Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Do not upload identifiable medical scans to a consumer chatbot, and do not treat Grok’s interpretation as a diagnosis. The warning follows a November 2024 episode in which Elon Musk encouraged X users to submit MRI scans, X-rays and other medical documents to Grok. Some users then posted the images and Grok’s responses publicly. Experts objected because the trend combined two serious risks: exposing highly sensitive health information and relying on a general-purpose AI system that had not been established as a clinically reliable diagnostic tool.

The reports documented incorrect or contradictory interpretations, but they did not establish a controlled accuracy rate, a confirmed data breach or a confirmed patient injury. The concern is broader: an occasional correct-looking answer does not make a chatbot a radiologist, a licensed clinician or an FDA-authorized diagnostic device.

What happened with Grok and medical scans?

Grok gained image-understanding capabilities in late October 2024. Musk subsequently encouraged people on X to submit medical documents, including MRI scans and X-rays, to test the system. Users asked Grok to interpret images and, in some cases, shared both the medical material and the chatbot’s response publicly.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Coverage published on November 20, 2024, described several reported errors. In one example, Grok reportedly identified a broken clavicle as a dislocated shoulder. Other reported tests involved a failure to recognize a “textbook” tuberculosis case and an implausible interpretation of a benign cyst. These were anecdotal demonstrations, not a peer-reviewed clinical trial or evidence that Grok caused a confirmed patient injury.

The central problem is not simply that AI can make mistakes. It is that users were combining an unvalidated medical use with a platform designed for social sharing and data processing.

Grok’s current documentation says it supports file uploads and image understanding on the web, iOS and Android, although features and availability can change. That technical capability should not be confused with clinical authorization or reliability.

Why medical scans are unusually sensitive

A scan can reveal far more than the visible body part. Files or accompanying reports may include:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • a patient’s name, date of birth, medical-record number or accession number;
  • hospital, clinic and imaging-facility details;
  • embedded metadata;
  • recognizable anatomy or a distinctive injury;
  • rare conditions that could identify someone even after labels are removed;
  • symptoms, medications, diagnoses and other clinical context.

Cropping an image, photographing a screen or blurring a name may remove some identifiers without making the material anonymous. A cropped image can also remove the very context needed for a safe interpretation. If the scan is posted on X, the exposure expands to include copying, screenshots, quote posts, search indexing, reposts and third-party archives.

Uploading another person’s scan creates an additional problem. A child’s, spouse’s or patient’s medical information should not be submitted without appropriate authorization.

Does HIPAA protect a scan uploaded to Grok?

Not automatically. HIPAA’s Privacy Rule applies primarily to specified covered entities—such as health plans, health-care clearinghouses and covered health-care providers—and their business associates in relevant circumstances. It is not a blanket privacy law covering every company that receives health information.

Doctor, hospital or patient portal: HIPAA may apply to the covered entity handling the information in its regulated role.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Consumer chatbot or social platform: Do not assume HIPAA protects a voluntary upload merely because the material is medical.

Public X post: Other users may copy or redistribute the image regardless of the privacy expectations the uploader had.

This does not mean consumer health information is outside all legal protections. The U.S. Department of Health and Human Services notes that the FTC Act can apply to companies handling consumer health information, particularly when privacy, retention, sharing or security practices are deceptive or unfair. That possibility does not make every upload illegal, nor does it give an uploader the same protections as a patient using a covered provider’s clinical system.

HIPAA, consumer-protection law, a platform’s privacy policy and medical-device regulation are separate questions. One does not automatically answer the others.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What X and xAI say about Grok data

The relevant controls differ depending on whether a person uses Grok inside X or through Grok’s website and mobile apps. Labels and availability can vary by country, account type, app version and future policy changes.

Grok on X

X says that public X data, as well as users’ interactions, inputs and results, may be shared with xAI for training and fine-tuning. X also expressly advises users not to share personal, sensitive or confidential information with Grok.

According to X’s current help documentation, the training-related control is located at:

Privacy & Safety → Data sharing and personalization → Grok & Third-party Collaborators → Data Sharing

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Users can delete Grok conversation history at:

Privacy & Safety → Data sharing and personalization → Grok → Delete Conversation History

X says deleted conversations are removed from its systems within 30 days, except where retention is required for security or legal reasons. Making an X account private prevents public posts from being used to train Grok and xAI’s underlying models or surfaced in response to queries, according to X. That does not undo copies already made by other people.

Official details are available in X’s Grok privacy and data-use guidance.

Grok on Grok.com and mobile apps

xAI’s consumer FAQ says content and interactions may be used to train models. The controls listed by xAI are:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Mobile app: Settings → Data Controls → Improve the model.
  • Grok.com: Settings → Data → Improve the Model.

xAI says Private Chat, where available, is not used for model training. It also says a limited number of authorized personnel may review conversations for purposes including improving performance, investigating security incidents or misuse, and complying with legal obligations. Private Chat should therefore not be treated as an invisible or risk-free channel.

xAI’s privacy policy says the company does not aim to collect sensitive personal information, including health information and biometric scans, and asks users not to provide it. That is an important warning and policy position—not a technical guarantee that an uploaded scan is never processed, retained, reviewed or handled in another permitted way.

