Industry story
OpenAI integrates ChatGPT Health with Epic EHR for clinicians
evals guardrails reliability security
OpenAI announced that ChatGPT Health will integrate with Epic's electronic health record (EHR) system, which holds data for over 325 million patients. Clinicians can now import patient records — including appointment notes, lab results, medications, and specialist documentation — and query them via ChatGPT. In some deployments, ChatGPT will be embedded directly within EHR workflows, enabling pre-visit reviews and clinical timeline generation without leaving a patient chart. The integration is read-only; the AI cannot write back to health records.
OpenAI is also launching a Healthcare Public Data plug-in that pulls from sources like ClinicalTrials.gov, PubMed, and RxNorm to help healthcare workers synthesize research and coverage data. The company reported that in a study of 4,300 physician responses across 27 clinical use cases, 99.1% were rated safe — though critics note that even a small error rate can cause serious harm. OpenAI simultaneously opened ChatGPT Work, Codex, and related tools to healthcare organizations with a Business Associate Agreement (a HIPAA-compliance contract), enabling broader compliant enterprise use. This comes amid active litigation: a Florida pastor sued OpenAI alleging a near-fatal ChatGPT recommendation, and a separate suit was filed in May by family members of a user who received harmful dosage advice.
Full analysis
OpenAI just wired ChatGPT into Epic, the record system that holds data for 325 million patients. Clinicians can now pull a patient's whole chart into ChatGPT and ask it questions, sometimes without leaving the chart. It's read-only, so the AI can't change anything in the record. And OpenAI is waving a 99.1% "safe" number while two lawsuits over near-fatal advice sit on its desk. That gap between the number and the litigation is the whole story for anyone building on this platform.
Here's what it means and how to think about it.
The Skeptic. 99.1% safe across 4,300 physician-reviewed answers is a marketing number wearing a lab coat. A doctor calling an output "safe" in a calm review session is not the same as a good outcome in a chaotic ER at 2 a.m. And OpenAI is claiming near-perfect safety while defending suits from a Florida pastor and a family who got bad dosage advice. Both things can't be fully true. The read-only framing is also thinner than it sounds. If a clinician acts on a hallucinated drug-interaction summary, the fact that ChatGPT can't write to the chart is cold comfort. Epic already runs deeper clinical tools from Abridge and Nuance with more trust.
The Safety Lens. A 0.9% unsafe rate is not a rounding error when the base is 325 million records. That's a population-scale harm surface, and OpenAI's own framing admits it and ships anyway. The compliance contract (the BAA, which just makes the tool HIPAA-legal to use) assigns zero clinical liability. When a flawed pre-visit summary nudges a doctor toward the wrong read, the harm is real and the blame is legally diffuse. Nobody's clearly on the hook. And nothing here is FDA-classified as a medical device, so it sits in a regulatory gap. The lawsuits already filed are the leading edge of what happens when this scales, not a set of isolated incidents.
The Enterprise Buyer. A chief information officer at a hospital doesn't buy on a demo. They buy after a 12-to-18-month security review, and the BAA is table stakes that gets you into the room, not across the finish line. The questions that stall the deal: who's liable when the summary is wrong, does the data stay walled off from OpenAI's other tenants, and does it pass the internal patient-safety committee. Epic's incumbents already cleared those gates. OpenAI hasn't. The realistic near-term buyer isn't the risk-averse academic medical center. It's the health system already spending on OpenAI for back-office work, extending a contract it already trusts.
The Compute Pragmatist. Clinical queries look nothing like consumer ChatGPT. One pre-visit review pulling a full patient history can run 50,000 to 100,000 tokens of context. Multiply that by every clinician at a large system and the cost per query dwarfs consumer use. HIPAA also forces dedicated, walled-off infrastructure. No sharing a server with the crowd. That isolation isn't free, and it means OpenAI is likely eating margin here to capture enterprise accounts. Whether this pencils out depends on whether they can price BAA-compliant, dedicated capacity without bleeding.
Where the thoughtful people split: the Safety Lens sees a harm surface that scales with every hospital that signs on, while the Enterprise Buyer sees a product that mostly won't ship at scale for a year because the security reviews haven't happened yet. Both are right, and that's the actual near-term picture. The dangerous version of this product and the widely-deployed version of this product are not the same product yet. The second tension: the Skeptic and Compute Pragmatist agree the 99.1% number is doing work it can't support, but for different reasons. One says the eval doesn't match reality; the other says the workloads that stress the system hardest (long, messy, polypharmacy charts) are exactly the ones the eval undersampled and the ones that cost the most to run.
What this actually hinges on: whether "read-only" holds as a real safety boundary or just a legal one. It's a real boundary against corrupting the record. It's no boundary at all against a clinician anchoring on a wrong summary. That's the crack the litigation is already prying open. If you're building anything adjacent to clinical AI, watch whether the FDA or a court decides a read-only summarizer that shapes clinical decisions is a medical device. That reclassification would reprice this entire category overnight.
Prediction: By the JPMorgan Healthcare Conference in January 2027, no large academic medical center (top-20 by NIH funding) will have publicly announced ChatGPT Health with Epic in general clinical production across its physician staff; the named deployments will be limited pilots, single departments, or health systems already under an OpenAI enterprise contract.
Confidence: Medium. Security-review cycles outrun the news cycle, and liability is unassigned.
Why: Health systems run 12-to-18-month IT security and patient-safety reviews before anything touches live clinical workflows, and this integration is barely a month old, so the calendar alone makes broad production adoption at a flagship academic center unlikely by January. The BAA clears the HIPAA paperwork but leaves clinical liability diffuse, which is exactly the objection a risk-averse academic medical center's safety committee raises first, and two active lawsuits over harmful advice give that committee written reasons to wait. The opposite outcome, a marquee academic center going live house-wide this fast, would require it to skip its own review process, and those centers are the least likely institutions to do that.
Revisit by 2027-01-31: We're right if the announced deployments are pilots, single departments, or pre-existing OpenAI enterprise customers. We're wrong if a top-20 NIH-funded academic medical center announces general clinical production use across its physician staff.
One more thing. If a court or the FDA moves first and calls this a regulated medical device, the security-review question becomes moot, because the product stops shipping in its current form entirely. That's the faster path to the same place.
Comments