Technology
OpenAI Connects ChatGPT to Epic Health Records and Public Medical Data
Healthcare organizations can now connect authorized Epic patient context and nine official public-health sources to ChatGPT for Healthcare. The integration could reduce chart-review work, but it places access control, citations and clinical oversight at the center of deployment.
By Patrick T ·

OpenAI is connecting ChatGPT for Healthcare to Epic electronic health records and nine official medical-data sources, allowing authorized clinical teams to review patient context, medication information, trials and coverage data inside one governed workspace. The integration is designed to summarize what changed in a chart and point users back to supporting records. It moves ChatGPT closer to the systems where care is documented, which makes permissions and verification more important than conversational polish.
Healthcare organizations can bring Epic context into ChatGPT or embed ChatGPT inside a supported EHR workflow. A clinician might ask which laboratory results changed, whether medications were updated or which follow-ups remain unresolved. The system assembles relevant information from the authorized record and cites the chart. That can reduce the manual search required before an appointment, but the final interpretation still belongs to the clinical team.
The public-data plugin connects to sources including PubMed, ClinicalTrials.gov, DailyMed, RxNorm and CMS Coverage. Structured connectors matter because medical work often depends on identifiers, versions and eligibility criteria that a general web search can blur. A pharmacy team needs the current label for a specific drug. A research coordinator needs an actively recruiting trial and its exact inclusion rules. The product is useful only if it preserves those distinctions.
OpenAI says physicians across 60 countries, 49 languages and 26 specialties have reviewed more than 700,000 model responses used to improve health behavior. In an evaluation spanning 27 EHR use cases and 4,363 ratings, physicians judged 99.1% of responses safe. Separate tests on connected public datasets produced good-or-better accuracy ratings above 93% for each of five sources. Those are strong vendor-reported results, not a substitute for local validation.
The Integration Layer Carries the Clinical Risk
A model can summarize only the information it receives. If an interface omits an outside prescription, delays a laboratory result or maps the wrong patient context, fluent output can make the gap harder to notice. Deployments should show source timestamps, record scope and unresolved connector errors next to the answer. A citation is useful when it points to the exact chart element and version, not merely the system from which a summary was drawn.

Role-based access should follow the EHR, not create a parallel permission universe. A researcher may view de-identified cohort data without seeing an individual note. A pharmacist may need medications but not unrelated behavioral-health records. An administrator enabling the integration has to test how those boundaries survive prompts that combine sources. The model should not infer permission merely because a user can describe the information they want.
Audit logs also need clinical context. Recording that a user asked a question is insufficient if the system retrieved ten documents, summarized four and ignored a conflicting result. Investigators should be able to reconstruct which sources entered the answer and which model version processed them. That record supports quality improvement and incident response without turning every prompt into a permanent copy of sensitive data.
OpenAI offers enterprise controls including single sign-on, audit logs and role-based access, and says applicable customers can use the service in HIPAA-compliant workflows under a Business Associate Agreement. HIPAA compliance does not certify clinical accuracy. It governs how protected information is handled. Health systems still need a safety case for each use, including who reviews output and what happens when the assistant is unavailable or wrong.
Public Data Can Make Answers More Verifiable
The nine-source plugin may prove more important than the headline EHR connection. Public medical knowledge changes through new studies, label updates, trial status and coverage decisions. A model relying on static training cannot guarantee the current version. Querying official datasets at answer time creates a path to fresher information and lets users inspect the underlying record. It also shifts reliability to connectors that must handle schema and availability changes.

ClinicalTrials.gov illustrates the benefit and limitation. A system can identify recruiting trials and compare criteria faster than a manual search. It cannot know whether a particular patient is appropriate without a complete record and professional judgment. Eligibility text may be ambiguous, sites may update slowly and travel or insurance can determine whether enrollment is practical. The tool should narrow work, not present a database match as a recommendation.
Medication questions demand similar care. DailyMed and RxNorm provide authoritative labeling and normalized identifiers, but the relevant answer may depend on dose, kidney function, allergies and a clinician's plan. A summary that retrieves the right warning can still apply it incorrectly. Systems should distinguish record extraction, evidence retrieval and clinical inference so reviewers know where uncertainty entered the chain.
Hospitals should measure whether the integration saves time without increasing correction work. Pre-visit preparation is a reasonable starting point because a clinician reviews the output before seeing the patient. Automated handoffs or treatment decisions carry higher consequences. Metrics should include omitted facts, unsupported claims, citation accuracy, time saved and whether users become less likely to inspect the original chart after repeated correct answers.
The Product Will Be Judged Inside the Workflow
Health systems have accumulated many AI pilots that work in demonstrations and fail at deployment because they add another screen or do not match responsibility. Embedding ChatGPT in Epic reduces interface switching, but it can also make the assistant feel like part of the medical record. Visual design should make generated content unmistakable and preserve a direct route to sources. Convenience must not erase provenance.
UCSF Health and AdventHealth are among the organizations quoted as exploring the capabilities. Their frontline evaluation will matter more than a generic productivity estimate. Different specialties use records differently, and local documentation practices shape what an assistant sees. A useful rollout should begin with narrow teams, compare performance across populations and allow clinicians to report failures without converting the feedback process into extra clerical work.
Patient correction rights also matter. Medical records contain mistakes, duplicate entries and outdated histories. If ChatGPT repeatedly summarizes an incorrect diagnosis, the model can amplify an error that was previously buried in one note. The interface should help clinicians identify the source and follow the health system's correction process rather than allowing users to edit generated summaries that leave the underlying record unchanged.
Language access creates another opportunity and risk. A multilingual assistant may help teams review documents or explain information across languages, but translation can alter clinical meaning. Health systems should validate the languages common in their patient population and distinguish support for staff review from direct patient communication. A response that is safe in English cannot be assumed to remain safe after translation without evaluation.
Downtime procedures should be designed before adoption. If clinicians reorganize pre-visit work around an assistant, a connector outage can delay care even when the EHR remains available. The product should fail visibly, avoid presenting stale context as current and provide a route back to conventional chart review. Resilience is part of clinical safety because the most useful system will become the one teams notice when it disappears.
Economic evaluation should include where saved time goes. A ten-minute reduction in chart review may create more patient time, increase appointment volume or simply absorb administrative work elsewhere. Leaders should define the intended benefit and ask staff whether it occurred. Productivity claims are incomplete if the workflow becomes faster for one role by transferring verification and documentation to another.
The Epic integration is a significant distribution step because it places a frontier assistant beside the patient record rather than outside it. The value will come from fewer minutes spent assembling context and more attention available for care. The risk is that a coherent summary becomes more trusted than the messy record beneath it. OpenAI and its hospital customers will have to prove that every shortcut ends with evidence a clinician can still inspect.
Topics: OpenAI, ChatGPT for Healthcare, Epic, EHR, health data