Companies

ChatGPT Health Connects to Epic, Read-Only by Design

OpenAI let healthcare organizations connect Epic records to ChatGPT for Healthcare. The link is read-only, and physicians rated 99.1% of responses safe.

Faruk TalmaçSeptember 3, 20263 min read6 views
ChatGPT Health Connects to Epic, Read-Only by Design

Picture the fifteen minutes before a follow-up appointment. Two years of a patient's history sits on the screen: visit notes, lab results, a medication list, reports from two different specialists. The answer is in there somewhere, and finding which tab it is in eats the fifteen minutes.

The integration OpenAI announced on September 1 aims at exactly those fifteen minutes. Healthcare organizations can now connect their Epic electronic health record environments to ChatGPT for Healthcare, so a clinician can ask about an authorized patient's record instead of hunting through it.

What it does, and what it refuses to do

The most consequential thing about this integration is a limitation rather than a feature. The connection is read-only. ChatGPT pulls data out of the record and writes nothing back, so no model output becomes part of the official chart unless a clinician puts it there.

Two workflows are supported. In the first, authorized patient data is pulled into ChatGPT to summarize a history, surface what changed since the last visit, or prepare for an appointment. In the second, ChatGPT is reachable from inside supported EHR workflows, so the clinician never leaves the chart.

A second capability shipped alongside it. The Healthcare Public Data plugin wires the workspace into nine official datasets, among them PubMed, DailyMed, CMS Coverage, ClinicalTrials.gov and RxNorm, which gives questions about trial eligibility or medication details a traceable source.

Look closely at the safety number

OpenAI had physicians evaluate responses across 27 clinical use cases and reports that 99.1% of 4,363 ratings were judged safe. UCSF Health is the featured pilot customer.

That number sounds excellent, and it deserves a second reading. 99.1% of 4,363 ratings leaves roughly 39 responses judged unsafe. In a system that drafts invoices, that ratio is close to perfect. In a system where the subject is a drug interaction, the same ratio means something entirely different. OpenAI says plainly that the tool is not suitable for diagnosis or treatment, and that HIPAA-compliant use requires a business associate agreement. The company also has pending litigation alleging harmful medical advice, which belongs in the same picture.

The design decision worth copying

Most organizations reading this do not run Epic and will not be deploying this next quarter. The transferable part is not the product, it is the architecture.

The riskiest deployments we see are the ones where the model is granted write access. When a generated paragraph lands directly in a record, an invoice or a ticket, accountability for a bad output gets blurry fast. Granting read access and leaving the write to a human preserves the audit trail and keeps the cost of a wrong answer near zero. That is a pattern you can apply to a claims system or a support desk, not just a hospital.

If you are planning something similar, the order matters. Classify the data and settle the notice and consent story first, decide where processing happens second, and choose the model last. Projects that run that sequence backwards usually stall in legal review at the pilot stage, whatever the benchmark scores said.

Sources: OpenAI, TechCrunch, Fierce Healthcare

Share This Article

Faruk Talmaç

Written by

Faruk Talmaç

Co-Founder & Editor

Co-founder of YZ Uzman, with 20+ years of experience in web design and software development.

More news

Want to put this technology to work in your business?

Let's talk