2 SEP 2026 — ChatGPT Health can now import patient records from Epic, whose systems hold data on more than 325 million people, giving clinicians read-only access to notes, labs, medications and specialist documentation. OpenAI reports 99.1 per cent of responses safe across 4,300 physician assessments. The other 0.9 per cent is about 39 responses that were not.

What shipped

The integration went live on 1 September. Clinicians can import records and question them: summarising a patient's information, reviewing history, and identifying what changed ahead of an appointment. In some deployments ChatGPT is embedded in the electronic health record workflow so a pre-visit review and clinical timeline can be built without leaving the chart.

Access is read-only, so the model cannot write into a patient record. OpenAI has added a Healthcare Public Data plug-in reaching ClinicalTrials.gov, CMS Coverage, RxNorm, DailyMed and PubMed.

Organisations with a business associate agreement can use ChatGPT Work, Codex, apps and connectors in compliant workflows. OpenAI states the product is not suitable for diagnosis or treatment. ChatGPT Health launched to US consumers in July 2026 and handles about 300 million health queries a week. The company faces lawsuits from a Florida pastor and family members alleging harmful advice on treatment and dosage.

325m+People whose records sit in Epic systems
99.1%Responses rated safe across 4,300 physician assessments
300mHealth queries a week on the consumer product
Read-onlyThe model cannot write back into the record

Read the safety figure as a count

Ninety-nine point one per cent sounds like a pass, but across 4,300 responses in 27 clinical scenarios it means about 39 were assessed as unsafe. The evaluation does not say what kind of unsafe they were.

Whether that number is reassuring depends entirely on the distribution. Thirty-nine responses that were unsafe by being unhelpfully vague is a different product from 39 that recommended a wrong dose, and the published figure does not distinguish them.

At 300 million weekly queries, even a high accuracy rate produces a large absolute number of bad answers, which is why a percentage is a poor way to describe safety at this scale and a count is a better one.

Read-only protects the record, not the patient

The read-only boundary is a significant engineering decision. A model that cannot write to a chart cannot introduce a fabricated allergy or silently alter a medication list, which removes a whole class of catastrophic failure.

It does not, however, remove the most important failure mode: a summary that omits or misstates something, which a clinician then acts on and writes into the record. The record stays accurate throughout, and the patient is treated on the basis of something incomplete.

This makes summarising a patient's history the most consequential capability on the list. It is exactly the task where an omission is invisible to a reader who has not also read the source material.

The lawsuits and the enterprise product are different things

The Florida litigation concerns advice given to consumers through the public product, and it will be cited in coverage of this announcement. The two situations are not the same and need to be assessed separately.

A consumer asking about their own symptoms has no clinical training, no access to the record and no professional accountable for the outcome. A clinician using a summarised chart has all three, and the professional duty sits with them regardless of what tool produced the summary. That difference is the whole argument for putting this in front of clinicians and not patients.

It also raises a question for the profession. If a clinician relies on a faulty summary and a patient is harmed, the duty of care has not moved. But the standard for what counts as a reasonable review will have to be restated for a workflow where the underlying notes are no longer read.

Compliance is a property of the contract

The business associate agreement language does real work in this announcement and is easy to read past. HIPAA compliance is created by a contract between a covered entity and its business associate, so it belongs to the arrangement rather than to the software.

An organisation that has executed one can use these workflows in a compliant way. The same clinician using the same product without one has no compliance position at all, and the software cannot tell the difference or refuse.

The most likely non-compliant use is a clinician pasting patient details into a personal consumer account to save time. No announcement about enterprise integrations addresses that. We reported that a records vendor took eight months to notify 9.5 million people under the same regime that governs this data. That regime assumes throughout that an organisation knows where its protected health information has gone.

What this means outside the United States

Epic's footprint and the BAA framework are American, and neither transfers. Singapore's Personal Data Protection Act and Malaysia's PDPA have no equivalent of the business associate construct, and health data sits under separate healthcare regulation in both.

For a regional provider evaluating such a tool, the American compliance framework does not import. What has to be established locally is where the data is processed, whether cross-border transfer is permitted for that category, what the retention position is, and who is accountable when a summary is wrong — none of which a BAA covers even where one exists.

The clinical question is separate and simpler. A tool that reduces the time a clinician spends assembling a history is valuable if the assembly is accurate, and the way to find out is a period of running it alongside the existing process rather than in place of it.