AI and health

AI and your medical record: what it can do, what it cannot, and how to use it without putting your data at risk

AI assistants can explain a lab report, summarise a 200-page record and prepare your questions for the doctor. They cannot diagnose and do not deserve your data without rules. What works, what does not, what to ask before giving access, and what an AI that respects your record looks like.

by Published 9 min read

Many people have already run the experiment: photographed their lab report, uploaded it to a chatbot and asked "is it serious?". The answer came in two seconds, polite, apparently competent. And they wondered, rightly, two things: can I trust it? and where did that photo go?

This guide answers both. It explains what AI assistants can do well with your medical record, what they cannot and why, what happens to your data when you hand it to a model, what European law says, and how to recognise an app that uses AI in the service of your record rather than its own user count.

What an AI can do well with your record

Today's language models are remarkably good at three things a patient needs daily and the healthcare system has no time to provide:

Explain. What a test measures, what a term in the discharge letter means, why a medication is taken in the morning, what a "TI-RADS 3 thyroid nodule" is. Explained in your language, at your level, with infinite patience. For this, AI is already more available than any doctor.

Summarise and organise. Years of records, dozens of documents, reduced to a timeline: what happened, when, who said what. An AI that reads your whole record can produce in 10 seconds the list of every TSH result from the last five years, with values, something that would take you an hour.

Prepare. The questions for tomorrow's consultation, based on what changed since the last one. A one-page summary for the new doctor. The medication list in the order the pharmacist wants it. An explanation, for a child, of what grandfather's diabetes means.

All of these share one thing: the AI works on your existing data and produces understanding, not decisions. Here it is very good and safe to use.

What it cannot do and why

It cannot diagnose. Not because it is "still" weak, but because diagnosis requires examination, clinical context, further tests and responsibility. An AI sees a photo of a report; the doctor sees you. An AI that says "you have hypothyroidism" on the basis of a TSH of 5.2 is statistically wrong many times over and answers for none of it.

It does not know what is not in the record. If the over-the-counter medications, last week's symptoms or the fact that you had a cold at the blood draw are missing, the answer is built on an incomplete picture, with the same confidence in tone. The quality of the answer is the quality of the record. The guide on the digital medical record explains why completeness matters.

It can make things up. The phenomenon is called "hallucination": the model produces a plausible, confidently phrased, false statement. A dose that does not exist, a non-existent interaction, a wrong reference range. The rate falls with newer models and with an AI that reads your sources rather than its memory, but it is not zero. The rule: any number, dose or recommendation given by an AI is checked at the source (report, leaflet, doctor).

It does not know your values and your risks. The decision to start a treatment, have an invasive investigation or wait involves what you want, what you can, what risk you accept. An AI can lay out the options; the choice is yours with your doctor.

Where your data goes when you give it to an AI

This is the part few people read before pressing "send".

When you upload a photo or text to a general-purpose chatbot (free or on a personal subscription), as a rule:

  • the data is sent to the company's servers, often outside the EU;
  • it may be used to train future models, unless you have explicitly turned the option off (where it exists);
  • it is retained for some time (days, months) for "safety and improvement";
  • there is no access log you can see and no medical consent in the GDPR sense.

A lab report with your name on it is health data, a special category under Article 9 of the GDPR. It is not illegal to upload it somewhere; it is, most of the time, a poor decision if you do not know exactly where it ends up.

What an AI integrated into a serious medical record app changes:

  1. The data does not leave the record. The AI reads from your record, with your consent, through the same mechanism a doctor would use. You upload nothing anywhere.
  2. It does not train on you. Model providers used under professional terms (API, data processing agreements) do not retain or train on customer data; the app must say explicitly which provider it uses and under what contract.
  3. There is a log. Every AI read is recorded like any other access: what it read, when, for which question.
  4. There is provenance. The answer shows which document or which value each statement comes from, so you can check. What the AI produced stays marked as "AI", separate from what a doctor wrote.
  5. Hosting is in the EU or, at least, with GDPR safeguards, and you can see where.

What the law says

Three texts matter in the European Union:

GDPR. Health data requires an explicit legal basis and clear information. An AI processing medical data is processing like any other: you must know who, why, where, for how long. Solely automated decisions with significant effects on you (Article 22) require additional safeguards and the right to human intervention.

