Kaizen Health logo
Try Kai free

Is It Safe to Share Family Medical Records with AI?

Pollsters have measured whether people use AI for health questions and how worried they are about privacy in general. Almost nobody has asked the family-specific version of that question yet. Here's what the data on record actually shows, and what it doesn't.

Kaizen Health Editorial TeamReviewed by the Kaizen Health editorial team
11 min read
An adult daughter and her senior mother looking together at a smartphone screen, smiling, in natural outdoor light
Key takeaways
  • The people most likely to say they get health information from AI chatbots are the youngest adults, not the parents or grandparents whose records families are often the ones deciding whether to share: 32% of adults 18-29 do, versus 16% of those 50-64 and 10% of those 65+ (Pew Research Center, April 2026).
  • The one confirmed, publicly disclosed incident involving a healthcare AI vendor in 2026 is the Xsolis breach: 1,396,519 people's records exposed after a phishing attack, disclosed via HHS OCR in June 2026. It was a breach of vendor infrastructure, not a case of a chatbot mishandling what someone typed into it.
  • Two federal and state regulatory actions launched in the past year, an FTC 6(b) inquiry (September 2025) and a 42-state attorneys general subpoena of OpenAI (June 2026), both explicitly name health data and how companies treat minors and seniors. Neither has concluded, but both signal regulators see this as unsettled.
  • AI use among adults 50+ nearly doubled in a year, from 18% in 2024 to 30% in 2025, with privacy concerns cited as the top adoption barrier (AARP Tech Trends, April 2026). Older adults aren't sitting this out; they're already deciding, often without family-specific guidance.
  • No major pollster has yet asked the questions that actually determine a family's risk: whether people feel differently sharing a parent's data than their own, which types of health information they'd share versus withhold, or who in the family is actually the one typing it in. That's a real gap in the evidence, not a settled answer either way, and it's the reason a framework matters more than a single stat here.

Search “is it safe to share medical records with AI” and most answers you’ll find borrow the same handful of statistics: how many adults use AI chatbots for health questions, how worried people say they are about privacy in general. Those numbers are real, and our guide to AI agents in family health and AI agent vs. chatbot breakdown already cover them, along with the HIPAA, training, and retention checklist every family should run before connecting any tool to a parent’s or child’s records. What none of that polling actually asks is the family-specific version of the question: do people feel differently sharing a parent’s data than their own? Which kinds of health information would they share, and which would they hold back? Who, in practice, is the one doing the typing?

This piece is built around what the evidence on record actually supports, including where it runs out. That gap, paired with the one confirmed 2026 incident involving a healthcare AI vendor and two live regulatory actions, is itself the honest, sourced answer to “is this safe” right now: safer than the general headlines suggest in some ways, less settled than a confident yes or no in others.

What the polling actually asks, and what it leaves out

A Pew Research Center report published April 7, 2026 (surveying 5,111 U.S. adults, fielded October 20-26, 2025) found a clear age gradient in who turns to AI chatbots for health information at least sometimes: 32% of adults 18-29, compared with 16% of adults 50-64 and just 10% of adults 65 and older. That’s a meaningfully different picture than a single topline number suggests. The people asking AI chatbots health questions directly skew young, while the parents and grandparents whose records a family often has to decide whether to share skew toward the group least likely to be the one asking.

Separately, KFF’s March 2026 tracking poll found 32% of adults had turned to AI for health information in the past year, and among those who had entered personal medical information into an AI tool, 65% said they were concerned about its privacy. Both figures are useful, and both stop short of the question this article’s title actually asks. Neither KFF nor Pew has published data comparing how someone feels about sharing their own health information with AI versus sharing a parent’s or a dependent’s, and neither has broken down willingness to share by the type of information involved, a medication list versus a mental health note versus a genetic test result. Those are real, specific gaps in the public record, not numbers this article is choosing to omit.

