Skip to content

PRIVACY September 3, 2026 5 min read

Asking an AI About Your Health

Health is the thing people ask an AI about at two in the morning, when they will not ring a doctor and will not put it in a search box either. It is also the category where the account attached to the question matters most.

HIPAA does not follow you into a chatbot

This surprises people, so it is worth being plain about: HIPAA binds healthcare providers, insurers, and the business associates who sign agreements with them. It does not attach to a question because the question is about health. Type a symptom into a general-purpose assistant and you are not a patient — you are a user, and the protections are whatever that company’s terms say they are.

That is not a scandal. It is just a different arrangement from the one people assume, and the assumption is doing real work at two in the morning.

What makes a health question different

A single question is rarely the problem. The problem is the sequence: the symptom in March, the specialist in April, the medication name in June, the second opinion in September — all under one account, all timestamped, all held by one company. Nobody set out to build a medical history. It accumulates because every message carries the same identity.

Nobody set out to build a medical history. It accumulates.

And unlike a browser history, you cannot really clear it by clearing it: deleting the conversation on your side is not the same as the provider ceasing to hold it, which is covered in what deleting actually deletes.

How to ask without handing over an identity

  • Leave out what the question does not need. Your name, date of birth, address and insurance number change nothing about the answer to “what causes this symptom”.
  • Watch the attachments. A photograph of a rash or a test result carries the GPS coordinates of where it was taken unless something removes them — see what happens to a photo you attach.
  • Ask in general terms. “A 40-year-old with these symptoms” gets the same answer as “I, personally, with my name attached”.
  • Check what the tool removes for you, because doing all of the above by hand, every time, at two in the morning, is not a plan anybody keeps to.

What Secure AI does here

The request reaching a model carries our credentials rather than your account, so a series of questions is not a series filed under a person. Names, addresses, phone numbers, card numbers and identifiers are taken out before the message leaves. Photos are redrawn so no location travels with them. If the step that does the removing cannot run, the message is refused rather than sent unprotected.

And the limits, which matter more in this category than any other: the substitution runs on a server rather than on your device, and recognising a third party’s name in a sentence — a doctor, a relative — is best-effort, with a setting to refuse rather than send when that check cannot finish. Neither of those is buried; both are on the privacy screen in the app.

None of this is medical advice, and an assistant is not a doctor. It is a way to ask the question you were going to ask anyway without the answer arriving in a file with your name on it.

Questions

Can my employer see health questions I ask?

On a company account or a company device, often yes — that is covered in can your employer see what you ask an AI. Health is the category where people most often ask from a work laptop without thinking about it.

Is a local model better for this?

For pure privacy, nothing beats a model that never sends anything. The trade is quality, and for health questions the quality of the answer is not a detail. That trade is set out honestly in our comparison of the approaches.

Try Secure AI free

Frontier AI chat — encrypted by default, with your identity stripped before any request reaches the provider.

App StoreGoogle Play
← Back to Latest News