HugoScore hugoscore.org

Full review

ChatGPT / ChatGPT Health CAIHL draft report

Evidence-linked HugoScore draft report for a health AI tool that affects patients.

ChatGPT / ChatGPT Health: CAIHL reassessment

September 8, 2026. Published AI-assisted draft.

ChatGPT’s documented Health controls include permissions for connected data and editable current context. Source records remain read-only. Source disconnection, conversation deletion, memories, ordinary-chat settings, and the legacy Health project have distinct boundaries.

Scope and agency posture

Consumer Health connections and ordinary ChatGPT health use must be distinguished, as must the legacy Health project. Preserve the August 9 baseline 75 and prior Claude provenance.

Posture: Potentially agency-expanding, with platform-custody caveat.

Axis: 75/100, retained provisionally. No numerical recalibration was performed.

Sources and documented findings

  • The current Health help page documents permission before connected-data use by default, adjustable permissions, editable current conditions/medications/family history, and read-only source records. Earlier Health chats and files remain in a project whose memories stay within it. Current access documentation names web and iOS, not Android.
  • The July launch page says disconnected-source data is deleted within 30 days, while content already in conversations remains until those conversations are deleted. Conversations using connected medical records or Apple Health are excluded from foundation-model training and ad targeting. Ordinary conversations follow account training settings. Health conversations can create memories, which require separate controls.
  • The Health Privacy Notice separately permits limited authorized personnel and service-provider access for model-safety improvement unless opted out, and provides an export/deletion rights route. Its older dedicated-Health and Connect Health wording needs to be read alongside current product documentation, not silently replaced by a blanket no-access promise.
  • The prior report's lawsuit narratives, usage figures and paid-model claims were not refreshed in this focused controls pass. They remain historical, unverified here, and are not used to determine this recommendation.

Patient authority

Inference from the documented workflow: Patients can set questions and goals, amend current context and decide when linked information is consulted. They cannot alter the provider's source record through Health. These are meaningful controls within a vendor-controlled platform, rather than evidence that every health record automatically informs every chat.

Critical capacity

Editorial assessment: Follow-up, correction of current context and record-grounded comparison can support reasoning. Editing context does not guarantee correction of future model errors or an investigation of a harmful answer. Connected outputs still need evidence and uncertainty scrutiny.

Informed control

Editorial assessment: The baseline overstates the loss of separation and understates permission controls. Users must distinguish source disconnection, conversation deletion, memories and ordinary-chat training settings. Safety access is a separate published condition from foundation-model training.

Assessment and limits

Replace the categorical architecture-loss narrative with the documented permission, legacy-project and retention boundaries. The platform-custody caveat remains justified, but these controls materially qualify it. No numerical recalibration is established.

Confidence: Medium for official published controls, limited for execution.

Remaining uncertainty: No live connection, permission, memory or deletion test. Litigation and independent safety validation were not refreshed.

Published documentation is evidence of stated conditions, not proof of actual implementation. Unknowns did not receive automatic negative points. Funding, sponsorship, and public code do not determine agency by themselves.

Review provenance

  • Reviewer/model: OpenAI Codex / GPT-6.
  • Method: Focused public-source reassessment using CAIHL: patient authority, critical capacity, and informed control. Existing evidence plus one focused primary-source pass and at most one targeted follow-up. No live product testing. Numerical scores remain provisional editorial placements, not a new calculation.
  • Human review: Hugo Campos authorized publication of these AI-assisted draft reassessments on September 8, 2026. This does not claim comprehensive human verification of every finding.
  • Earlier review: 2026-08-09. Historical assessment. Earlier claims are not automatically reverified by this publication.