Health

ChatGPT and health data: what professionals need to know

Summarising a report, rewording a letter, preparing a summary: generative AI tempts healthcare professionals too. But health data is among the most protected data in French and European law. What you need to know before pasting a single line of a patient record.

Published on Updated on 6 min readBy the Tacite-IA editorial team

Contents
  1. What counts as health data?
  2. Medical secrecy and information sharing
  3. Health data hosting (HDS)
  4. What the authorities recommend
  5. Possible uses, provided you minimise
  6. Good practice for a practice or a healthcare facility
  7. Frequently asked questions
  8. Sources

Summarising a report, rewording a letter to a colleague, preparing an information leaflet or a literature review: generative AI also appeals to healthcare professionals, in private practice as in hospitals. But a patient record is not just any text. Health data is protected at once by the GDPR, by medical secrecy and by hosting rules specific to France. Here, with sources, is what you need to know before pasting a single line of a patient record into ChatGPT or another assistant.

What counts as health data?

The GDPR defines data concerning health as personal data related to the physical or mental health of a person, including the provision of health care services, which reveal information about their health status (Article 4, point 15).1 The definition is broad: a reason for consultation, a treatment, a test result or a simple mention of sick leave all fall within it.

This data belongs to the special categories whose processing is prohibited in principle (Article 9(1)), subject to the exceptions listed in paragraph 2, including preventive medicine, medical diagnosis and the provision of health care, under the responsibility of a professional bound by secrecy.1 France’s data protection authority, the CNIL, specifies that health data covers a person’s past, present or future physical or mental health.7

Medical secrecy and information sharing

Article L1110-4 of the French Public Health Code guarantees every person receiving care respect for their private life and for the secrecy of information concerning them. This secrecy covers all information that has come to the professional’s knowledge and applies to all professionals working within the health system.2 The sharing of information between professionals is itself governed by this text. Breach of secrecy is punishable by one year’s imprisonment and a fine of 15,000 euros (Article 226-13 of the French Criminal Code).3

Entering elements of a patient record into an online AI service amounts to passing them to a third party that processes them on its servers. For its consumer services, OpenAI states that it may use content to improve its models, unless this is turned off, and asks users not to enter sensitive information that they would not want reviewed or used.9 The question is therefore not merely technical: it goes to the heart of the secrecy owed to the patient.

The message is sent as it is: the name, IBAN and health information reach the vendor, which processes and retains them under the rules of the plan being used.

A letter containing health data, sent as it is or after the data has been replaced on the computer. Fictitious data.

Health data hosting (HDS)

In France, Article L1111-8 of the Public Health Code requires anyone who hosts personal health data collected in the course of prevention, diagnosis, care or social and medico-social follow-up, on behalf of the person who produced it or of the patient, to hold a certificate of conformity (HDS certification, for hébergement de données de santé) when the hosting is on digital media; hosting on paper is subject to a separate approval.4 The same article leaves it to a decree to specify the host’s obligations regarding storage of this data within the territory of a Member State of the European Union or of the European Economic Area.4 France’s digital health agency (Agence du numérique en santé) describes the scheme, under which the certificate is issued for three years.5 Since the certification framework published in the Journal officiel (France’s official gazette) in May 2024, the physical hosting of the data must take place exclusively in a country of the European Economic Area.10

For a professional, the practical consequence is to check, before adopting a tool that stores patient data on their behalf, whether that tool or its host holds the appropriate certification. A consumer chat assistant is not designed as a medical record hosting service. For everyday uses, the simplest approach is still not to put any identifying data into it.

What the authorities recommend

On 30 October 2025, France’s national authority for health (Haute Autorité de santé, HAS) published a guide entitled “Premières clefs d’usage de l’IA générative en santé” (first keys to using generative AI in health), updated on 15 April 2026 and organised around four verbs: learn, check, assess, communicate.6 One of its keys deals specifically with confidentiality: whenever a generative AI system is accessible on the internet or offers no assurance that confidentiality is respected, each request must be checked to ensure that no information allowing direct or indirect identification, or covered by medical secrecy, is shared.6

The HAS gives concrete examples of elements to remove: surnames, first names, initials, dates, postal and email addresses, phone numbers, social security numbers.6 It also points out that professionals must check the content produced before using it.

For its part, the CNIL recommends that every organisation govern the use of generative AI through a policy, involve the data protection officer and train users.8 In the health sector, these recommendations take on particular importance, since the data at stake is among the most sensitive.

Possible uses, provided you minimise

Many tasks require no data about a specific patient: preparing a general information leaflet, rewording a protocol, structuring a presentation, translating a document with no identities in it. Others can be done on a text from which identifying elements have been removed. The difficulty in healthcare is that context quickly identifies someone: a rare condition, an age, a town and a date of hospital admission may be enough to recognise a person. We cover this question in our guide to anonymising data before ChatGPT.

referral-letter.txtAnonymised version

Can you reword this letter more clearly?

