Nearly one in every six adults now turns to an AI chatbot for health-related questions at least once a month, according to a new survey cited by Consumer Reports. The finding, reported by WPBF 25 News this week, comes as tools like ChatGPT, Microsoft Copilot, and Google Gemini become woven into daily digital life—and as experts sharpen their warnings about unreliable answers and weak privacy safeguards.

The Survey That Should Give You Pause

The 17% figure emerged from a Consumer Reports survey that gauged how often people lean on conversational AI for medical information. Health reporter Kevin Loria told WPBF that the appeal is understandable: “They can be quite good at generating a lot of information, and they're very comprehensive and easy to understand.” For someone facing a long wait for a doctor’s appointment or puzzling over a lab result, an instant, plain-language explanation feels like a gift.

But that fluency carries a trap. “It’s really hard to know when there are inaccuracies, and these systems do get things wrong,” Loria said. “Fabrications can be hard to detect.” A chatbot can invent a dosage, mistake a dangerous symptom for a minor condition, or manufacture a study—all while sounding authoritative. And because the answer is tailored and conversational, users often over-trust it. A separate study found that many people cannot distinguish between a chatbot’s response and a real doctor’s advice.

When Your Windows PC Becomes a Doctor’s Office

For Windows users, the risk is not theoretical. Copilot sits in the taskbar, the Edge sidebar, and Microsoft 365 apps. Asking it about a rash, a medication interaction, or mental health feels as natural as asking for a weather forecast. But a health question is not an ordinary query, and the privacy guardrails many assume exist may not apply.

Microsoft’s consumer Copilot is not a HIPAA-covered entity. The same holds for free versions of ChatGPT and Gemini. The U.S. Department of Health and Human Services clarifies that HIPAA’s protections extend only to certain healthcare providers, insurers, and their business associates—not to every app or chatbot that receives health information. “If an organization does not meet those definitions,” HHS states, “it is not required to comply with HIPAA’s rules.” The Federal Trade Commission separately cautions that health apps and services may use sensitive information for research, advertising, or even sale, and that such tools may not be HIPAA-compliant.

This means the symptom description you type into a chatbot could theoretically be stored, analyzed, or shared far beyond what you intended. A 2026 study from the University of Oxford stressed that real-world use is far messier than curated benchmarks, and that standardized tests cannot establish whether systems are safe for broad public use in high-stakes scenarios.

The Hallucination Problem Isn’t Just Academic

Large language models are pattern matchers, not medical databases. When they lack knowledge, they often generate confident-sounding nonsense. A major randomized study published in Nature Medicine found that when members of the public used LLMs for medical decision support, the systems identified relevant conditions in only about 34% of cases on average. Responses to similar descriptions of potentially serious symptoms varied wildly, leaving users without a reliable signal of urgency.

Researchers at the University of Oxford echoed that finding, warning that “public-facing LLM medical guidance could be inaccurate and inconsistent.” Their large user study demonstrated that people struggle to provide all the context a clinician would normally gather, and that AI cannot compensate for missing information it never received.

This is particularly dangerous in triage situations. A chatbot that downplays chest discomfort one minute and overreacts to a minor headache the next erodes any sense of calibration. And the confident, empathetic tone common to modern AI assistants can lull users into believing the hard work of medical reasoning has been done for them.

A Cascade of Privacy Pitfalls

Users routinely paste detailed health information into chatbots: symptoms, photos, medication lists, lab results, even entire discharge summaries. The logic is simple—the interface feels private, immediate, and nonjudgmental. But that feeling is a poor proxy for legal and technical protections.

“AI systems are not bound by the same privacy laws as your doctor's offices,” Loria cautioned in the WPBF report. The FTC’s consumer guidance adds that health apps and services may collect, use, or share data in ways users don’t expect, and that conventional HIPAA protections don’t automatically follow the data. Even if a piece of information started in a medical record, entering it into an unregulated app removes those safeguards.

For Windows users, Microsoft’s privacy statement for Copilot outlines how data is processed. It may include human review, model training, or retention. That might be acceptable for a recipe suggestion, but for a mental-health crisis or a reproductive health question, the calculus changes.

From WebMD to ChatGPT: A Brief History of Self-Diagnosis

People have always sought health information outside the clinic. WebMD and Google symptom searches became household habits a generation ago. What changed is the interface: where search engines return links and force users to compare sources, chatbots deliver a single synthesized answer in the voice of a knowledgeable assistant. That shift from “here are some resources” to “here is your answer” is profound.

ChatGPT’s launch in late 2022 kicked off an arms race. Microsoft embedded Copilot into Windows, Edge, and Office. Google brought Gemini to phones and the Chrome omnibox. Apple is rolling out its own AI health features. Meanwhile, COVID-19 accelerated telehealth and comfort with digital health tools. The result is an environment where asking an AI about a suspicious mole is just another Tuesday.

But the technology’s rapid deployment has outstripped both regulation and public understanding. A systematic review in JAMA Network Open examined studies evaluating LLM-provided health advice and found such variation in how clinical accuracy was reported that broad claims about medical performance remain unreliable. A Stanford Medicine-led study, meanwhile, discovered that even when AI is used to support physicians, it tends to agree with clinicians rather than challenge them—raising concerns about automation bias rather than independent checks.

A Safer Playbook for Using AI Health Information

The responsible path is not “never use AI.” It is to use AI for preparation and comprehension, not diagnosis or treatment decisions. The goal is to make your next doctor visit more productive, not to replace it.

Stick to education, not diagnosis.
Ask the chatbot to explain a medical term, translate a complex description, or generate a list of questions to bring to your provider. Instead of “Do I have condition X?” try “What should I ask my doctor about symptoms like X and Y?” Instead of “Can I stop taking this medication?” try “What side effects should I report to my pharmacist when taking drug Z?”

Strip identifying details.
Never paste full names, addresses, insurance IDs, patient portal credentials, or identifiable medical reports into a consumer chatbot. If you want help formulating a question, describe the situation in general terms. Even then, treat the output as a draft for a human conversation.

Verify, verify, verify.
For any health information that could influence a decision, require the chatbot to identify a primary medical authority—a guideline from the CDC, NIH, or a respected medical organization—and then open the original source. Do not accept a citation at face value; AI can invent study titles and authors. Compare at least two authoritative sources. If the information still feels actionable, run it past a clinician or pharmacist.

Know the privacy landscape.
Read Copilot’s privacy settings. Review the terms for any AI tool you use. The FTC recommends understanding what data an app collects and shares before entering sensitive information. Assume that anything you type may be stored, used for training, or accessed in a breach.

Trust flesh-and-blood professionals.
If a situation appears urgent, severe, rapidly worsening, or potentially life-threatening, step away from the prompt field and contact local emergency services or a qualified medical professional.

The Next Chapter in AI Health Advice

Regulators are watching. The FTC has signaled interest in health app privacy enforcement, and lawmakers are beginning to ask whether consumer AI tools should carry clearer medical disclaimers. In the research community, pressure is mounting for transparent, real-world testing of AI safety in health contexts—not just benchmark scores.

Microsoft, Google, and OpenAI are all actively working on HIPAA-compliant enterprise versions of their AI for healthcare organizations. But those remain for professional use, behind institutional access controls, not for individual consumers firing off a quick prompt. The gap between what AI can do in a controlled clinical setting and what it should do in a living room at midnight remains wide.

For now, the best health advisor remains a licensed, accountable human who can see the full picture—and who carries real liability for getting it wrong. AI can inform that human, but it doesn’t yet replace them.