when regulations might apply to his company.
Meanwhile OpenAI won't even sign Business Associate Agreements required under current HIPAA law for handling protected health information.
They want special treatment carved out for consumer health apps so they can avoid liability.
Here's what you need to understand.
When hospitals get hacked and patient data is exposed, they face massive fines and lawsuits under HIPAA.
When OpenAI's ChatGPT Health gets breached, they face nothing.
Zero legal consequences for exposing your most private information.
That's not innovation.
That's a con job.
Sources:
- Sharon Goldman, "OpenAI launches ChatGPT Health in a push to become a hub for personal health data," Fortune, January 7, 2026.
- Staff, "Is ChatGPT HIPAA Compliant? Updated for 2025," HIPAA Journal, May 14, 2025.
- Thomas Kean Jr., Letter to Sam Altman regarding AI security concerns, U.S. House of Representatives, December 11, 2024.
- Sam Altman, X post regarding AI security vulnerabilities, December 27, 2025.
- Ina Fried, "ChatGPT Health is dedicated tab for health. Here's how it works," Axios, January 7, 2026.
- Staff, "OpenAI Reveals 2025 Data Breach via Mixpanel, Exposing API User Info," WebProNews, November 27, 2025.
- Uri Gal, "OpenAI's data hunger raises privacy concerns," The Conversation, December 3, 2025.
