Cole Brennan: Hey — you look like you've already read something today that annoyed you, so you're going to love this topic.
Malcolm Reeves: Bold assumption. But go ahead.
Cole Brennan: 300 million. That's how many people in the U.S. were already asking ChatGPT health questions every single week by July 2026. Not after the launch — before it, during a pilot most of them had no idea was happening.
Malcolm Reeves: Wait — 300 million weekly, before the official product even existed?
Cole Brennan: Before the official product. In January 2026 it was 230 million — so 70 million people organically started doing this in six months without any formal feature, without Apple Health integration, without Epic or Oracle Health connected. Just... typing symptoms into a chat window at 2 AM the same way they'd Google it.
Malcolm Reeves: And then July 23rd, OpenAI makes it official. ChatGPT Health, full rollout — but you said something to me before we started recording about the timing, and I want to hear you say it out loud.
Cole Brennan: Yeah, so — the day before the rollout, July 22nd, a Florida pastor files a lawsuit alleging ChatGPT gave him a near-fatal suggestion. Specifically that it told him not to consult a doctor. And then July 23rd — boom, official launch, physician consultants attached, the whole formal apparatus. That sequence is not something I can just set aside.
Malcolm Reeves: So the question isn't really whether ChatGPT Health is useful — it's what it means when something invisible and already massive suddenly gets a name, a structure, a liability story attached to it.
Cole Brennan: And that's — that's the part I want to actually unpack, because I think a lot of people hear 'ChatGPT Health' and picture like, a chatbot answering medical trivia. But that's not what this is anymore.
Malcolm Reeves: Right — so let me try to put it plainly. You know that well-read friend everyone wishes they had? The one who happened to go to medical school? Before July 23rd, that friend was answering your questions from memory alone. Now you've handed them your entire medical file — your Apple Health fitness data, your doctor's notes from Epic, your lab results from Oracle Health, your One Medical records. That's what changed.
Malcolm Reeves: The AI isn't guessing anymore. It's reading. And Function Health, which does those deep biomarker panels — that data's in there too. So picture someone, say, a 34-year-old in Phoenix who had bloodwork done last Tuesday. She opens ChatGPT on her phone Sunday afternoon, asks about fatigue. The model isn't working from generalities — it's looking at her actual ferritin levels.
Cole Brennan: Okay but who actually built the pipes connecting all those different systems? Like, Epic and Oracle Health don't just... talk to each other natively.
Malcolm Reeves: No, they don't. The infrastructure underneath all of this is a company called b.well. They're the ones who built the actual connectivity layer. OpenAI is the interface, but b.well is the plumbing.
Cole Brennan: And most people using this — free-tier users — they're getting GPT-5.5 Instant. Not the top-of-the-line model. Which, I mean, I don't know exactly what that means for the quality of the health reasoning, but it's worth naming.
Malcolm Reeves: It is. And OpenAI is explicit that ChatGPT Health is a support tool — not for diagnosis, not for treatment. But the January 2026 pilot started with just Apple Health, Function Health, and MyFitnessPal. What launched in July is a different order of magnitude. The architecture is the same; the reach is not.
Cole Brennan: But here's what breaks the clean version of that — the moment she actually connects her Epic records to ChatGPT, does HIPAA even follow the data?
Malcolm Reeves: No. And this is the part that quietly unsettles me. OpenAI is a technology company — not a covered healthcare entity under HIPAA. So once those records leave Epic's system and land on OpenAI's servers, the federal protections that governed them inside Epic... they may not travel with the data.
Cole Brennan: Wait — so the act of connecting to ChatGPT Health is itself the thing that strips the protection?
Malcolm Reeves: Structurally, yes. And there's a Lifehacker and Gizmodo-aligned editorial that called the broadly available version a — and this is their phrasing — a 'major downgrade in privacy' from the pilot. But here's the nuance I want to hold onto: this isn't a clean rupture. Patient portals, consumer health apps, data brokers — they've been eroding this for years. b.well, as the infrastructure layer, adds another link in the chain. OpenAI is just the most visible node yet.