“I am referring Mr André Fabre[NAME_1], born on 14/02/1957[DATE_OF_BIRTH_1], NIR 1 57 02 33 063 123 08[NIR_1],

followed for poorly controlled type 2 diabetes[HEALTH_1], for your opinion on adjusting his treatment.”

4 items replaced on the device
The identifying elements and the health data are replaced before sending; the rewording request remains possible. Fictitious example. A human reread is still needed for context.

Good practice for a practice or a healthcare facility

  1. No identifying data in a consumer toolName, date of birth, social security number, address, file number.
  2. Remove the context tooRare condition, place, date of hospital admission: all clues.
  3. Check the tool’s frameworkContract, place of processing, retention, certified hosting where required.
  4. Keep clinical judgementReread and check any output before using it.
  5. Involve the DPORecord of processing, impact assessment, patient information where needed.
  6. Write the rule downA policy that says what is allowed, and with which tools.
Six rules built from the GDPR, the French Public Health Code and the recommendations of the HAS and the CNIL (sources 1, 2, 4, 6 and 8).

These rules naturally belong in an AI use policy, which we offer as a template to adapt. For contractual aspects and general compliance, see also our article on ChatGPT and GDPR compliance for businesses.

Tacite-IA can help apply the rule at the moment it matters: it detects on the computer, before anything is sent to AI assistants in Chrome and Edge, names preceded by a title (Mr, Ms, Dr…), social security numbers, dates of birth and health mentions, and offers a version in which they are replaced with tags. Attached files are read on the computer and replaced with an anonymised text copy; scanned PDFs cannot be read. The analysis is carried out without AI and without sending the content to our servers. It does not replace rereading for context or choosing suitable tools, and it does not cover desktop apps.

Frequently asked questions

Can a doctor use ChatGPT?

No text prohibits the tool as such, but in France doctors remain bound by medical secrecy (Article L1110-4 of the Public Health Code) and by the GDPR, which classes health data as sensitive data. For any tool accessible on the internet without a guarantee of confidentiality, France’s national authority for health (HAS) recommends checking that no identifying information or information covered by medical secrecy is shared.

Can health data be sent to an online AI?

Health data is a special category of data (Article 9 of the GDPR), whose processing is only permitted in specific cases and with safeguards. Sending it to a consumer service raises questions of secrecy, sub-processing and hosting. The simplest solution is to remove every identifying element before sending.

What is HDS certification?

It is the certification required by Article L1111-8 of the French Public Health Code to host personal health data on digital media on behalf of a professional, a facility or the patient. Issued for three years, it has required physical hosting within the European Economic Area since the 2024 certification framework.

Is removing the patient’s name enough?

Often not. In healthcare, context quickly identifies someone: a rare condition, an age, a town or a date of hospital admission may be enough. You need to remove direct identifiers and reread the text for these indirect clues.

Sources

  1. Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data (General Data Protection Regulation). EUR-Lex. Accessed on 5 October 2026.
  2. French Public Health Code (Code de la santé publique), Article L1110-4 (private life and secrecy of information). Légifrance (official French legal database). In French. Accessed on 8 October 2026.
  3. French Criminal Code (Code pénal), Article 226-13 (breach of professional secrecy). Légifrance (official French legal database). In French. Accessed on 8 October 2026.
  4. French Public Health Code (Code de la santé publique), Article L1111-8 (hosting of health data). Légifrance (official French legal database). In French. Accessed on 8 October 2026.
  5. Certification HDS : tout savoir. Agence du numérique en santé (France’s digital health agency). In French. Accessed on 8 October 2026.
  6. Premières clefs d’usage de l’IA générative en santé. Haute Autorité de santé (France’s national authority for health), 30 October 2025, updated on 15 April 2026. In French. Accessed on 8 October 2026.
  7. Qu’est-ce qu’une donnée de santé ?. CNIL (French data protection authority), 8 January 2018. In French. Accessed on 8 October 2026.
  8. Les questions-réponses de la CNIL sur l’utilisation d’un système d’IA générative. CNIL (French data protection authority), 18 July 2024. In French. Accessed on 5 October 2026.
  9. How OpenAI handles data in consumer services. OpenAI Help Center. Accessed on 5 October 2026.
  10. Publication au Journal officiel du référentiel de certification HDS : souveraineté des données et améliorations du référentiel. Agence du numérique en santé (France’s digital health agency), 16 May 2024. In French. Accessed on 8 October 2026.
One measure among others

Govern AI use without slowing your teams down

Tacite-IA detects sensitive data in messages and files before they are sent to AI assistants in Chrome and Edge, and in coding assistants (Claude Code, Cursor, Windsurf, Codex, Gemini CLI, Copilot CLI). Analysis runs 100% on the device, with no AI, and comes with an admin console and an audit mode. Desktop apps (the ChatGPT desktop app, the Chat tab in Claude Desktop, Copilot in Windows) are not covered.

€6 excl. VAT per user per month billed annually, €8 excl. VAT billed monthly. 3-month trial.

Further reading