What a lab report reveals about you
A typical lab report combines two kinds of data. The first is identifying information: your name, date of birth, sex, address, patient or medical record number, the lab's accession number or barcode, the ordering clinician and collection dates. The second is clinical content — dozens of values that can hint at conditions, medications, pregnancy or lifestyle. Free-text comments and diagnosis codes on some reports can be more revealing than the numbers themselves.
When a US health care provider, health plan or their business associate holds that information, it is protected health information (PHI) under HIPAA. Once you download it and share it yourself, it is just as sensitive, but the legal protections now depend on who receives it.
Removing your name is not always enough. A rare result, the name of a small local lab and an exact collection date can together narrow a report down to one person, which is why de-identification standards treat dates and locations as identifiers too. Terms such as PHI and de-identification are defined in our glossary.
- Name, date of birth and sex
- Patient ID, medical record, accession or barcode numbers
- Address, phone number and email
- Ordering clinician, clinic and insurance details
- Free-text comments and diagnosis codes
How to redact a lab report before uploading
Redaction means permanently removing identifying details, not just covering them. A black box drawn over text in many PDF viewers leaves the underlying text selectable — and text extraction, which is how AI tools read PDFs, will still see it.
HIPAA's “safe harbor” de-identification standard lists 18 identifier types, including all elements of dates except the year, which is a useful benchmark for what to remove. Our guide to preparing a lab report for AI analysis shows how to do this without losing the ranges and units an AI tool needs.
- Save an untouched copy of the original PDF for your own records.
- Use a PDF tool with a true redaction feature that deletes the text underneath, or export pages as images and crop out the header.
- Remove names, dates of birth, record and accession numbers, barcodes, contact details, insurance details and clinician names.
- Keep test names, values, units, reference ranges, H/L flags and the collection month and year.
- Search the redacted file for your surname; if it is found, the redaction failed.
- Clear the document properties, which can store names or patient IDs, or print to a fresh PDF.
What happens to a file after you upload it
Uploading feels like a single action, but behind it are several steps. A service typically stores the original file, extracts its text, sends that text to a model for processing, and then saves the resulting conversation or report. Each step can run on different systems, and some may be operated by subcontractors — often called sub-processors — such as cloud hosting providers.
That is why a privacy policy should say where data is stored, which sub-processors handle it and whether files are kept after the analysis is complete. A dedicated analyzer that produces one report and a general chatbot that keeps an open-ended conversation history can handle the same upload very differently, so read each policy on its own terms.
Data retention and model-training settings
Two settings matter more than any marketing claim: how long a tool keeps your uploads and conversations, and whether that content can be used to train or improve its models. General-purpose chatbots typically save chat history by default and offer controls to turn history off or exclude conversations from training. Defaults, names and locations of those controls change over time, so check them before each sensitive upload rather than relying on memory.
A good privacy policy states a specific retention period, explains whether deleted content is erased or kept for a while for safety and abuse monitoring, and says whether human reviewers can see what you upload. Dedicated health tools should explain the same things in plain language. If a policy is vague about retention or training, treat the vagueness as the answer.
Temporary chats are not zero retention
Many assistants offer a temporary or incognito mode that is not saved to your history. That reduces exposure, but providers may still keep content briefly for safety review. Read the description of the specific mode before relying on it.
Does HIPAA protect what you upload?
Often, no. The HIPAA Privacy Rule applies to covered entities — health plans, health care clearinghouses and health care providers that conduct certain electronic transactions — and to business associates working on their behalf. A consumer AI app you sign up for yourself is usually none of these, so HIPAA generally does not reach the copy of your results you choose to give it.
That changes when a tool is provided through your hospital, clinic or insurer under a business associate agreement; then the vendor has HIPAA obligations for the data it handles for that organization. When a website says “HIPAA-compliant,” ask what that means for you as an individual user: it may describe enterprise contracts, not the free consumer version you are using.
Some US states have started to fill the gap. Washington's My Health My Data Act, for example, requires many companies to get consent before collecting or sharing consumer health data and gives residents a right to have it deleted. Protections still vary widely by state.
