AI-generated content. This article was researched and written by an automated AI editorial system and published without prior human review. Every factual claim is checked against cited primary sources before publication, but no journalist read this page before you did — treat it accordingly, and report anything that looks wrong. How this works ›

Some links on this page are affiliate links. We may earn a commission at no extra cost to you.
Updated: Sep 3, 2026
·
openaichatgpthealthcareenterpriseintegrationsprivacystrategyvendor-risk

OpenAI just plugged ChatGPT into 325 million patient charts — and the most important word in the announcement is 'read-only'

TL;DR: On Tuesday 1 September 2026 OpenAI announced that healthcare organisations can connect their Epic environments to ChatGPT for Healthcareread-only access to appointment notes, lab results, medications and specialist documentation, in a system holding records for more than 325 million patients. Alongside it, a Healthcare Public Data plugin covering nine official sources including PubMed, ClinicalTrials.gov, CMS Coverage, RxNorm and DailyMed. Launch partners: AdventHealth, Baylor Scott & White, Boston Children’s, Cedars-Sinai, HCA Healthcare, Memorial Sloan Kettering, UCSF Health. Safety evaluation: 99.1% of 4,363 physician ratings judged responses safe across 27 clinical use cases. The thesis: the model is not the news and neither is healthcare. The frontier labs have stopped trying to be your system of record and started competing to be the reading layer over everyone else’s — and “read-only” is not a limitation on that strategy, it is what makes it deployable. For you: the connector list is now a more important purchase criterion than the benchmark table.

What shipped

Two things, and they are worth separating because they carry very different risk.

The Epic connection. Healthcare organisations can now link their Epic environment to ChatGPT for Healthcare. A clinician can pull authorised patient information — appointment notes, laboratory results, medications, specialist documentation — into the assistant and ask questions across it: what has changed since the last visit, which labs came back, how the medication list has moved, what follow-ups are still open. OpenAI supports two deployment shapes: pulling EHR context into ChatGPT, or embedding ChatGPT inside the EHR workflow itself.

The access is read-only. ChatGPT can retrieve and reason over the record. It writes nothing back.

The Healthcare Public Data plugin. A connector spanning nine official healthcare data sources. The named ones are PubMed, ClinicalTrials.gov, CMS Coverage, RxNorm and DailyMed, covering literature, trial eligibility, reimbursement policy, drug terminology and medication labelling. This half touches no patient data at all and is available to individual clinicians as well as to organisations.

Deployment runs under a Business Associate Agreement for HIPAA workflows, with role-based access, single sign-on and audit logs. Existing ChatGPT for Healthcare customers request the Epic connection through a workspace administrator; ChatGPT Enterprise customers go through their account team for Regulated Workspace eligibility. It is the tail end of a sequence — ChatGPT Health arrived for consumers earlier in 2026 (accounts of the exact month differ), ChatGPT for Clinicians followed in April with clinical search, research and workflow tools for referral letters and prior authorisations.

Why the capability is not the story

Nothing in the description above requires a 2026 model. Summarising a patient chart and flagging what changed since the last visit has been within reach of a competent language model for about two years. If capability were the constraint, this product would have shipped in 2024.

The constraint was never capability. It was access, and the paperwork that governs it. A model that cannot see the chart is useless no matter how good it is, and a model that can see the chart without a BAA, audit logs and role-based access is a compliance incident rather than a product.

So what OpenAI actually shipped is not an AI feature. It is a legally deployable pipe into someone else’s system of record, with seven brand-name health systems willing to attach their names to it on day one. That is a distribution achievement and an enterprise-agreement achievement. The intelligence was the easy part.

This is the same transition we described when OpenAI’s Presence launch marked the labs turning into deployment companies. The model layer has commoditised faster than almost anyone predicted — the top ten entries on any credible intelligence index are now separated by margins that do not decide purchases, a point Meta’s Muse Spark 1.3 made again this week by arriving sixth in the world and changing nobody’s shortlist on that basis alone. When the models converge, the competition moves to what the models can reach.

”Read-only” is the strategy, not a caveat

It is tempting to read read-only access as a timidity — a first version, with write access to follow once everyone is comfortable. That reading misses what the constraint buys.

Read-only makes the product deployable without renegotiating clinical accountability. Nothing enters the chart. No order is placed. No clinical action is taken by software. Every output passes through a licensed professional who remains responsible for it. That keeps the assistant outside the regulated device conversation, outside the malpractice conversation, and inside the category of tools a health system’s counsel can approve in weeks rather than quarters.

It is also what makes the safety numbers survivable. OpenAI reports that physicians across 60 countries and 26 specialties reviewed more than 700,000 model responses, and that across 27 clinical use cases, 99.1% of 4,363 physician ratings judged responses safe. Turn that around: roughly 39 responses were rated unsafe — about one in 111.

For a decision-support tool that a clinician reads before acting, one in 111 is a defensible figure, and probably compares well with a hurried human synthesis of the same chart at the end of a long shift. For anything that wrote to the record or acted on its own, one in 111 would be indefensible. The percentage is only acceptable because of the architecture around it. The separate figure worth more of your attention is the reported over 93% accuracy across five connected data sources, because retrieval accuracy is the actual failure mode of a summarisation tool — a confidently wrong lab value is a worse outcome than an unhelpful answer, and OpenAI’s own position remains that the tool is not suitable for diagnosis or treatment.

