Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

Privacy Tip #503 – Read This Before You Upload Medical Information into an AI Tool

By Linn Foster Freedman on August 13, 2026
Email this postTweet this postLike this postShare this post on LinkedIn

The current statistics on how many people upload their medical information into a generative AI tool are staggering. It is clear to me that people are unaware of the risks of doing so, and if you are contemplating sharing your medical information with a generative AI tool, like ChatGPT, Gemini or Claude, please read this first.

Earlier this year, OpenAI announced the launch of a version of the chatbot dedicated to assist individuals with navigating their health records. Whether you are contemplating sharing your medical information with ChatGPT, or another chatbot, there are risks of doing so that have been outlined in the article “When Patients Share Everything With an AI Chatbot – Risks and Opportunities of Large Language Models” published in the Journal of the American Medical Association.

The article outlines the “potential benefits and discuss the attendant risks of privacy violations, discrimination, and the exacerbation of health disparities that may accompany the unfiltered upload of EHRs” into large language models. These risks include the fact that once the health information is shared with a commercial company, it is not protected by HIPAA, the federal law that protects health information that is created or maintained by medical providers. In addition, the shared information could be disclosed as output for other prompts by other people. Further, the results could be inaccurate, biased, or discriminatory. Finally, the information can be shared with other third parties as outlined in the company’s privacy policy.

It is imperative that prior to uploading any medical information, you read the company’s privacy policy thoroughly, understand the risks, minimize uploading the actual medical records, and be cautious about relying too heavily on the results.

There are studies that show that caution should be used when receiving diagnosis or treatment information from an AI tool. Several individuals have sued AI developers for misdiagnosis that allegedly caused them harm. One individual is suing ChatGPT and its CEO alleging that “ChatGPT’s medical advice nearly killed him.” OpenAI’s terms state that individuals should not rely on it for medical advice. Unfortunately, it is well-known that it is rare for individuals to read privacy policies in depth.

The takeaway? As we have said before, it is really important to read privacy policies before you share your information, even if they are long. Take the time, as that is the only way you will find out how companies are using and disclosing your most sensitive information.

It is similarly important to understand that your medical information is not protected when you share it with a third party. Protect your most sensitive information, and know the risks before you share it with a commercial entity or rely on the results of an AI bot.

Tags: AI
Photo of Linn Foster Freedman Linn Foster Freedman

Linn Freedman practices in data privacy and security law, cybersecurity, and complex litigation. She is a member of the Business Litigation Group and the Financial Services Cyber-Compliance Team, and chairs the firm’s Data Privacy and Security and Artificial Intelligence Teams. Linn focuses her…

Linn Freedman practices in data privacy and security law, cybersecurity, and complex litigation. She is a member of the Business Litigation Group and the Financial Services Cyber-Compliance Team, and chairs the firm’s Data Privacy and Security and Artificial Intelligence Teams. Linn focuses her practice on compliance with all state and federal privacy and security laws and regulations. She counsels a range of public and private clients from industries such as construction, education, health care, insurance, manufacturing, real estate, utilities and critical infrastructure, marine and charitable organizations, on state and federal data privacy and security investigations, as well as emergency data breach response and mitigation. Linn is an Adjunct Professor of the Practice of Cybersecurity at Brown University and an Adjunct Professor of Law at Roger Williams University School of Law.  Prior to joining the firm, Linn served as assistant attorney general and deputy chief of the Civil Division of the Attorney General’s Office for the State of Rhode Island. She earned her J.D. from Loyola University School of Law and her B.A., with honors, in American Studies from Newcomb College of Tulane University. She is admitted to practice law in Massachusetts and Rhode Island. Read her full rc.com bio here.

Read more about Linn Foster FreedmanEmail
Show more Show less
  • Posted in:
    Privacy and Cybersecurity
  • Blog:
    Data Privacy + Cybersecurity Insider
  • Organization:
    Robinson & Cole LLP
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo