ChatGPT Expands Into Sensitive Data
Coverage from The Record, Startup Fortune, and others
Articles
33
Active Days
428
The Topic

OpenAI is extending ChatGPT beyond general conversation into financial guidance, medical-record analysis, persistent file storage, and mental-health safety interventions. These features increase the platform’s practical value while also concentrating highly sensitive information and decisions inside a consumer AI service, raising questions about data retention, legal protections, account compromise, consent, and human oversight. A separate Japan-based incident illustrates how ChatGPT-generated code can also support unauthorized activity against online services.
First Article: 05/26/25
Latest Article: 07/27/26
Summary
- ChatGPT Finance connects accounts from thousands of financial institutions and exposes balances, spending, investments, and payment information to the service.
- ChatGPT Health can combine medical records, laboratory data, and wearable information, but connected records may not retain the same protections they had with healthcare providers.
- OpenAI says financial and health data can be disconnected or deleted and that health data is not used for model training or advertising; experts describe some protections as contractual or insufficient.
- ChatGPT Library stores uploaded and generated files separately from conversations, so deleting a chat does not necessarily delete associated files.
- Trusted Contact adds optional human review and notifications for suspected serious self-harm situations, creating a tradeoff between intervention and sensitive mental-health privacy.
- A Japanese investigation alleges that a teenager used ChatGPT-assisted code and rotating IP addresses to disrupt Bandai Channel and compromise user information.
History
The story is sharpened around specific ChatGPT product rollouts for finance and health, with clearer claims about data protections and a new human-review safety feature for self-harm cases. The cyber incident is also reframed as a Japanese allegation involving a teenager and rotating IPs, rather than a more general disruptive-code example.
The biggest change is that the story now includes a new safety-intervention dimension: OpenAI is adding human-reviewed alerts for suspected serious self-harm discussions, which raises fresh concerns about sensitive disclosure. The security angle also broadened, with a reported Bandai incident now described more specifically as ChatGPT-assisted code enabling account disruption and IP-blocking evasion.
