Artificial intelligence is making health information easier to summarize, explain, organize, and discuss. A patient can copy a laboratory report into a chatbot, ask for help understanding a medical term, upload a long history, or use an app to organize questions before an appointment. The convenience is obvious. The data question is less obvious. Before someone pastes a medical history, medication list, diagnosis, insurance document, or other sensitive information into a consumer AI tool, there is a basic governance question worth asking: Where does this information go after I press send?
Many people hear “health information” and assume the Health Insurance Portability and Accountability Act (HIPAA) automatically protects whatever they type into any health-related app. That is not how the system works. The U.S. Department of Health and Human Services explains that HIPAA protections depend on the relationship between the app and a HIPAA-covered entity or business associate. Information sent to a consumer-selected app that is not acting for a covered entity may no longer be protected by the HIPAA Rules in the same way it was inside a health system. HHS provides guidance here.
That does not mean consumer health technology operates in a legal vacuum. The Federal Trade Commission’s Health Breach Notification Rule, for example, applies to many health apps and similar technologies outside HIPAA and requires covered companies to provide notifications after certain breaches of unsecured health information. But different rules can apply to different products, relationships, and data flows. For patients, the practical lesson is that “health-related” and “HIPAA-protected” are not interchangeable labels.
The same issue becomes more important as general-purpose AI tools are used for health questions. A person may think only about the quality of the answer. Governance requires thinking about the input as well. Before sharing sensitive health information with a consumer AI service, five questions can help make the data flow more visible.
1. What information am I actually giving the system
A copied medical record can contain much more than the detail a person wants explained. Names, dates of birth, addresses, account numbers, clinician names, facility information, family history, and other identifiers may travel with the relevant medical text. Minimizing unnecessary information is different from withholding information from a clinician; it is about avoiding unnecessary disclosure to a separate consumer technology.
2. Is the information stored, and for how long
A useful privacy notice should explain whether prompts, files, or conversations are retained and how deletion works. “Delete chat” and “delete underlying data” are not always the same operation.
3. Can the information be used to improve or train systems
Patients should understand whether their content can be used beyond answering the immediate request. Settings, account types, and product policies may differ, so the answer should come from the service’s current privacy and data-use documentation rather than assumption.
4. Who else can receive or access the information
Third-party processors, integrations, plug-ins, human reviewers, analytics providers, or connected services may change the data path. The most important privacy question is often not simply “Does this company sell my data?” but “Who can receive it, for what purpose, and under what conditions?”
5. What happens if something goes wrong
Patients should be able to find a contact process for privacy concerns, correction, deletion requests, or suspected breaches. Accountability is stronger when a user knows where to go before there is a problem.
Clinicians and health care organizations also have a role in this conversation. As patients increasingly arrive with AI-generated summaries, questions, and interpretations, digital literacy should include privacy literacy. A short reminder that consumer AI tools may operate under different privacy rules than a hospital portal can be more useful than either blanket encouragement or blanket fear. The goal is not to tell patients never to use AI. These tools can help people organize complex information and prepare better questions. The goal is to make sure convenience does not hide the data transaction taking place underneath the conversation.
AI makes the interface feel conversational. Health information, however, remains sensitive whether it is typed into a form, uploaded as a PDF, spoken to a voice assistant, or pasted into a chatbot. The question “What can this AI tell me?” is only half of responsible use. The other half is: What did I just tell the AI, and where is that information going next?
Michael Neely is an educator.



















