- The people most likely to say they get health information from AI chatbots are the youngest adults, not the parents or grandparents whose records families are often the ones deciding whether to share: 32% of adults 18-29 do, versus 16% of those 50-64 and 10% of those 65+ (Pew Research Center, April 2026).
- The one confirmed, publicly disclosed incident involving a healthcare AI vendor in 2026 is the Xsolis breach: 1,396,519 people's records exposed after a phishing attack, disclosed via HHS OCR in June 2026. It was a breach of vendor infrastructure, not a case of a chatbot mishandling what someone typed into it.
- Two federal and state regulatory actions launched in the past year, an FTC 6(b) inquiry (September 2025) and a 42-state attorneys general subpoena of OpenAI (June 2026), both explicitly name health data and how companies treat minors and seniors. Neither has concluded, but both signal regulators see this as unsettled.
- AI use among adults 50+ nearly doubled in a year, from 18% in 2024 to 30% in 2025, with privacy concerns cited as the top adoption barrier (AARP Tech Trends, April 2026). Older adults aren't sitting this out; they're already deciding, often without family-specific guidance.
- No major pollster has yet asked the questions that actually determine a family's risk: whether people feel differently sharing a parent's data than their own, which types of health information they'd share versus withhold, or who in the family is actually the one typing it in. That's a real gap in the evidence, not a settled answer either way, and it's the reason a framework matters more than a single stat here.
Search “is it safe to share medical records with AI” and most answers you’ll find borrow the same handful of statistics: how many adults use AI chatbots for health questions, how worried people say they are about privacy in general. Those numbers are real, and our guide to AI agents in family health and AI agent vs. chatbot breakdown already cover them, along with the HIPAA, training, and retention checklist every family should run before connecting any tool to a parent’s or child’s records. What none of that polling actually asks is the family-specific version of the question: do people feel differently sharing a parent’s data than their own? Which kinds of health information would they share, and which would they hold back? Who, in practice, is the one doing the typing?
This piece is built around what the evidence on record actually supports, including where it runs out. That gap, paired with the one confirmed 2026 incident involving a healthcare AI vendor and two live regulatory actions, is itself the honest, sourced answer to “is this safe” right now: safer than the general headlines suggest in some ways, less settled than a confident yes or no in others.
What the polling actually asks, and what it leaves out
A Pew Research Center report published April 7, 2026 (surveying 5,111 U.S. adults, fielded October 20-26, 2025) found a clear age gradient in who turns to AI chatbots for health information at least sometimes: 32% of adults 18-29, compared with 16% of adults 50-64 and just 10% of adults 65 and older. That’s a meaningfully different picture than a single topline number suggests. The people asking AI chatbots health questions directly skew young, while the parents and grandparents whose records a family often has to decide whether to share skew toward the group least likely to be the one asking.
Separately, KFF’s March 2026 tracking poll found 32% of adults had turned to AI for health information in the past year, and among those who had entered personal medical information into an AI tool, 65% said they were concerned about its privacy. Both figures are useful, and both stop short of the question this article’s title actually asks. Neither KFF nor Pew has published data comparing how someone feels about sharing their own health information with AI versus sharing a parent’s or a dependent’s, and neither has broken down willingness to share by the type of information involved, a medication list versus a mental health note versus a genetic test result. Those are real, specific gaps in the public record, not numbers this article is choosing to omit.
The one confirmed incident on record
Rather than a general warning, here is a specific, documented case. Xsolis, a healthcare AI vendor whose clinical-decision tools are used by hospital systems including Mayo Clinic, Legacy Health, Rochester Regional Health, and UW Medicine, suffered a phishing-based breach beginning January 20, 2026. According to HIPAA Journal’s reporting and TechTarget’s coverage, the breach exposed names, Social Security numbers, dates of birth, insurance information, and medical treatment records belonging to 1,396,519 people. It was publicly disclosed through the HHS Office for Civil Rights breach portal on June 22, 2026, five months after the intrusion began. Becker’s Hospital Review counted eight health systems affected in total.
The distinction worth holding onto is what kind of risk this was. Xsolis is infrastructure hospitals use behind the scenes for clinical decision support, not a consumer chatbot a family types questions into directly. The breach happened because someone clicked a phishing link inside the vendor’s systems, the same way breaches have happened at healthcare vendors for years before AI was part of the story. It is not evidence that an AI tool misread, leaked, or misused what a person typed into it in the moment. Both are real categories of risk. They are not the same risk, and a family evaluating any AI health tool should ask about both separately: what happens to data behind the scenes, and what happens to what you type in directly.
