DISPATCHES · Summit Cognitive

← All dispatches

Data GovernanceField NotesJuly 26, 20264 min read

Connected health data needs a context boundary

Making health records available across conversations improves continuity while expanding the number of ordinary contexts in which sensitive facts can influence an answer.

A dedicated health space creates a visible boundary. The user enters it expecting medical context to matter. When connected health information can inform ordinary conversations, continuity improves: dietary restrictions can shape restaurant suggestions, injuries can shape activity plans, and recent results can inform appointment preparation. The same convenience makes the boundary less obvious. Sensitive context can become relevant in places that do not feel clinical.

OpenAI's July 23 Health launch says users can choose to let connected medical records and Apple Health information inform conversations across ChatGPT. By default, the product asks permission before using connected health information, and users can allow access once or always. This is a meaningful context-control surface, not a one-time connection decision.

Connection, retrieval, use, memory, and disclosure are different acts. A user may connect a record for one purpose, permit its use in a response, decline to create durable memory, and still not intend the resulting inference to leave through another plugin. Product design should preserve these distinctions rather than compressing them into health access enabled.

Make relevance and provenance visible

When health context influences an answer, the user should be able to see that it was used and identify the relevant source. A medication list from a hospital record, a wearable metric, and a fact the user typed have different authority and freshness. An answer that blends them without provenance can sound coherent while hiding a consequential disagreement.

The system should minimize what it retrieves. A restaurant question may need an allergy, not a complete record. An exercise plan may need a recent injury and activity trend, not unrelated diagnoses. Purpose-limited retrieval reduces exposure and makes the user's permission easier to understand.

A connected record should become relevant by purpose, not merely available by proximity.

Cross-context tests should include accidental disclosure, ambiguous pronouns, shared devices, quoted conversations, plugin actions, and tasks where health is only indirectly relevant. The question is not only whether the model can use the information helpfully. It is whether the system can avoid using or exposing it when the user's purpose does not support that step.

The boundary must survive model and feature changes. A new memory system, connector, action plugin, or conversational mode can create a fresh route for health-derived information. Dependency reviews should reopen the context assessment before the old permission is allowed to authorize the new path.

Permission state should be easy to inspect and change from the conversation where it matters. A person should be able to see whether health context was allowed once, allowed persistently, denied, or unavailable because the source disconnected. Revoking persistent use should affect future retrieval promptly without pretending that prior messages never contained the information. These states require clear language because deletion, disconnection, and permission withdrawal have different effects.

Context selection should tolerate uncertainty. A system may infer that a request concerns diet, exercise, travel, work accommodations, or family planning without knowing whether the person wants health data involved. In borderline cases it can ask narrowly before retrieval and explain what category would help. The question should not reveal a hidden diagnosis on a shared screen merely to obtain permission to use it.

Evaluation needs paired cases in which the ordinary answer is useful both with and without health context. Reviewers can then see whether connected data materially improves the response, introduces unwarranted medical framing, or leaks into wording that a bystander could interpret. Measure unnecessary health-context invocation as a failure class, not just failure to use relevant information.

The experience should support a temporary mode for sensitive planning. A person may want connected context for one conversation without adding durable memory or allowing it to influence later topics. Temporary use needs a clear end state and a receipt of what was accessed. It should not promise that downstream systems forgot information they were required to retain; it should state the actual boundary in plain language.

Operate the boundary

The practical starting point is a named control for the distinction among connection, purpose-limited retrieval, response use, memory, and external disclosure of health-derived information. Write the boundary in terms an operator can evaluate: the initiating principal, permitted purpose, affected resources, allowed consequences, escalation path, expiry condition, and evidence produced. A policy sentence is useful context; the enforced object and its observable state are what make the policy operational.

Test the boundary by moving the same health fact across dedicated, ordinary, temporary, shared, and plugin-enabled conversations while varying the user's permission at each step. Preserve the starting state, the agent's route, any intervention, the final effect, and the gaps in observation. Repeat the exercise after changing a model, tool, provider, policy, or data source. A control that passed once should not silently lend its assurance to a materially different system.

The leading signal is health-context uses with visible source and purpose, plus prevented or confirmed external disclosures and stale-source warnings. Pair it with a consequence measure so teams do not optimize the dashboard while weakening the outcome. Review both on a fixed cadence and after every material incident or migration. When the signal disappears, determine whether the risk disappeared or the instrumentation did.

The health-data product and privacy owners together should own the decision to continue, narrow, pause, or expand the workflow. The owner needs authority over the control and access to its evidence; responsibility without either becomes ceremonial. Record the decision, the evidence cutoff, the residual uncertainty, and the next review date so the claim can age honestly.

— Dispatches · Summit Cognitive

Continue from here

Turn the argument into a practice.

Get new dispatches, assess how your organization handles consequential decisions, or explore Summit Cognitive.