HugoScore hugoscore.org

General-purpose AI assistant (health use)

ChatGPT / ChatGPT Health

ChatGPT’s documented Health controls include permissions for connected data and editable current context. Source records remain read-only. Source disconnection, conversation deletion, memories, ordinary-chat settings, and the legacy Health project have distinct boundaries.

AI-assisted draft Read full report Open directory

Published September 8, 2026 as an AI-assisted draft. The public report separates documented facts, agency judgments and unresolved questions.

75 /100 toward patient-directed
Agency posture Potentially agency-expanding, with platform-custody caveat
The question we ask Who does ChatGPT / ChatGPT Health serve in this deployment?
Control Consumer Health connections and ordinary ChatGPT health use must be distinguished, as must the legacy Health project.
Agency read Potentially agency-expanding, with platform-custody caveat
Vendor
OpenAI
Who it serves
Patient-directed use of a vendor-controlled general-purpose AI platform, with a dedicated consumer health space
Primary User
Patients, caregivers, and consumers asking health and wellness questions, including people connecting their own medical records and wellness apps
Control Model
Vendor-hosted public service. Controls and downstream processors depend on the assessed deployment.
Patient Impact
Follow-up, correction of current context and record-grounded comparison can support reasoning. Editing context does not guarantee correction of future model errors or an investigation of a harmful answer. Connected outputs still need evidence and uncertainty scrutiny.
Profile Status
AI-assisted draft
Last assessed
Sep 8, 2026
Review Confidence
Medium for official published controls, limited for execution (AI-assisted draft)
AI / Model
OpenAI Codex / GPT-6
Human Review
Hugo Campos authorized publication of these AI-assisted draft reassessments on September 8, 2026. This does not claim comprehensive human verification of every finding.

Summary judgment · 75 out of 100 toward patient-directed

Consumer Health connections and ordinary ChatGPT health use must be distinguished, as must the legacy Health project. Preserve the August 9 baseline 75 and prior Claude provenance.

Potentially agency-expanding, with platform-custody caveat

ChatGPT’s documented Health controls include permissions for connected data and editable current context. Source records remain read-only. Source disconnection, conversation deletion, memories, ordinary-chat settings, and the legacy Health project have distinct boundaries.

Patient agency

How this tool changes agency

Expands agency when

Follow-up, correction of current context and record-grounded comparison can support reasoning. Editing context does not guarantee correction of future model errors or an investigation of a harmful answer. Connected outputs still need evidence and uncertainty scrutiny.

Limits agency when

No live connection, permission, memory or deletion test. Litigation and independent safety validation were not refreshed.

Patient agency assessment

Who sets and changes the goal?

Patient authority

Patients can set questions and goals, amend current context and decide when linked information is consulted. They cannot alter the provider's source record through Health. These are meaningful controls within a vendor-controlled platform, rather than evidence that every health record automatically informs every chat.

What can the patient understand, question, or do?

Critical capacity

Follow-up, correction of current context and record-grounded comparison can support reasoning. Editing context does not guarantee correction of future model errors or an investigation of a harmful answer. Connected outputs still need evidence and uncertainty scrutiny.

Can the patient evaluate the conditions of use?

Informed control

The baseline overstates the loss of separation and understates permission controls. Users must distinguish source disconnection, conversation deletion, memories and ordinary-chat training settings. Safety access is a separate published condition from foundation-model training.

Text findings

Conditions of use

Published controls and their limits

The baseline overstates the loss of separation and understates permission controls. Users must distinguish source disconnection, conversation deletion, memories and ordinary-chat training settings. Safety access is a separate published condition from foundation-model training.

What remains unknown?

Not tested or not established

No live connection, permission, memory or deletion test. Litigation and independent safety validation were not refreshed.

Who evaluated this?

AI-assisted public-source draft

Vendor statements describe published conditions, not independently verified behavior. No clinical, security, accessibility, or legal validation is claimed. Earlier evidence remains dated in the report and history.

Sources checked

Source-specific findings and retrieval limitations are recorded in the full report.

Review provenance

Criteria

CAIHL-derived HugoScore framework and September 7 qualitative review priorities. Draft v1.2 numerical anchors remain unadopted.

Reviewer

AI-assisted public-source reassessment prepared in OpenAI Codex.

AI / model

OpenAI Codex / GPT-6

Human review

Hugo Campos authorized publication of these AI-assisted draft reassessments on September 8, 2026. This does not claim comprehensive human verification of every finding.

Review date

2026-09-08

Limitations

No live connection, permission, memory or deletion test. Litigation and independent safety validation were not refreshed. No live product use, patient-data upload, account creation, code audit, clinical evaluation, or independent implementation validation.

Review method

Focused public-source reassessment using CAIHL: patient authority, critical capacity, and informed control. Existing evidence plus one focused primary-source pass and at most one targeted follow-up. No live product testing. Numerical scores remain provisional editorial placements, not a new calculation.

AI-assisted draft · Medium for official published controls, limited for execution (AI-assisted draft)