ChatGPT For Healthcare Adds Patient-Record Access

OpenAI's read-only Epic integration lets approved healthcare workspaces summarize authorized patient records while Epic permissions and clinicians stay in control.

TL;DR
  • Epic Records: Approved healthcare workspaces can connect ChatGPT to Epic patient records for preparation after organizational setup, with clinicians limited by existing chart permissions.
  • Read-Only Workflow: ChatGPT can summarize authorized records in its own chats or supported patient-chart layouts, but cannot update charts, place orders, or message patients.
  • Separate Public Data: A second plugin searches nine official sources without patient-record access and has different eligibility from the Epic integration.

OpenAI has added a read-only Epic electronic health record integration for approved ChatGPT for Healthcare and HIPAA-enabled ChatGPT Enterprise workspaces, letting clinicians summarize chart information for visit preparation without changing the patient record. Access depends on organizational configuration, each clinician’s Epic sign-in, and the chart permissions that person already has.

Epic Systems Corporation is the leading electronic health record (EHR) software company in the US healthcare industry.

The September 1 release supports two experiences. A clinician can bring authorized Epic context into ChatGPT to review a history or prepare for an appointment. In supported deployments, an organization can also place ChatGPT inside the EHR layout so the clinician can use it without leaving the chart. Both experiences sit above Epic’s existing access controls; neither turns ChatGPT into a new source of patient records or an autonomous clinical system.

The integration can reduce the work of finding and assembling relevant chart details, but an organization must first establish a regulated connection and clinicians remain responsible for checking the record and making care decisions.

Deployment Starts With the Organization

The Epic connection is not a feature that any clinician can switch on in a personal account. OpenAI says it is available to approved ChatGPT for Healthcare workspaces and eligible ChatGPT Enterprise customers using a Regulated Workspace configuration, which restricts the enterprise features that can handle protected health information. An applicable Business Associate Agreement (BAA), defines OpenAI’s obligations for covered services.

Administrators on both sides create the connection. The healthcare organization registers or approves an Epic OAuth application, supplies its FHIR R4 base URL and OAuth credentials, reviews the permitted data scopes, and publishes a workspace-specific EHR app. FHIR is the standard interface through which the app requests defined health-record resources; OAuth handles the user’s authorization to that connection. The workspace administrator then makes the Epic plugin available to the appropriate roles.

Administrative installation does not connect a clinician’s Epic account. Each user must sign in through the organization’s Epic authorization flow. The Epic plugin uses that person’s existing chart permissions, so it cannot reveal a record the same clinician could not already open in Epic.

Individual ChatGPT for Clinicians accounts do not receive the Epic integration. Epic access still requires an approved organization-managed workspace and its EHR configuration.

What Clinicians Can and Cannot Do

Once connected, ChatGPT can retrieve authorized clinical notes, medications, conditions, encounters, laboratory results, and related history. A clinician might ask what changed since a previous visit, request a summary of recent results, or gather medication and specialist updates before an appointment. The response can point back to supporting chart information, which gives the user a route to inspect the underlying record rather than treating the summary as the record itself.

The connector cannot update the chart, place an order, send a patient message, or override existing permissions. Its role is retrieval and synthesis. A missing chart remains missing when the user’s Epic credentials do not permit access, and a generated summary does not change the dates, entries, or decisions in the source record.

Clinicians therefore retain two jobs that the integration does not absorb: reviewing the relevant source record and making the care decision. That human responsibility matters because a fluent summary can make scattered information easier to use without proving that it is complete, clinically appropriate, or correctly prioritized for a particular patient.

Public Data Is a Separate Product

OpenAI launched Healthcare Public Data alongside the Epic connection, but the two plugins have different data and access models. Epic retrieves authorized patient-chart information after organization-specific setup and an individual Epic sign-in. Healthcare Public Data searches public information and cannot access patient charts or medical records.

The public-data plugin combines nine read-only sources: PubMed, ClinicalTrials.gov, DailyMed, RxNorm, openFDA, CMS Coverage, CMS Open Data, Medicare Care Compare, and the NPI Registry. Together they cover research, trial listings, medication labels and identifiers, FDA safety information, Medicare policy and utilization data, facility measures, and provider identifiers. Their inclusion in one plugin does not make the sources interchangeable; each retains its own scope and limitations.

Eligibility also differs. Supported ChatGPT for Healthcare and HIPAA-enabled Enterprise workspaces can use the public-data plugin under administrator controls. Eligible U.S. users of individual ChatGPT for Clinicians can install it as well, even though those individual accounts cannot use Epic. Administrators can manage the plugin and each included app separately, and installing the plugin does not automatically connect all nine apps.

Public access does not make patient information appropriate search material. OpenAI instructs users not to put protected health information or patient identifiers into public-data searches. It also warns that a workspace BAA does not by itself authorize an external public-data provider to receive such information. App calls can appear in compliance logs, while a provider’s own policies may govern data sent to that service.

Vendor Tests Are Not Clinical Outcomes

OpenAI says physicians evaluated connected-EHR responses across 27 clinical use cases. In 4,363 ratings, the company reports that 99.1 percent of responses were rated safe. In a separate company evaluation across five connected public-data sources, each source produced a good-or-better accuracy rating above 93 percent.

UCSF Health is participating as a pilot partner. Its chief executive, Suresh Gunasekaran, said the organization is exploring whether the integration can help teams identify important changes in complex records and potentially spend less time assembling information. He also said frontline teams are validating the capability in practice.

This Is Not Consumer ChatGPT Health

The Epic release is separate from the consumer ChatGPT Health experience that OpenAI introduced in January which lets an individual bring personal health information into a dedicated consumer environment. The September integration instead begins with a healthcare organization’s approved workspace, Epic configuration, and workforce permissions.

The distinction also limits what earlier criticism can show. A later test of consumer ChatGPT Health using Apple Watch data found inconsistent cardiac assessments, but it did not test this Epic connector, its permission controls, or its clinician workflow. 

For connected clinicians, Epic remains the source of the patient record and the source of permission. ChatGPT adds a read-only preparation layer, while the healthcare organization controls deployment and the clinician retains the decision.

Markus Kasanmascheff
Markus Kasanmascheff
Markus has been covering the tech industry for more than 15 years. He is holding a Master´s degree in International Economics and is the founder and managing editor of Winbuzzer.com.
Subscribe
Notify of
guest
0 Comments
Newest
Oldest Most Voted