The AI Act (2024). AI systems used as medical devices (diagnosis, treatment) are "high-risk": they require conformity assessment, human oversight, documentation, transparency. An assistant that explains and organises without diagnosing does not fall into this category, but it must be transparent that it is an AI and must not claim to be what it is not.

EHDS (2025). Wellness and record apps that want to be interoperable with health systems register and follow the European format; AI that consumes record data should consume it through the same controlled channels as any other system, not through uncontrolled copies.

The practical translation: a serious medical AI presents itself as AI, does not diagnose, tells you where it takes the data from and where it sends it, and leaves the decision to a human.

How to use AI with your record, safely

A simple protocol, in five rules:

  1. Do not upload documents with identifying data to general-purpose chatbots. If you want to ask something general ("what is ferritin?"), ask without your report. If you want to ask about your values, use an AI that reads from the record with consent and a log, or anonymise (cut the name, ID number, date of birth) first.
  2. Ask for sources. "Where does this value come from?" or "which document says that?" A good AI shows you the document; a weak one gives you a round answer.
  3. Use it for questions, not final answers. The best outcome of a conversation with an AI is a list of good questions for your doctor, not a decision.
  4. Check the numbers. Doses, ranges, frequencies: against the leaflet, the report, the doctor. Always.
  5. Check the access. Every few months, look at the record's log: what the AI read, when. If the app has no log, you have your answer about how serious it is.

How to recognise an AI that respects your record

Questions to ask before giving it access:

  • Does it read from the record with explicit consent, by category, revocable?
  • Does it say which model provider it uses and whether the data is used for training? (The right answer: it is not.)
  • Does it mark what the AI produced separately from clinical data?
  • Does it show the sources of each statement from your record?
  • Does it refuse to diagnose and send you to a doctor when the question is clinical?
  • Does it have an access log visible to you?
  • Does it tell you where the data is processed (EU, another jurisdiction, with what safeguards)?

A "no" to any of the first three is a stop signal.

How Anpheros helps

The assistant in Anpheros Daily reads from your FHIR record through the same context API clinics and authorised apps use: with your consent, by category, with every read in the access log. You upload nothing anywhere; you ask, and the answer comes with its sources marked (which document, which value, which date). Everything the AI produces stays labelled as AI, separate from what a doctor or a laboratory wrote, and the data is not used to train models. The assistant explains, summarises and prepares questions; it does not diagnose and says explicitly when a question belongs with your doctor. For developers, the same mechanism is available as a context API, with a token budget and provenance labels, documented at developers.anpheros.com.

Frequently asked questions

Can I ask a chatbot to interpret my lab results?

You can ask it to explain what they measure and what the ranges mean; that is useful. Do not rely on it to interpret your values, because it does not know your context, can be confidently wrong and, in general-purpose chatbots, you do not even know where the data goes. Use it to understand and to prepare your questions for the doctor.

Is my data used to train the AI?

In consumer general-purpose chatbots, often yes, unless you turn the option off. In serious medical record apps, no: the model is used under professional contracts that prohibit training on customer data, and the app should say so explicitly. If it does not, ask.

Is medical AI regulated in the EU?

Yes. The AI Act classifies systems used for diagnosis or treatment as high-risk, with strict requirements. Assistants that explain and organise without diagnosing have transparency obligations. The GDPR applies in full to health data, AI or not.

Is it safe to let an AI read my whole record?

It is as safe as the mechanism through which it reads. If access is by consent per category, logged, revocable, hosted in the EU and without training, the risk is comparable to a doctor's access. If "reading" means you upload PDFs to a foreign service, it is not.

Can AI tell me whether two medications interact?

It can flag known interactions and help you understand them, based on your complete list. It does not replace the check by a doctor or pharmacist, who know the dose, kidney function and the rest of the context. The guide on the medication list explains why the complete list matters more than the tool.

This guide is for information and does not replace medical advice. For decisions about your health, talk to your doctor. In an emergency, call 112.
About the author
Adrian Kereky

Founder of Anpheros. An electronics engineer, he spent six years in the automotive industry on hardware design and compute architectures for driver assistance before building Anpheros: the patient-controlled medical record and the HL7 FHIR R4 platform it runs on.

More about Anpheros and the author →

Keep your medical record with you

Anpheros Daily keeps symptoms, lab results, medications and documents in one place, in a standard format, under your control. The Basic plan is free.

Get Anpheros Daily