UCSF Health CEO Suresh Gunasekaran framed the value in the terms the sector actually cares about: bringing relevant information together more quickly could “reduce time spent synthesising data and give clinicians more time with patients.” That is a documentation-burden pitch, not a clinical-judgement pitch. It is the right pitch, and it is what read-only permits you to promise honestly.

Epic is the interesting party here

Epic holds the records. Everyone else is negotiating for a view of them.

The established AI relationship in that building runs through Microsoft: Azure OpenAI Service, Nuance and Epic partnered on ambient clinical technology, and Nuance’s DAX Copilot is fully embedded in the Epic EHR across a large deployed base. On the other side of that market sits Abridge, deployed at more than 300 health systems including a Kaiser Permanente rollout, alongside Suki and Nabla. Epic has also been building its own AI functionality, which puts it in partial competition with the vendors integrating into it.

Those are all write-side tools — they listen to an encounter and produce a note. OpenAI has come in on the read side, and has done it with a direct relationship rather than through Microsoft. Today those are complementary. The thing to watch is whether they stay that way, because both directions converge on the same asset, and the party that owns the asset is neither of them.

For buyers outside healthcare the transferable observation is this: your systems of record are about to be contested territory, and the vendor who gets a first-party connector into yours acquires an advantage that no model improvement can offset. The lesson we drew from the Pentagon’s multi-model GenAI.mil build applies with more force here: read the terms attached to a connector before you standardise on it, not at renewal, because a connector is far harder to swap than a model.

The failure mode is the pipe

Three days before this announcement, a Microsoft 365 authentication outage stripped Copilot of its grounding. The model was fine throughout. The pipe was not, and an assistant that cannot reach your data is not a degraded assistant — it is an unusable one, at the exact moment your users have built their day around it.

The security version of the same exposure appeared in Copilot’s CoSnitch memory-poisoning flaw, where the connector was the attack surface rather than the model. Any pathway by which content you do not control reaches the context window is a pathway into a workflow that people have started to trust.

A read-only clinical connector inherits both. Two questions to put to any vendor selling you a grounded assistant, in healthcare or anywhere else:

  1. What does the assistant do when the connector is unavailable? The only acceptable answer is that it says so. An assistant that silently falls back to answering from parametric memory, in a workflow where users have learned to expect grounded answers, is worse than one that fails loudly.
  2. What content can reach the context window, and who controls it? In an EHR, chart notes contain free text that originated with many parties. Read-only protects the record from the model. It does nothing to protect the model from the record.

There is a third question that is contractual rather than technical, and it is the one buyers skip: what are the data terms on this specific connector? They are frequently distinct from the vendor’s general terms, and healthcare is the proof that vendors will write bespoke terms when the customer has leverage to ask — a pattern we traced through the carve-outs that exist only inside negotiated agreements. The existence of a BAA-backed regulated workspace tells you the vendor is capable of that commitment. It does not tell you that you have one.

What to take from it

If you are in healthcare: evaluate the Healthcare Public Data plugin first. It delivers a real share of the value — grounded answers on trials, coverage, labelling and literature instead of plausible-sounding recall — while carrying no protected health information, needing no EHR integration and no BAA. It is the cheapest way to find out whether grounded retrieval changes anything for your clinicians before you take on patient-data risk.

If you are not: change what you evaluate. The connector inventory, the terms attached to each connector, and the behaviour when a connector fails now tell you more about what a tool will be worth to you than any benchmark. Research-grounded tools like Consensus and Elicit have been making the narrower version of this argument for years, and Perplexity built an entire product on the premise that a cited answer beats a confident one — the Perplexity versus ChatGPT comparison is largely a proxy fight about grounding. What is new in September 2026 is that the general assistants are now buying their way into regulated systems of record, and that the platform layer beneath these integrations has a short half-life worth pricing into any build-versus-buy decision.

On disclosure: if a clinician-facing tool at your organisation produces text that reaches a patient, the Article 50 transparency obligations that came into force last month may land on you as the deployer, not on OpenAI as the provider. That question is worth asking before deployment rather than after. Our productivity tools shortlist covers the general-purpose end of the same market, where the same connector questions apply with lower stakes.

The bottom line

OpenAI did not announce a smarter model on 1 September. It announced that ChatGPT can now read from a database holding 325 million patient records, under a BAA, with seven major health systems willing to say so publicly.

Strip the vertical away and the move is general: when models converge, the fight moves to the pipes, and the pipes run into systems somebody else owns. The winner of that fight is not the lab with the best benchmark. It is the one that signs the integration agreement first and writes the data terms the customer’s counsel will accept.

Read-only is what makes it work. It keeps the accountability with the clinician, keeps the product out of the regulated-device conversation, and makes a one-in-111 unsafe rate into something a hospital can live with. That restraint is the most commercially astute part of the whole announcement — and it is the design principle worth borrowing when you deploy an AI tool against your own system of record.

