Opens in a new tab

AI is moving inside the medical record. Privacy is only part of the risk

OpenAI’s new Epic integration allows healthcare organisations to bring authorised patient context from the electronic health record into ChatGPT for Healthcare, with UCSF Health among the pilot partners.

September 17, 2026
Editorial
AI is moving closer to the clinical record itself, allowing authorised patient information to be analysed alongside medical evidence and institutional guidance.khunkornStudio / Shutterstock.com

IPM Take

The most consequential healthcare AI may not be the chatbot patients can see. It may be the system quietly sitting beside the clinician with access to the chart.

OpenAI’s new integration with Epic brings authorised patient information into ChatGPT for Healthcare, allowing clinicians to ask questions such as what has changed since the last visit, whether medications have been altered, which laboratory results deserve attention and what follow-up remains unresolved. The system can also point users back to the supporting information in the record.

That is a meaningful step beyond transcription.

It means generative AI is beginning to operate on the longitudinal data from which clinical decisions are made.

The upside is obvious. Medical records are enormous, fragmented and increasingly difficult for humans to synthesise quickly. But once AI begins determining what in that record is important enough to surface, information retrieval becomes a clinical act.

Privacy matters. So do the things that happen after access is granted: what the model overlooks, what it prioritises, whether clinicians over-trust the summary, and who is responsible when the output is wrong.

Executive Summary

OpenAI announced an integration between ChatGPT for Healthcare and Epic electronic health record environments. Healthcare organisations can use it to bring authorised patient context into ChatGPT or, in supported deployments, integrate ChatGPT directly within the EHR interface. UCSF Health is participating as a pilot partner.

The system is designed to synthesise information including appointment notes, laboratory results, medication changes and specialist documentation. OpenAI has also introduced a Healthcare Public Data plugin connecting nine official data sources, including PubMed, DailyMed, ClinicalTrials.gov and CMS Coverage.

OpenAI says ChatGPT for Healthcare includes role-based access controls, single sign-on, audit logs and Business Associate Agreements for applicable customers. It also states that content shared with ChatGPT for Healthcare is not used to train its models.

OpenAI reports that physicians evaluated the new EHR-connected capabilities across 27 clinical use cases and rated 99.1% of 4,363 responses as safe. That is useful product-evaluation evidence, but it is company-generated testing and should not be interpreted as proof of real-world clinical safety or patient benefit.

The broader regulatory context already imposes significant responsibilities. HIPAA requires covered entities and business associates to protect electronic protected health information through administrative, physical and technical safeguards. HHS guidance includes controls such as authentication, encryption and audit trails.

US health IT rules are also moving beyond privacy alone. The federal HTI-1 framework introduced transparency requirements for predictive algorithms embedded within certified health IT, intended to help clinical users assess fairness, appropriateness, validity, effectiveness and safety.

Why it matters

  • HTA bodies: AI embedded in the medical record will need to be assessed as more than software accuracy. Evaluation should consider whether summarisation or prioritisation improves clinical decisions, reduces workload, changes downstream testing and performs consistently across patient groups.
  • Payers: EHR-connected AI could reduce expensive administrative and clinical inefficiencies, but it may also influence referrals, diagnostic testing and treatment selection. Payers will need evidence that efficiency gains do not simply create additional downstream utilisation.
  • Industry / innovation partners: Access to longitudinal clinical data creates enormous opportunities for decision support and personalised care, but enterprise adoption will increasingly depend on permission architecture, auditability, interoperability and demonstrable real-world safety, not model capability alone.

The electronic health record was supposed to make patient information easier to use.

Instead, modern clinicians often face the opposite problem: too much information.

Years of laboratory tests, discharge summaries, medication changes, referrals, imaging reports and specialist notes can sit inside one record. The critical fact may be there, but finding it can require scrolling through pages of clinical history.

Generative AI offers an obvious solution.

Rather than asking the clinician to search the record manually, the system can search, organise and summarise it.

OpenAI’s Epic integration moves directly into that space. Clinicians can ask what changed since the previous visit, identify recent abnormal results or retrieve unresolved recommendations. The AI can then generate a synthesis while pointing back to the underlying chart information.

That could become one of the most practically useful applications of generative AI in medicine.

It could also become one of the most consequential.

The AI does not need to diagnose to influence care

Much of the debate around medical AI has focused on whether a model can diagnose disease correctly.

EHR-connected AI changes the question.

A system may never formally diagnose anything yet still influence a diagnosis by deciding which facts deserve the clinician’s attention.

Imagine a patient with years of fragmented cardiometabolic history. The AI may surface a rising HbA1c, a medication change and an unresolved cardiology referral while compressing dozens of other observations into the background.

That is useful because prioritisation is exactly what clinicians need.

But prioritisation is not neutral.

If an important finding is missing from the summary, clinically relevant context is misinterpreted or a medication timeline is reconstructed incorrectly, the error could enter the clinical decision before anyone realises information was omitted.

This is why benchmark performance alone is insufficient. OpenAI’s internal physician evaluations are encouraging, but they do not answer how clinicians will behave after relying on the system repeatedly, whether automation bias develops or whether performance changes across specialties, institutions and patient populations.

Privacy starts with access, but governance cannot end there

The privacy discussion also needs precision.

The new integration does not mean a public chatbot automatically receives unrestricted access to hospital records. OpenAI describes a governed enterprise environment in which organisations control access and authorised patient context is brought into the system according to existing permissions. Its healthcare product includes role-based controls, audit logs and the option of a Business Associate Agreement to support HIPAA-compliant use.

Those safeguards matter because health records contain some of the most sensitive information an organisation holds.

HIPAA already requires regulated entities to protect electronic PHI, and federal guidance emphasises access controls, encryption, audit trails and continuing security risk assessment.

But regulatory compliance answers only part of the question.

A system can be HIPAA-compliant and still perform poorly. It can be secure and still produce a misleading summary. It can correctly identify a risk and still create more work than it saves.

The real governance challenge is therefore wider than privacy.

Health systems will need to know who can activate AI against a patient record, which workflows it can influence, what evidence clinicians should verify, how errors are reported, whether performance is monitored after updates and where human review remains mandatory.

The Washington Post Intelligence analysis captures the broader shift: technology companies are moving beyond administrative automation toward AI systems capable of synthesising clinical notes, evidence and medical-record data, while hospitals see potential gains in both efficiency and individualised care. Privacy and safety advocates are asking whether evidence and safeguards are keeping pace.

That tension is likely to define the next phase of healthcare AI.

The breakthrough is no longer simply that AI can read the chart.

It is that AI can increasingly decide what in the chart the clinician sees first.

That makes medical-record integration potentially transformative.

It also makes governance part of the clinical intervention.

Source & Evidence