OpenAI puts ChatGPT inside Epic patient charts, read-only

Share
OpenAI puts ChatGPT inside Epic patient charts, read-only

Two moves this afternoon define where AI is actually being trusted: OpenAI wired ChatGPT straight into the electronic health record that most US hospitals run on, and the EU finalised a rulebook that treats a chatbot as infrastructure subject to public-safety law. Different rooms, same question — who carries the risk when the model misreads the record.

OpenAI says ChatGPT for Healthcare can now read Epic patient records, and the ceiling matters more than the feature. Healthcare organizations can connect Epic environments to ChatGPT so clinicians can pull appointment notes, lab results, medications, and specialist documentation into one view, then ask what changed since the last visit or which results need review before today's appointment. In some deployments the assistant sits inside the chart layout itself, so the clinician never leaves the record. Crucially, OpenAI says the integration is read-only: the AI does not write anything back. A companion Healthcare Public Data plugin reaches nine official sources including ClinicalTrials.gov, CMS Coverage, RxNorm, DailyMed, and PubMed, so teams can check trial eligibility, drug labels, and coverage policy versions without opening nine tabs. Launch partners named by OpenAI include AdventHealth, Baylor Scott & White Health, Boston Children's Hospital, Cedars-Sinai, and HCA Healthcare, and UCSF Health is piloting the integration — its CEO framed the pitch as giving clinicians time back rather than replacing judgment.

The safety number OpenAI is leading with is strong, and that is exactly why it deserves scrutiny. The company says it collected 4,363 physician ratings across 27 clinical use cases — pre-visit review, clinical timelines, medication review, handoff summaries — and 99.1% of responses were rated safe. Read the other way: roughly 0.9% were not, and at clinical volume that is not a rounding error, it is a queue. A separate two-round evaluation put more than 93% of responses at "good" or better accuracy on each of five connected data sources. The timing is uncomfortable for OpenAI regardless of the numbers: ChatGPT Health only reached all US consumers in July, and a lawsuit covered that month alleges the product gave a near-fatal dosage recommendation. Read-only is the right architecture for this — a summariser that cannot alter the chart has a bounded blast radius — but the failure mode that matters is a clinician acting on a confident, wrong summary, and no permission model fixes that.

Brussels has finished what it started on August 31: ChatGPT is now a "very large" platform, and the Commission got there by calling it a search engine. The designation covers services with more than 45 million monthly EU users; Reddit (more than 57 million) and Roblox (46.6 million players) were named alongside it, and all three have four months to comply with the Digital Services Act's extra obligations. ChatGPT reported more than 159 million EU users at the end of March. The duties go past content moderation into systemic risk: assessing and mitigating harms from the service and its algorithmic systems across illegal content, minors, users' physical and mental well-being, fundamental rights, electoral processes, and public security. Penalties run to 6% of global annual turnover, with a possible EU operating ban for serious repeat violations — X was fined €120 million earlier, and TikTok has been told to change its design or pay. The interface think-tank Interface put the stakes plainly: OpenAI already carries risk-management duties under the AI Act, and the DSA widens the scope.

The connective tissue is accountability placement. OpenAI is building clinical products whose whole design premise is that the human stays in the loop; the EU has decided the user count alone is enough to make the deployment itself a regulated object. Neither is a ban, and neither is a rubber stamp — both are bets that an AI system can be made safe by constraining where it sits. That bet is now load-bearing in hospitals and in law.

If 99.1% of responses are safe, is that good enough to sit inside a patient chart — or should read-only be the floor, not the design? Tell us in the comments.

Sources: OpenAI — Healthcare organizations can now connect EHR and additional industry data to ChatGPT · TechCrunch · The Straits Times · Euractiv · OpenAI — Introducing ChatGPT Health