See xAI’s consumer FAQ and consumer privacy policy for the applicable terms.

Why opting out does not make an upload safe

Turning off model-improvement or data-sharing controls can reduce some future training or personalization uses. It does not eliminate every risk. The image still has to be processed to generate a response, and policies may allow limited retention, security processing, legal retention or authorized review.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Opting out also cannot prevent:

  • public exposure if the image was posted on X;
  • screenshots, reposts or copies made by other users;
  • identifying information contained in the scan or report;
  • disclosure of another person’s health information;
  • an incorrect medical interpretation.

X’s documentation also says feedback submitted after opting out may still be used for training. Settings are useful safeguards, but they are not the same as never uploading the material in the first place, and they are not necessarily retroactive deletion instructions.

Can Grok diagnose an MRI, X-ray or CT scan?

Grok may describe visible features or generate a medical-sounding assessment. That is not equivalent to:

  • clinical validation for a defined medical use;
  • a radiologist’s interpretation;
  • a diagnosis by a licensed clinician;
  • an FDA-authorized medical device used within its specific intended purpose;
  • a clinical workflow with patient history, prior images, image-quality controls and human review.

Medical imaging is difficult because findings can be subtle, the important abnormality may be outside the selected image, and interpretation depends on modality-specific expertise. Diagnosis often requires symptoms, physical examination, laboratory results, prior studies and the full imaging series—not a screenshot supplied without context.

A wrong answer can create false reassurance and delay care. A false alarm can produce panic, unnecessary testing or inappropriate self-treatment. The responsible conclusion is not that Grok is always wrong; it is that an occasional correct answer cannot establish diagnostic reliability.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The FDA’s materials distinguish wellness-oriented software from products intended for medical treatment and emphasize the importance of a product’s intended use. A consumer chatbot should not be assumed to be an authorized diagnostic device simply because it can analyze an image.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

The four main harm pathways

1. Privacy and identity exposure

A scan may be linked to an X username, profile, location or public conversation. A rare diagnosis, distinctive anatomy or detailed report can identify a person even when the obvious label has been hidden. Public posting makes permanent redistribution difficult to control.

2. Training and human-review exposure

Depending on the product, settings and timing, inputs and outputs may be used for model improvement. Official materials also describe limited authorized review. The relevant question is not only whether data is “sold”; sharing, processing, review, retention and model improvement can all matter.

3. Medical-safety errors

Grok can miss a finding, mislabel anatomy or express uncertainty poorly. Users may change treatment, skip urgent care or seek unnecessary care based on an answer that has no accountable clinician behind it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

4. Social and discrimination risks

Publicly associated health information can affect relationships, employment, insurance decisions, reputation and exposure to harassment. A person may believe an interaction is private until it is posted, screenshotted or shared.

What to do instead

  • Ask the radiology department or treating clinician to explain the report.
  • Use the patient portal or the provider’s established clinical communication channel.
  • For a consequential decision, seek a qualified radiologist or specialist second opinion.
  • If using AI to translate medical language, consider sharing only a de-identified excerpt rather than an image or full record, and check the service’s current privacy terms first.
  • Use AI to prepare questions for a clinician—not to decide whether to seek emergency care or start, stop or change treatment.

For organizations, a medical-imaging AI should be evaluated separately from a consumer chatbot. Ask whether it is a regulated or authorized product for the specific intended use, whether a qualified clinician reviews the result, what validation supports the claim, how uploads are retained and whether contractual protections such as a business-associate agreement apply. An enterprise security or HIPAA-related claim does not automatically make a consumer account suitable for diagnosis.

If you already uploaded a medical scan

  1. Delete the conversation using the applicable X, Grok.com or mobile-app control.
  2. Remove public posts and replies containing the image or response.
  3. Check for copies in reposts, quote posts, media attachments and screenshots. You may not be able to remove third-party copies.
  4. Review privacy controls and disable relevant X data sharing or Grok model-improvement settings.
  5. Use the privacy-request channel for X or xAI to ask about access or deletion.
  6. Notify the affected person or institution if the scan belonged to someone else, where appropriate.
  7. Monitor for identity-abuse concerns if the upload contained names, dates of birth, medical numbers or other identifiers.
  8. Ask a clinician about any medical interpretation Grok provided, whether reassuring or alarming.

X currently says deleted conversation history is removed from its systems within 30 days, subject to security and legal exceptions. Deletion timelines and outcomes can differ by product and account, and deletion cannot undo copies made elsewhere.

For future uploads, the safest rule is simple: keep identifiable scans, pathology images, genetic results and full medical records inside an accountable health-care workflow.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.