Cole Brennan: So it's not that ChatGPT Health broke something — it accelerated something that was already breaking.
Malcolm Reeves: Now picture a 47-year-old woman in Tampa. Thursday, 6 AM, chest tightness, uninsured, terrified of the ER bill. She opens ChatGPT Health. Her Epic records flow through. She is not thinking about data governance — she is scared. And the thing is, that's exactly the use case that makes this feature genuinely valuable and genuinely precarious at the same time.
Cole Brennan: And she has no idea there's no HIPAA backstop on the other end.
Malcolm Reeves: We don't actually know how OpenAI will handle that data long-term. Retention policies aren't publicly detailed. That's — I mean, that's not an accusation, it's an honest gap in what's been disclosed.
Cole Brennan: Which connects directly to something we haven't touched yet — what 'physician-reviewed' actually means for GPT-5.5 Instant, and why the opaque methodology there might matter more than anyone's admitting right now.
Malcolm Reeves: And that opaque methodology is exactly where the weight lands. OpenAI says physician consultants reviewed GPT-5.5 Instant — improvements in accuracy, clarity, completeness. Ashley Alexander, their VP of Health Products, she's the one putting her name on that framing publicly. But the review process itself — who those physicians were, how many, what test set they used — none of that is published.
Cole Brennan: Right — and 'physician-reviewed' is doing, like, enormous credibility work for essentially no disclosed methodology.
Malcolm Reeves: Could one cardiologist reviewing a set of test cases count?
Cole Brennan: Genuinely — I don't know. And I want to be honest about that, because the sourcing here is thin. We don't have the benchmark numbers. OpenAI hasn't disclosed the error-rate thresholds they used to clear this for broad deployment. So we're not in a position to say they cut corners — but we can't say they didn't, either.
Malcolm Reeves: No published clinical benchmarks. That's the gap.
Cole Brennan: And here's what makes it actually — wait, GPT-5.5 Instant is the free-tier model. That's not the premium product for paying subscribers. That is the widest possible audience. So whatever the physician review was — rigorous, cursory, something in between — it's now the safety floor for the most users, not the fewest.
Malcolm Reeves: The opacity scales with the reach.
Cole Brennan: Exactly — I mean, picture a college sophomore, no insurance, Googles a rash at midnight, ends up in ChatGPT Health instead. She's on the free tier. GPT-5.5 Instant. And the only assurance underneath that interaction is 'physician-reviewed' — a phrase Ashley Alexander can say in a press statement without OpenAI ever publishing what it actually means.
Malcolm Reeves: So the question the listener should be sitting with — is 'physician-reviewed' a meaningful clinical safeguard, or is it a credibility wrapper that makes the liability story cleaner without making the product demonstrably safer?
Cole Brennan: And it's free. Not premium, not a gated feature. Free, Go, Plus, Pro. The whole funnel. Which means the liability question isn't abstract anymore. It's: when GPT-5.5 Instant gets something wrong for someone on the free tier, who actually absorbs that?
Malcolm Reeves: The user. That's where the risk lands. Not OpenAI — they've attached the physician consultant framing, they've said 'support, not replace.' The Florida pastor lawsuit is one day old and the formal apparatus is already in place. That's not coincidence, that's — I mean, that sequencing is deliberate risk architecture.
Cole Brennan: Which might end up being a net positive, right? Like, I want to hold that. 300 million people were doing this with zero accountability structure. Now there's at least a named feature, a named VP — Ashley Alexander has her face on it — some form of review. That's more than there was.
Malcolm Reeves: It is more. Whether it's enough — honestly, I don't know. And I think that's where I actually land. Not 'this is dangerous' and not 'this is fine.' Just... the behavior got formalized before the rules did.
Cole Brennan: That's the one sentence I keep — yeah. That's it. The behavior got formalized before the rules did.
Malcolm Reeves: Go get some sleep. And maybe don't diagnose anything tonight.