top of page
Search

ChatGPT Adds Healthcare Public Data and Epic Connections for Clinicians

  • Veronika
  • 4 hours ago
  • 5 min read

September 6, 2026

OpenAI has added new healthcare data connections for eligible ChatGPT for Healthcare and HIPAA-enabled ChatGPT Enterprise workspaces. The update includes a Healthcare Public Data plugin that searches nine public sources and an Epic connection that can retrieve authorized information from electronic health records.

Both tools are read-only. The launch is intended to help clinicians and healthcare staff research evidence and review permitted patient information without manually switching between many systems. It also highlights the privacy and governance requirements that accompany AI in clinical settings.

ChatGPT healthcare connections: key facts

  • Healthcare Public Data combines nine public healthcare information sources.

  • Coverage includes research, clinical trials, medication data, Medicare information and provider records.

  • The Epic connection retrieves authorized patient information from an organization’s electronic health record.

  • Epic access requires administrator configuration, an individual sign-in and existing chart permissions.

  • Both connections are read-only and controlled separately by workspace administrators.

What Healthcare Public Data provides

The public-data connection is designed for evidence and operational research. Clinicians can search biomedical literature, clinical trials, medication information, government healthcare datasets and provider records through one ChatGPT workflow.

Because these are public sources, users must not include protected health information in their searches. The connection does not access patient charts. Its value comes from reducing the time required to search multiple authoritative databases and synthesize relevant findings.

How the Epic connection works

Epic is a widely used electronic health record platform. The new connection allows eligible users to review patient information they are already authorized to see. It does not create new chart permissions or allow ChatGPT to bypass the healthcare organization’s controls.

An administrator must configure the Epic application, and each user signs in individually. Existing patient-chart permissions continue to determine what information is available. The connection is read-only, which limits the risk of an AI system modifying a medical record.

Potential benefits for clinicians

Healthcare workers often divide their attention among clinical literature, patient records, internal policies and administrative systems. Bringing authorized sources into one interface could help prepare for appointments, compare evidence, summarize a chart or identify questions for further review.

The system may also reduce repetitive research and documentation work. Yet it should support—not replace—clinical judgment. AI can omit context, misunderstand chronology or generate an incorrect synthesis even when its sources are accurate.

Privacy, HIPAA and protected health information

OpenAI states that eligible workspaces can use the healthcare connections, but coverage under a Business Associate Agreement depends on the product, configuration and task. Organizations must confirm that an applicable agreement and approved workspace setup are in place before using Epic with protected health information.

Protected health information should never be included in queries to public healthcare sources. Administrators should manage plugin availability, app access, audit controls and user training. Access should follow the minimum-necessary principle.

Why read-only access matters

Read-only design creates a meaningful safety boundary. The AI can retrieve and summarize information but cannot directly change orders, diagnoses or notes through these connections. That keeps consequential medical actions within existing clinical workflows.

Read-only does not eliminate risk. A summary may still influence a decision, and displaying information outside its original interface can change how it is interpreted. Clinicians should verify important details in the source record and follow institutional policy.

What healthcare organizations should evaluate

Before deployment, organizations should test source accuracy, permission enforcement, audit logs and failure behavior. They should define when outputs require source review, how citations are displayed and what staff must do when the AI conflicts with the medical record.

Training should cover privacy, appropriate use and the limits of automated synthesis. High-impact decisions must remain with qualified professionals, and patients should receive care based on validated information rather than unreviewed model output.

The wider significance

The update shows how enterprise AI is moving beyond general chat into regulated workflows connected to specialized systems. The competitive advantage will increasingly come from secure access to trusted data, not only from the underlying language model.

Healthcare is a demanding test because accuracy, privacy and accountability all matter. The safest deployments will preserve institutional controls and make the source of every important claim easy to inspect.

The bottom line

ChatGPT’s new healthcare connections could make public evidence and authorized Epic data easier for clinicians to use. Read-only access and existing permission controls are important safeguards, but responsible adoption still requires contracts, configuration, training and human review. The technology should help professionals navigate information—not make medical decisions on its own.

Source: OpenAI Enterprise and Healthcare release notesDesigning evidence-based clinical workflows

A useful healthcare assistant should show where information came from, when it was published and whether it applies to the patient’s situation. Clinicians need direct links to the underlying study, guideline or chart entry so they can verify important claims quickly.

Organizations can create templates for common tasks such as trial searches or pre-visit summaries. Each template should define approved sources, required citations and the point at which a qualified professional reviews the result.

Avoiding automation bias

People may give extra weight to an answer because it appears fluent and personalized. This automation bias is particularly risky when an AI synthesis omits a contraindication, confuses two patients or presents uncertain evidence too confidently.

Interfaces should communicate uncertainty and encourage source review. Training can use realistic examples where the model is wrong, teaching clinicians to treat it as a fallible assistant rather than an authority.

Permission design for Epic access

The Epic connection should inherit existing chart permissions, but healthcare organizations still need to test edge cases. Temporary staff, shared roles, emergency access and recently changed assignments can create unexpected visibility.

Audit logs should record the user, patient record, purpose and information retrieved. Monitoring can flag unusual access patterns, while administrators should be able to disable the connection quickly without disrupting the underlying EHR.

Data minimization and retention

Even read-only tools can expose more information than a task requires. Prompts should retrieve the minimum necessary portion of a chart, and outputs should avoid repeating identifiers unless essential. Temporary working data needs clear retention and deletion rules.

Healthcare leaders should confirm which activities fall under a Business Associate Agreement and which do not. Product eligibility alone does not guarantee that every workflow is compliant.

Evaluating accuracy in practice

Testing should include missing data, conflicting notes, duplicate names and outdated medication lists. Reviewers can score factual accuracy, completeness, citation quality and whether the assistant recognizes when it lacks enough information.

Performance should be monitored after launch because source systems, models and clinical guidance change. A safe program includes incident reporting and a process for pausing workflows when new risks appear.

Patient communication and transparency

If AI helps draft patient instructions, clinicians should review medical accuracy and readability. Translations require additional checks for terminology and cultural context. Patients may also benefit from knowing when automated assistance contributed to a document.

The goal should be clearer communication and more clinician time, not faster production of text that nobody verifies.

What to watch next

Adoption will depend on integration quality, auditability and evidence that the tools reduce administrative burden without increasing clinical risk. Organizations should watch how permissions behave at scale and whether citations remain reliable across public sources and patient records.

The broader opportunity is a connected information layer that helps professionals find evidence while preserving existing responsibility. Healthcare will judge AI by patient outcomes, privacy and trust—not by the number of generated summaries.

 
 
 

Recent Posts

See All

Comments


bottom of page