The one confirmed incident on record

Rather than a general warning, here is a specific, documented case. Xsolis, a healthcare AI vendor whose clinical-decision tools are used by hospital systems including Mayo Clinic, Legacy Health, Rochester Regional Health, and UW Medicine, suffered a phishing-based breach beginning January 20, 2026. According to HIPAA Journal’s reporting and TechTarget’s coverage, the breach exposed names, Social Security numbers, dates of birth, insurance information, and medical treatment records belonging to 1,396,519 people. It was publicly disclosed through the HHS Office for Civil Rights breach portal on June 22, 2026, five months after the intrusion began. Becker’s Hospital Review counted eight health systems affected in total.

1.4M
people's records exposed in the Xsolis healthcare AI vendor breach, disclosed via HHS OCR in June 2026
5 mo.
gap between the January 2026 phishing intrusion and its public disclosure that June
8
hospital systems confirmed affected, including Mayo Clinic and UW Medicine (Becker's Hospital Review)

The distinction worth holding onto is what kind of risk this was. Xsolis is infrastructure hospitals use behind the scenes for clinical decision support, not a consumer chatbot a family types questions into directly. The breach happened because someone clicked a phishing link inside the vendor’s systems, the same way breaches have happened at healthcare vendors for years before AI was part of the story. It is not evidence that an AI tool misread, leaked, or misused what a person typed into it in the moment. Both are real categories of risk. They are not the same risk, and a family evaluating any AI health tool should ask about both separately: what happens to data behind the scenes, and what happens to what you type in directly.

Regulators are asking the family question, even if pollsters aren’t

Two active actions launched in the past year, and both explicitly reference family-relevant data handling rather than AI privacy in the abstract. The FTC’s September 2025 6(b) inquiry and a 42-state attorneys general subpoena of OpenAI in June 2026 both name health data specifically.

1
FTC 6(b) orders, September 11, 2025. The Federal Trade Commission ordered seven companies operating consumer AI chatbots, including OpenAI, Meta, and Alphabet, to disclose their data-collection and safety practices, with specific reference to how they inform minor users and their guardians or parents.
2
42-state attorneys general subpoena of OpenAI, June 12, 2026. A coalition led by New York Attorney General Letitia James subpoenaed OpenAI over data handling practices, with the document demand explicitly naming consumer and health data alongside the treatment of minors and seniors, corroborated by MLQ News.

Neither action has produced a public finding as of this writing, and neither should be read as evidence of wrongdoing on its own. What they show is that regulators, not just pollsters, now consider family-relevant health data handling by consumer AI companies an open question worth formally investigating. That’s a different kind of signal than a survey number, and it’s one families weighing whether to use these tools should know is actively unfolding, not settled.

What older adults are actually doing with AI right now

AI adoption among older adults nearly doubled in a single year. AARP’s 2026 Tech Trends survey (3,838 adults, fielded September-October 2025, published April 7, 2026) found AI usage among adults 50 and older rose from 18% in 2024 to 30% in 2025, with privacy concerns cited as the top barrier for those who haven’t adopted it. Combined with the Pew figure above, the picture is that older adults are already using these tools, at a fast-growing rate, even though they’re the age group least likely to be asking AI health questions directly and the group least represented in the polling on this specific topic.

That combination matters for a family caregiving context. It means an aging parent may already be experimenting with an AI tool on their own, independent of any decision an adult child makes about sharing records with one. The safety question this article is answering isn’t hypothetical for a future decision; for a meaningful share of families, it’s already in progress.

The questions nobody has publicly answered yet

Three specific questions, the ones that would most directly answer “is this safe for my family,” don’t have a public, tier 1-3 answer as of this writing.

1
Do people feel differently sharing a parent's data than their own? No major pollster has run this comparison. It's plausible people are more cautious with a parent's or dependent's data than their own, or the reverse; the honest answer is that nobody has asked yet.
2
Which types of health information would people share, and which would they withhold? KFF and Pew report general willingness to use AI for health information, not a breakdown by information sensitivity, such as a medication list versus a mental health note versus a genetic result.
3
Who, within a family, actually does the typing? AARP's data shows older adults are adopting AI fast, but no survey has asked whether it's the parent, an adult child, or another family member entering health information on a shared or family member's behalf.