Frequently asked questions

I don't work in healthcare. Why does this matter to me?

Because the shape of the move is general and the vertical is incidental. For three years the competitive question in AI tooling was which model is smartest, and that question is close to exhausted — the top ten models on any credible index are separated by margins that do not decide purchases. The question that replaces it is what a tool can read. An assistant wired into your CRM, your ticketing system, your document store and your code host beats a marginally better model wired into nothing, every time, on work that involves your actual context. What OpenAI did on 1 September is build a first-party pipe into a system of record it does not own, in a regulated vertical, with the compliance paperwork attached. Expect the same pattern aimed at whatever system of record your industry runs on. When you next evaluate an AI tool, spend your time on the connector list and the terms attached to it rather than on the benchmark table.

Is 99.1% safe a good number?

It is a good number for a decision-support tool with a clinician in the loop, and it would be an alarming one for anything autonomous — which is precisely why the read-only design matters. The evaluation covered 27 clinical use cases and 4,363 physician ratings, of which 99.1% were rated safe. Invert it: roughly 39 responses were not, about one in every 111. A separate evaluation reported over 93% accuracy across five connected data sources, which is the more sobering figure, because retrieval accuracy is where a summarisation tool actually fails. The context that makes 99.1% acceptable is that nothing here writes to the chart, nothing prescribes, and a licensed professional reads every output before it touches care. Strip any one of those away and the same percentage becomes indefensible. OpenAI's own position remains that the tool is not suitable for diagnosis or treatment.

How is this different from Nuance DAX or Abridge, which are already in Epic?

Different job, and mostly complementary rather than competitive today. Ambient documentation tools — Microsoft's Nuance DAX Copilot, Abridge, Suki, Nabla — listen to the clinical encounter and produce a note, which is a write-side workflow aimed at reducing documentation burden. Abridge alone reports deployment across more than 300 health systems and DAX Copilot is fully embedded in Epic through a Microsoft, Nuance and Epic partnership. OpenAI's integration is the read side: pulling existing chart context into a general assistant so a clinician can interrogate a patient's history. The strategic detail worth noticing is that Epic sits at the centre of both, and that Epic's most established AI partnership runs through Microsoft. OpenAI has now built its own direct route to the same data. For buyers, that is a live question about whether these stay complementary through the next contract cycle.

What do we actually need in place to turn this on?

It depends which product you are on, and the distinction is easy to miss. Existing ChatGPT for Healthcare customers request the Epic connection through their workspace administrator. ChatGPT Enterprise customers need to contact their OpenAI account team about Regulated Workspace eligibility, which is a separate qualification rather than a toggle. Individual clinicians on ChatGPT for Clinicians can install the Healthcare Public Data plugin but cannot connect an EHR — that is an organisational deployment by design. On the compliance side the deployment supports HIPAA workflows under a Business Associate Agreement, with role-based access controls, single sign-on and audit logs. The BAA is the load-bearing element: without one signed and in force, none of the rest of this is usable for protected health information regardless of what the product can technically do.

What is the Healthcare Public Data plugin, and is it the more useful half?

For many organisations, quite possibly yes. It connects ChatGPT to nine official healthcare data sources — the named ones include PubMed for literature, ClinicalTrials.gov for trial eligibility, RxNorm for drug terminology, DailyMed for medication labelling and CMS Coverage for reimbursement policy — and it lets a user query across them in a structured way rather than by hoping the model remembers. That matters because it converts questions that previously invited a hallucinated answer into retrieval against a named, current, authoritative source. It also carries no protected health information, needs no EHR integration and no BAA, and is available to individual clinicians. If you want to understand what these connectors are worth without taking on patient-data risk, this is the half to evaluate first.

What is the failure mode nobody is planning for here?

The connector, not the model. We watched this play out in real time three days before this announcement, when a Microsoft 365 authentication outage stripped Copilot of its grounding — the model was fine, the pipe was not, and an assistant that cannot reach your data is not a degraded assistant but an unusable one. The security version of the same exposure showed up in Copilot's CoSnitch memory-poisoning flaw, where the connector was the attack surface rather than the model. A read-only clinical connector inherits both risks: an Epic authentication failure takes the capability offline mid-shift, and any path by which untrusted content reaches the context window is a path into a workflow that clinicians have started to trust. Ask your vendor what the assistant does when the connector is unavailable, and make sure the answer is something other than silently answering anyway from parametric memory.

Should this change what my organisation buys?

It should change your evaluation criteria more than your shortlist. Three things are worth doing regardless of vertical. First, inventory your systems of record and find out which ones your candidate vendors have first-party connectors into, because that list is now the real product differentiator. Second, read the data terms attached to each connector rather than the vendor's general privacy page — connector terms are frequently distinct, and healthcare is the illustration that vendors will write specific terms when a customer has the leverage to demand them. Third, ask what happens at renewal: a connector is a dependency, and unlike a model it usually has no substitute. On the pure question of which assistant is smartest, the honest answer this week is that the gap is small enough not to decide anything, which is exactly why the connectors are where the competition moved.

Sources

Related tool reviews

Questions or corrections? Email Pick Right. Want the full list? See all news.