> Accessing "non-public" data through that is endictment on their infra security more than it is OpenAI
No, it is not. Medical/health information is pretty much the most sensitive and confidential information possible on a personal level. You do not let a system already known for unwanted intrusion near any such system. Unless, of course, you're a sociopathic reckless money-grubbing cowboy, which is a long-winded way of writing "CEO".
What you are arguing is essentially if people have weak locks, its their fault if they get broken into. Or if a bug doesn't taste bad, then it's their fault if it gets eaten by a bird. This thinking puts the blame on the victim, which is 100% the wrong place.
Yes, I agreed that the Australian Government should have better security, but in government that's actually pretty hard when people see a government contract as license to charge $200 for a hammer. See the Australian Bureau of Meteorology website upgrade for an example of that kind of debacle.