HIPAA only applies to data originating from a covered entity.
It doesn't apply to information the patient supplies directly.
As a patient, I can take out a street sign displaying my health records if I want. It's my data.
If I want to upload it to a strange AI or any other app, that's completely fine. HIPAA isn't involved, for either me or the company I upload to.
In fact, quite the opposite. CMS has been going to great pains over the past decade or so to create standards to help patients get access to their records and own them themselves.
Different states may have additional protections in this case, and I know there has been some discussion at the federal level about regulating these "wellness" apps.
As an interesting technical detail not many people know, HIPAA only applies to Covered Entities and Business Associates engaging in the electronic exchange of information using "standard transactions", and was intended to regulate insurance and billing transactions.
A doctor that keeps paper charts and bills cash directly to the patient wouldn't fall under HIPAA at all.
It’s a pretty fine line, and if they want to do anything beyond just telling you things about your data, actually taking any sort of actions or communications with health care providers, they should qualify as a business associate under HIPAA. And I certainly am never going to share my healthcare data with an AI company without any sort of regulations or oversight, beyond a TOS.