That absence isn’t a reason to distrust the data that does exist; it’s a reason to treat this as a decision each family currently has to make on its own judgment, not one a national average can settle for them.

A risk framework for families, until the data catches up

Given what the evidence does and doesn’t cover, a family can still make a reasoned decision by treating the open questions above as things to decide deliberately, rather than default into.

1
Separate vendor risk from input risk. Ask both what happens if the company behind the tool is breached (the Xsolis scenario) and what happens to what you type in directly. A strong answer to one isn't a strong answer to both.
2
Decide together, not unilaterally. Since no research shows whether a parent and their adult child would answer the sharing question the same way, don't assume consent on someone else's behalf. Have the specific conversation.
3
Segment by sensitivity yourself. In the absence of published guidance on which record types are safer to share, apply your own judgment: a medication list carries different stakes than a mental health note or genetic result, and you don't need a survey to know that.
4
Assume the regulatory picture is still moving. With an active FTC inquiry and a 42-state subpoena underway, a company's current privacy policy could look different in a year. Recheck it periodically rather than deciding once and forgetting.
5
Ask if a parent is already using AI independently. Given AARP's adoption numbers, don't assume the family's AI decision starts from zero. Ask directly whether a parent has already started using a tool on their own.
DateEventSource
Sept. 11, 2025FTC issues 6(b) orders to 7 AI chatbot companies on data-collection and safety practicesFTC.gov
Oct. 20-26, 2025Pew Research fields its AI health-information survey (published April 2026)Pew Research Center
Jan. 20, 2026Phishing intrusion begins against Xsolis, a healthcare AI vendorHIPAA Journal
June 12, 202642 state attorneys general subpoena OpenAI over data handling, naming health data and seniorsTechCrunch
June 22, 2026Xsolis breach publicly disclosed via HHS OCR: 1,396,519 people affectedHHS OCR / HIPAA Journal

Where Kaizen Health fits

Kaizen Health was built around the family decision this article describes, not around a general-purpose product that happens to touch health topics. Sharing is something a family sets and can change at any time, record by record, rather than an all-or-nothing default. Kai, Kaizen’s AI assistant, summarizes the records a family chooses to upload on a HIPAA-compliant platform where personal health data is never used to train the underlying model.

How Kaizen handles this

Decide as a family which records to share, and with whom, before any AI tool touches them. Kaizen's sharing controls are set by your family and can be changed at any time.

Try it with a document

For the deeper walkthrough of what to check on any AI product, HIPAA status, training policy, and retention, before you connect it to a parent’s or child’s records, see our HIPAA, training, and retention checklist. For a feature-by-feature look at how the biggest 2026 products compare on those same questions, see Copilot Health, ChatGPT Health & Amazon Health AI, Compared. And if the records themselves aren’t organized yet, our guide to organizing medical records for aging parents is worth doing first. It makes every question in this article easier to answer, because you’ll actually know what you’re deciding whether to share.

Whoever ends up asking a parent these questions, and deciding what to share on the family’s behalf, is usually the same person already carrying the rest of that coordination. Our guide to the hidden retirement cost of family caregiving covers the part of that role that a privacy settings screen never shows.

Frequently Asked Questions

Not yet, as far as the major pollsters have published. KFF and Pew Research Center have both measured whether people use AI for health information and how worried they are about privacy in general, but neither has asked respondents to compare their comfort sharing their own health data with an AI tool against sharing a parent's or dependent's data. That specific family question is an open gap in the public polling record, not a settled "caregivers are fine with it" or "caregivers are worried about it" finding either way.

Kaizen Health Editorial Team
The Kaizen Health editorial team researches and writes family health content, with review from licensed clinicians before publication.

Get Kaizen Health free

Download the App