Regulators are asking the family question, even if pollsters aren’t
Two active actions launched in the past year, and both explicitly reference family-relevant data handling rather than AI privacy in the abstract. The FTC’s September 2025 6(b) inquiry and a 42-state attorneys general subpoena of OpenAI in June 2026 both name health data specifically.
Neither action has produced a public finding as of this writing, and neither should be read as evidence of wrongdoing on its own. What they show is that regulators, not just pollsters, now consider family-relevant health data handling by consumer AI companies an open question worth formally investigating. That’s a different kind of signal than a survey number, and it’s one families weighing whether to use these tools should know is actively unfolding, not settled.
What older adults are actually doing with AI right now
AI adoption among older adults nearly doubled in a single year. AARP’s 2026 Tech Trends survey (3,838 adults, fielded September-October 2025, published April 7, 2026) found AI usage among adults 50 and older rose from 18% in 2024 to 30% in 2025, with privacy concerns cited as the top barrier for those who haven’t adopted it. Combined with the Pew figure above, the picture is that older adults are already using these tools, at a fast-growing rate, even though they’re the age group least likely to be asking AI health questions directly and the group least represented in the polling on this specific topic.
That combination matters for a family caregiving context. It means an aging parent may already be experimenting with an AI tool on their own, independent of any decision an adult child makes about sharing records with one. The safety question this article is answering isn’t hypothetical for a future decision; for a meaningful share of families, it’s already in progress.
The questions nobody has publicly answered yet
Three specific questions, the ones that would most directly answer “is this safe for my family,” don’t have a public, tier 1-3 answer as of this writing.
That absence isn’t a reason to distrust the data that does exist; it’s a reason to treat this as a decision each family currently has to make on its own judgment, not one a national average can settle for them.
A risk framework for families, until the data catches up
Given what the evidence does and doesn’t cover, a family can still make a reasoned decision by treating the open questions above as things to decide deliberately, rather than default into.
| Date | Event | Source |
|---|---|---|
| Sept. 11, 2025 | FTC issues 6(b) orders to 7 AI chatbot companies on data-collection and safety practices | FTC.gov |
| Oct. 20-26, 2025 | Pew Research fields its AI health-information survey (published April 2026) | Pew Research Center |
| Jan. 20, 2026 | Phishing intrusion begins against Xsolis, a healthcare AI vendor | HIPAA Journal |
| June 12, 2026 | 42 state attorneys general subpoena OpenAI over data handling, naming health data and seniors | TechCrunch |
| June 22, 2026 | Xsolis breach publicly disclosed via HHS OCR: 1,396,519 people affected | HHS OCR / HIPAA Journal |
Where Kaizen Health fits
Kaizen Health was built around the family decision this article describes, not around a general-purpose product that happens to touch health topics. Sharing is something a family sets and can change at any time, record by record, rather than an all-or-nothing default. Kai, Kaizen’s AI assistant, summarizes the records a family chooses to upload on a HIPAA-compliant platform where personal health data is never used to train the underlying model.
Decide as a family which records to share, and with whom, before any AI tool touches them. Kaizen's sharing controls are set by your family and can be changed at any time.
Try it with a documentFor the deeper walkthrough of what to check on any AI product, HIPAA status, training policy, and retention, before you connect it to a parent’s or child’s records, see our HIPAA, training, and retention checklist. For a feature-by-feature look at how the biggest 2026 products compare on those same questions, see Copilot Health, ChatGPT Health & Amazon Health AI, Compared. And if the records themselves aren’t organized yet, our guide to organizing medical records for aging parents is worth doing first. It makes every question in this article easier to answer, because you’ll actually know what you’re deciding whether to share.
Whoever ends up asking a parent these questions, and deciding what to share on the family’s behalf, is usually the same person already carrying the rest of that coordination. Our guide to the hidden retirement cost of family caregiving covers the part of that role that a privacy settings screen never shows.
Frequently Asked Questions
Not yet, as far as the major pollsters have published. KFF and Pew Research Center have both measured whether people use AI for health information and how worried they are about privacy in general, but neither has asked respondents to compare their comfort sharing their own health data with an AI tool against sharing a parent's or dependent's data. That specific family question is an open gap in the public polling record, not a settled "caregivers are fine with it" or "caregivers are worried about it" finding either way.
