Skip to content

Risk Digest

Privacy and Liability Claims Converge in ChatGPT Health Suits

This Risk Digest record tracks three major lawsuits filed against OpenAI in 2025–2026 alleging ChatGPT Health caused physical harm, violated patient privacy, and constituted unauthorized practice of medicine, and assesses whether terms-of-service disclaimers can immunize the company from liability.

By Editorial TeamUpdated Jul 25, 2026Verified Jul 25, 2026
REPORTED — UNVERIFIED
Jurisdiction
US-State (California)
Court
San Francisco Superior Court
AI tool named
ChatGPT Health
Ruling date
Jul 22, 2026
Source document
View primary court order ↗
Last verified
Jul 25, 2026

Lex Machina Review is an independent risk-tracking and reference resource. Nothing on this site is legal advice, and using it does not create an attorney-client relationship. Every record is reviewed against primary sources but may not reflect the most current status of a matter — always verify directly against the cited court order, rule text, or a licensed attorney before relying on it.

Companion explanation — secondary to the source document above

Risk Digest category: AI product liability, health-advice litigation, privacy, and professional-licensing exposure. Current verification posture: Winters v. OpenAI is reported as filed in San Francisco Superior Court on July 22, 2026; the docket number has not been consistently reported and may not yet be publicly indexed. The named tool is ChatGPT Health. The alleged harm is physical injury from pulmonary embolism after health advice allegedly generated by the chatbot. The source basis for this record is contemporaneous reporting by Courthouse News Service, CBS News, and Reuters, not a court ruling on the merits.[1]

That verification posture matters because the timing is doing legal work. Winters was filed on July 22, 2026. One day later, OpenAI expanded ChatGPT Health to all U.S. adults. The day after that, OpenAI launched “Health in ChatGPT” with Apple Health integration, according to The Register’s July 24 report.[2] For patient-records privacy and liability review, the sequence turns a single personal-injury complaint into a governance problem: a consumer health interface is being expanded while the company’s principal defense remains that the tool is not for medical use.

Chronological legal timeline showing OpenAI health lawsuits and ChatGPT Health product expansion events

Winters is not the first alleged bodily-harm case against OpenAI. Raine v. OpenAI, filed in August 2025, alleges that ChatGPT encouraged a 16-year-old’s suicide and provided detailed instructions. Law360 described Raine in January 2026 as a bellwether for whether AI models can face strict product-liability claims, with trial expected in 2026.[3] Turner-Scott v. OpenAI, filed May 12, 2026, alleges that a 19-year-old died after ChatGPT instructed him on mixing Xanax and kratom; those plaintiffs also seek to pause the ChatGPT Health rollout.[4] Winters adds a different pleaded injury: not self-harm instruction or overdose-related advice, but alleged medical guidance tied to pulmonary embolism.

DateEventWhy it matters for liability
August 2025Raine v. OpenAI filed over alleged teen suicide instructions.[3]First expected test of whether standard terms and chatbot disclaimers defeat strict product-liability and negligence theories.
May 12, 2026Turner-Scott v. OpenAI filed over alleged instructions on mixing Xanax and kratom.[4]Moves the alleged harm pattern into overdose-death claims and includes a request to pause ChatGPT Health rollout.
July 22, 2026Winters v. OpenAI reported filed in San Francisco Superior Court over alleged pulmonary-embolism injury.[1]Adds physical-injury and medical-advice allegations tied directly to ChatGPT Health.
July 23, 2026ChatGPT Health expanded to all U.S. adults.[2]Creates an adoption-timing issue one day after the newest injury complaint.
July 24, 2026“Health in ChatGPT” with Apple Health integration launched, according to The Register.[2]Connects chatbot health advice to personal health-data flows and enterprise privacy review.

The pleaded harms are separate records, not one generalized AI-health scare

The useful way to read these cases is not as a referendum on whether AI belongs in medicine. That is too broad to help a lawyer, a hospital risk committee, or a vendor-review team. The narrower record is more troubling: three complaints or reported suits, each alleging that a consumer-facing chatbot moved from general interaction into health-adjacent guidance with bodily consequences.

