When OpenAI announced on Sept. 1 that ChatGPT could connect to Epic, reactions split between “this changes everything” and “this changes nothing.” For chief medical information officers and chief technology officers, the more consequential questions lie elsewhere: Will this integration close the information gap between patients and their physicians, or widen it? And who is positioned to tell?
What “read-only” actually means
OpenAI’s documentation is unambiguous: “Access is read-only and follows existing workspace, Epic, and patient-chart permissions.” Clinicians can query the record without leaving it; the model cannot write a note, place an order, modify the chart or message a patient.
Read-only does not mean limited. The tool does real cognitive work; it simply does not act. That deliberate design keeps the clinician in the decision seat. Adoption will also be uneven: an administrator must connect and enable Epic access, and pricing follows ChatGPT Enterprise terms based on organization size and deployment needs.
Vendors and three jobs described as one
The assumption that ambient documentation vendors are now in trouble rests on a category error. A read-only tool cannot replace a product whose value is generating the note. That market’s competitive event came in February, when Epic shipped native AI Charting. Vendors are already moving deeper into revenue cycle and coding.
Leaders need sharper vocabulary than “AI summarization.” Capture turns a live patient-physician conversation into documentation. Retrieval makes sense of what is already in the record. Native documentation is the EHR generating the note itself. A system that has solved capture has not solved retrieval, and conflating them confuses both governance and clinician expectations.
The AI divide inside the exam room
We have moved from “Dr. Google” to “Dr. ChatGPT.” Pew Research found this summer that about a third of American adults use AI chatbots for health questions, and a quarter use them to figure out what is causing their symptoms. Patients arrive after hours with a tool that is always available but knows only what they tell it, not their medications, imaging or history.
The physician holds the other half of the puzzle: the objective record, but no view of the chatbot conversation. I call this the AI divide: a gap in information and trust inside the exam room, where the person with the least clinical training has often held the more capable tool.
The stakes are real. Emergency physician colleagues recently described two cases. A man in his 40s having a myocardial infarction declined treatment after a chatbot suggested he needed “more evaluation;” the delay left him with life-altering complications. Another patient was told by a chatbot that his symptoms could indicate a stroke, and he reached the emergency department in time. Same technology, opposite outcomes.
An assistant that reads the chart can begin to close this divide, precisely because it is read-only: the clinician gains fluency with the record without ceding judgment. If time saved on chart review is returned to the patient rather than absorbed into throughput, both sides arrive prepared. But the same integration could widen the divide if summaries omit critical details, if model updates quietly degrade performance, or if reclaimed time simply becomes more visits. Which outcome we get is an empirical question, and today no one is positioned to answer it.
Guardrails are not governance
Guardrails are constraints built into a tool. Governance is the system of people, rules and accountability that defines those guardrails, verifies they work and acts when they fail. Guardrails without governance erode; governance without guardrails catches nothing in the moment.
The current guardrails are a credible start. OpenAI’s Epic connection is read-only, inherits chart permissions, logs access, points back to source documentation and does not train on customer data. Epic’s assistant, Art, requires clinician review and shows its sources. Three structural gaps remain:
- Self-attestation. The guardrails were designed and tested by the companies selling the products.
- Fragmented validation. Each health system validates alone, with governance maturity that varies widely.
- Continuous change. Models update on the vendor’s cadence. A spring validation is a snapshot of a moving target by fall.
A compounding risk sits beneath all three: AI reading AI. Many notes are now first drafted by ambient AI, then signed by a physician. When a retrieval tool summarizes that record, an upstream error, such as an omitted penicillin allergy, can propagate downstream and gain authority at each step. Someone must monitor the whole chain, not one tool.
The case for an independent healthcare AI safety board
A restaurant does not inspect its own kitchen, and medicines are monitored after approval as well as before. Clinical AI warrants the same discipline from a body independent of vendors and of any single health system. A healthcare AI safety board would:
- Evaluate before deployment against standardized clinical test sets, not vendor benchmarks.
- Monitor continuously after go-live, detecting drift across institutions after model updates.
- Measure the divide itself through shared metrics: summary accuracy and omission rates, AI-attributable safety events, and whether reclaimed time reaches the patient.
- Test security, so one compromised credential cannot expose a patient population.
- Require incident reporting and issue rapid cross-institution alerts.
Independence is the point. No vendor sees beyond its product, and no health system sees beyond its walls. Only an outside body with visibility across both can credibly say whether the divide is closing or widening.
Accountability should be shared, not shifted. As with driver-assist cars, where a defect implicates the manufacturer as well as the driver, clinicians verify and decide; health systems select, train and monitor; vendors ensure performance and disclose failures. An independent board gives all three a common standard.
Policy is already moving
Massachusetts offers a preview. Lawmakers are advancing legislation requiring a licensed health professional, not an algorithm alone, to make insurer denials of care. This month, Gov. Maura Healey urged state lawmakers to require independent third-party evaluation of AI models, arguing that “third-party audits of companies’ own standards are not enough,” and to require faster reporting of AI safety incidents, with a threshold as low as a single death. “The death of even one person is catastrophic,” she said.
The governor’s proposal addresses AI broadly, not health care specifically. But I believe health care needs the same principle applied to clinical AI: an independent board that keeps evaluating these tools long after they are switched on in our hospitals.
The direction is right — the measurement is missing
The patient holds one half of the puzzle; the physician holds the other. AI at the chart can help bring them together, and after two uncomfortable years, that is worth naming. But AI is being handed the keys to our most sensitive environments before the locks and cameras are installed. Whether this integration closes the AI divide or widens it will be settled not by vendor announcements or single-site pilots, but by sustained, independent measurement. We should build it now.
Dr. Hashmi is CEO of Magna GenAI Consulting in Boston. She advises hospitals, businesses, healthcare AI companies and startup executives on AI systems. She has contributed to Forbes on AI in business and healthcare, speaks regularly at Healthcare Information and Management Systems Society, has given invited grand rounds at Harvard University Medical School–affiliated hospitals, including Mass General Brigham, and leads AI strategy workshops for institutions such as Cleveland Clinic. She can also be reached via LinkedIn.