Healthieo privacy policy
Last updated: August 25, 2026. This is a short public notice for a private test. It is not legal advice and it is not a HIPAA business associate agreement.
Who this is for
You. Connect only your own record. Each person must authorize their own health system.
What Healthieo does
- You create a Healthieo account.
- You sign in to MyChart / Epic and allow read-only access through SMART on FHIR.
- Healthieo stores encrypted access and refresh tokens so it can retrieve USCDI data you already authorized, such as medications, visits, labs, conditions, and allergies.
- A private Custom GPT can sign in to Healthieo and retrieve only the slice needed to answer your question.
Healthieo never asks for your MyChart username or password.
What we do not do
- Write back to your chart
- Sell health data
- Use health data for advertising
- Put this GPT in the GPT Store or Plugin Directory (it stays private for now)
Who else can see retrieved data
- Your health system (Epic / MyChart) sees the authorization you approve.
- OpenAI / ChatGPT receives the snippets Healthieo returns when you ask the Custom GPT a question. That is how GPT Actions work. OpenAI handles that data under its own terms and privacy policy.
- The Healthieo operator can see connection errors and account email. We do not log chart contents in public project notes.
How long tokens last
Epic access tokens last about one hour. Healthieo stores an encrypted refresh token and uses it to get a new access token without another MyChart login until you disconnect or the health system revokes access. ChatGPT’s Healthieo login token lasts about one hour.
Your choices
In Healthieo you can disconnect a health system. You can stop using the GPT. You can ask the operator to delete your Healthieo account.