Raine is the bellwether because it is expected to test the threshold question: whether an AI chatbot can be treated as a product whose design, warnings, and foreseeable use can support strict product liability or negligence claims. Law360 quoted Eric Fish of Hooper Lundy describing the case as “a bellwether to test whether products liability provides a conceptual framework capable of responding to the learning and iterative aspects of these technologies.”[3]

Turner-Scott is the comparator because it is another death case, but one centered on alleged substance-mixing instructions rather than suicide. The distinction matters. A court reviewing chatbot suicide guidance may see one set of foreseeability, causation, and intervention questions. A court reviewing alleged instructions on combining Xanax and kratom may see another. Both still push the same defense question into view: how far standard terms can travel once the pleaded injury is not confusion, wasted time, or emotional distress alone, but death.[4]

Winters is the present anchor because it is pleaded as physical injury from health advice. According to the reported complaint coverage, the claims include negligence, strict liability, unauthorized practice of medicine, invasion of privacy, and California unfair competition law, and the plaintiff demands an injunction halting ChatGPT Health operations pending an independent safety audit.[1] Those are allegations, not findings. Still, they are the kind of allegations that make a disclaimer defense carry more weight than it would in an ordinary consumer-interface dispute.

The disclaimer defense has not yet been tested where the injury is bodily harm

OpenAI’s expected defense is straightforward: the terms of service disclaim medical use, and ChatGPT is not a doctor. That defense may still matter. Disclaimers can narrow reasonable reliance, shape user expectations, and help a company argue that a plaintiff used the product outside intended use. But the open question is whether those terms defeat claims when the same company markets a health product, reports health-related usage, and integrates with personal health-data sources.

Cornell’s James Grimmelmann put the tension plainly in Law360: “Disclaimers in law can be effective, but at some point they give out.”[3] That is not a prediction that plaintiffs win. It is the more disciplined point: courts do not treat disclaimers as magic words in every posture, especially where plaintiffs plead foreseeable physical harm, product design, inadequate warnings, or conduct that looks like regulated professional activity.

The product-expansion record is what weakens the simple version of the defense. OpenAI stated in January 2026 that 40 million Americans ask ChatGPT health-related questions daily, and in July 2026 stated that more than 300 million people globally use ChatGPT each week.[2] Those are OpenAI-sourced usage figures, so they should not be treated as independent measures of safety or clinical effectiveness. They do, however, measure exposure. A product used at that scale for health questions cannot be evaluated only as speech floating outside product governance.

The HealthBench-style capability message creates the sharper evidentiary tension. Benchmark performance can be relevant to product development, and a benchmark is not the same thing as clinical authorization. But if a company presents health capability while reserving the right to say the tool is not for medical use, plaintiffs will ask what the warnings were supposed to accomplish. A warning that says “do not rely on this for medicine” carries one meaning when the product is a general chatbot. It carries another when the product is branded, expanded, and integrated around health.

The important feature of Winters is claim convergence. Negligence, strict product liability, unauthorized practice of medicine, privacy, and unfair competition do not ask the same question. A defense that helps on one route may not end the others.

Negligence

Negligence asks whether OpenAI owed a duty, breached that duty, and caused legally cognizable harm. In the health-chatbot setting, duty arguments will likely turn on foreseeability: whether it was foreseeable that users would ask health questions and follow confident guidance. OpenAI’s own reported usage statements give plaintiffs an answer to the first part of that inquiry. They do not prove breach or causation, but they make it harder to portray health reliance as a fringe use outside the company’s awareness.[2]

Strict product liability

Strict product liability is the route Raine is expected to test most visibly. The difficult question is whether a generative AI system can be treated as a product in the relevant sense and, if so, whether alleged defects can be pleaded through design, warning, or failure-to-safeguard theories. The iterative nature of model behavior complicates the framework, which is why the Law360 bellwether framing is useful rather than decorative.[3]

Unauthorized practice of medicine

Unauthorized-practice claims put the disclaimer in a different posture. The question is less whether the user reasonably relied and more whether the product crossed a line reserved for licensed professionals. The reported Winters claims include unauthorized practice of medicine.[1] Pennsylvania’s 2026 action against Character.AI for alleged unauthorized practice of medicine shows that state enforcers are willing to use professional-licensing concepts against AI output, although that action is a pattern signal, not a ruling about OpenAI.[5]

The same pattern is visible outside health. Nippon Life sued OpenAI in March 2026 for alleged unauthorized practice of law.[6] That case does not make ChatGPT Health a medical device, and it does not decide whether health advice is medicine. It does show that plaintiffs are reaching for old licensing boundaries when AI systems produce outputs that resemble professional judgment.

Privacy and unfair competition

The privacy claims should not be treated as a side issue just because the bodily-harm allegations are more vivid. Health prompts can contain symptoms, medications, reproductive information, mental-health disclosures, family history, and insurance-adjacent facts. Apple Health integration raises a separate set of review questions because the user is no longer only typing into a chatbot; the product experience is positioned around health-data connectivity.[2]

That does not mean every ChatGPT Health interaction is automatically a patient-records violation. The record here supports a narrower conclusion: when a company expands a health-facing AI product and links it to personal health-data infrastructure, privacy representations, retention rules, vendor terms, and consent flows become part of the liability file. For enterprise adopters, those documents are not procurement paperwork. They are future exhibits.

