Privacy Experts Warn Against Uploading Medical Scans to AI Chatbots

Security advocates urge people to stop sharing sensitive medical images like X-rays and MRIs with AI chatbots. Uploading this data risks exposing private health information and potentially feeds it into AI training datasets without strict protections.

Security and privacy advocates strongly warn users against uploading sensitive medical images, such as X-rays, MRIs, and PET scans, to AI chatbots like ChatGPT, Gemini, and Grok. Although users increasingly turn to generative AI to interpret their health results, this practice exposes highly protected personal data to significant risks. Medical data carries federal protections, but those safeguards disappear the moment a user voluntarily shares this information with a consumer AI application.

The primary danger stems from how generative AI models handle uploaded inputs, as companies frequently use this data to train and improve their systems. It remains unclear exactly how these tech companies utilize, store, or share the medical images they receive, forcing users to rely entirely on corporate promises. Furthermore, most consumer AI apps do not fall under the strict protections of the U.S. healthcare privacy law HIPAA, leaving uploaded health data completely vulnerable.

This trend gains particular attention as platforms like X actively encourage users to submit medical scans to the Grok chatbot to improve its diagnostic capabilities. However, Grok's privacy policy reveals that X shares user personal information with an unspecified number of related companies, raising serious concerns about who ultimately accesses these private records. Because private medical data has already been discovered in public AI training datasets, users face the real threat that their sensitive health information becomes permanently accessible to employers, insurers, or malicious actors.

Read More at the original source →