GDPR: health data is special-category data
In the EU, Article 9 of the GDPR classifies data concerning health as a special category of personal data. Processing it is prohibited unless a specific condition applies — for consumer apps, usually your explicit consent. The UK GDPR contains an equivalent rule, and GDPR can apply to a company based outside Europe when it offers its service to people in the EU.
In practice, this gives EU and UK users rights worth using: access to a copy of your data, erasure, withdrawal of consent and information about who receives it. A service aimed at European users should name its legal basis for processing health data and explain how to exercise these rights.
The FTC Health Breach Notification Rule
In the US, many health apps outside HIPAA are still subject to the FTC Health Breach Notification Rule. It requires vendors of personal health records and related entities to notify affected users, the FTC and in some cases the media after a breach of unsecured health information. The FTC updated the rule in 2024 to make clear that it covers health apps and that a breach includes unauthorized disclosure — such as sharing data without permission — not only hacking.
The rule is about notification, not prevention. It tells you when something has gone wrong, but it does not limit what a company may collect in the first place. Your strongest protection is still uploading less.
Deleting your account and uploads
Before you upload, find out how to leave. A trustworthy tool lets you delete individual reports and your whole account, either in the app or through a documented request, and says how long backups persist afterward. EU and UK users can request erasure under GDPR, and several US states, including California, give residents deletion rights under state privacy laws.
Keep a short note of every tool you have uploaded results to, and when. It makes cleanup simple if you change your mind, close an account or a service changes its terms.
Questions to ask any AI tool before uploading
Run through this list for any service — general chatbot or dedicated analyzer — before your first upload:
The same questions apply to every platform in our rankings, from general models such as ChatGPT and Gemini to Kantesti, our #1-ranked dedicated analyzer: check each one's current policy yourself rather than relying on summaries. Privacy also appears in our buyer's checklist for AI blood test analyzers, and our methodology explains how transparency factors into each platform's score.
- Who operates the service, and in which country is my data stored?
- How long are uploads and chat history kept, and can I change that?
- Is my content used to train or improve models, and can I opt out?
- Can staff or contractors view my uploads, and when?
- Is data encrypted in transit and at rest?
- Is data shared with or sold to advertisers, data brokers or other third parties?
- Does HIPAA apply to my use, or GDPR where I live?
- How do I delete one report, and my entire account?
- Does the tool state clearly that it is informational and not a substitute for a clinician?
Frequently asked questions
Does HIPAA apply when I upload my lab results to a chatbot?
Usually not. HIPAA covers health plans, clearinghouses, health care providers that conduct certain electronic transactions, and their business associates. A consumer chatbot you use on your own is generally none of these. A version provided through your hospital or clinic under a business associate agreement may be covered.
What should I remove from a blood test before uploading it to AI?
Remove your name, date of birth, address, phone, email, patient and record numbers, accession numbers and barcodes, insurance details and clinician names. Keep test names, values, units, reference ranges and flags, which the AI needs to interpret results accurately.
Can AI companies use my blood test to train their models?
Some can, depending on the provider and your settings. Check the privacy policy and account controls for a model-training opt-out before uploading, and favor tools that state clearly whether user content is used for training.
Is health data protected under GDPR?
Yes. GDPR Article 9 classifies data concerning health as special-category data, which may only be processed under specific conditions such as explicit consent. The UK GDPR has an equivalent provision.
Is a screenshot safer than a PDF?
Not necessarily. Cropping a screenshot can remove header details, but images are easier for AI to misread, and photos taken with a phone camera can carry location metadata. A properly redacted, text-based PDF is usually the better balance of privacy and accuracy — see why AI chatbots misread lab results.
Sources
- U.S. HHS — HIPAA for Professionals and Individuals — Official HHS hub for HIPAA rules and who they apply to.
- U.S. HHS — The HIPAA Privacy Rule — Explains covered entities, business associates and protected health information.
- GDPR Article 9 — Processing of special categories of personal data — Full text of the EU rule that classifies data concerning health as special-category data.
- FTC — Health Breach Notification Rule — U.S. rule requiring many health apps outside HIPAA to notify users after a breach of health data.
- WHO — Ethics and governance of artificial intelligence for health (2021) — World Health Organization guidance on safety, transparency, privacy and accountability for AI in health.
Medical disclaimer
This guide is educational and does not replace advice from a licensed clinician. If you have urgent symptoms, contact your local emergency number.