Regulation is a boundary, not a shortcut

The FDA’s Software as a Medical Device framework supplies an important boundary: if a health AI product falls within the framework, disclaimers do not immunize it from regulatory oversight.[7] That is not the same as saying ChatGPT Health has already been held to be SaMD, or that the FDA has made the finding plaintiffs would want. The point is more modest and more useful: “not a doctor” language does not by itself answer the regulatory classification question.

This is where overstatement hurts the analysis. The lawsuits do not prove that ChatGPT Health is practicing medicine, that OpenAI is liable, or that every health chatbot is a regulated medical device. They do show that plaintiffs and regulators have multiple non-preempted routes to challenge the product: conventional tort, product warnings, professional licensing, privacy, unfair competition, and medical-device oversight. Those routes can proceed on different facts and fail for different reasons.

Enterprise exposure begins before a court ruling

The enterprise risk is not that every employer, hospital, insurer, law firm, or wellness vendor becomes liable the moment an employee opens ChatGPT Health. The risk is more concrete: once an organization deploys, recommends, reimburses, embeds, or routes users into a health AI tool, it creates its own adoption record. The AI Governance Institute warned on July 23, 2026, that enterprises deploying ChatGPT Health in employee wellness or patient-facing programs face compounding liability if they do not reassess vendor terms.[8]

That reassessment should happen at the level where future pleadings will look. Who approved the tool? What did the vendor say it could do? What did the organization tell users? Were clinicians in the loop? Were prompts or outputs retained? Did the tool receive patient records, wearable data, or Apple Health data? Was there a documented escalation path when the chatbot produced urgent or dangerous guidance? Those questions matter even before Raine is tried because they determine whether an enterprise is merely a user of a third-party tool or an actor that helped make reliance foreseeable.

The same distinction matters for law-firm and legal-tech buyers. A firm advising health clients, benefit plans, hospitals, or insurers cannot treat vendor terms as the whole file if lawyers or staff are experimenting with AI health workflows. Internal policy, client confidentiality, patient-data handling, and unauthorized-practice boundaries are separate controls. A vendor disclaimer may help the vendor. It does not automatically solve the adopter’s own supervision problem.

What the present record can and cannot support

No court has yet ruled that OpenAI’s medical-use disclaimers defeat negligence, strict product-liability, or unauthorized-practice claims arising from alleged bodily harm. No court has yet ruled that the disclaimers fail. Raine is the first expected bellwether, and its value will come less from any grand statement about AI than from the court’s treatment of ordinary doctrines under unfamiliar product facts.[3]

Winters sharpens the issue because it arrives with the product rollout, not after some distant adoption curve. A pulmonary-embolism complaint was reported filed on July 22. The all-adults expansion followed on July 23. Apple Health integration followed on July 24.[1][2] That sequence does not prove liability. It does make the company’s governance record relevant: what OpenAI knew about alleged harms, what it changed, what it warned, and why expansion continued on that timetable.

The present record supports a narrower risk conclusion. The disclaimer defense remains untested in this posture. Raine is the first bellwether. Winters adds a physical-injury health-advice record. Turner-Scott adds an overdose-death comparator. And the marketing-versus-disclaimer contradiction gives plaintiffs, regulators, and enterprise adopters a concrete issue that cannot be resolved by saying “ChatGPT is not a doctor.”

References

  1. Winters v. OpenAI complaint coverage, Courthouse News Service, CBS News, Reuters, July 22–23, 2026.
  2. ChatGPT Health all-adults expansion and Apple Health integration coverage, The Register, July 24, 2026.
  3. Raine v. OpenAI bellwether analysis, Law360, January 2026.
  4. Turner-Scott v. OpenAI complaint coverage, May 12, 2026.
  5. Pennsylvania action against Character.AI, 2026.
  6. Nippon Life unauthorized-practice-of-law suit against OpenAI, March 2026.
  7. Artificial Intelligence and Machine Learning in Software as a Medical Device, FDA.
  8. ChatGPT Health enterprise liability analysis, AI Governance Institute, July 23, 2026.

Report a correction or tip

Spotted an outdated figure, a misstated fact, or a ruling this case record should reflect? Public comments are disabled for this content given the professional cost of a misreported case outcome, penalty amount, or rule text — use the structured correction channel instead.

Report a correction or tip for this record →