OpenAI has launched a new Epic electronic health record integration for ChatGPT for Healthcare, alongside a Healthcare Public Data plugin giving direct access to nine official public healthcare sources including PubMed, DailyMed and ClinicalTrials.gov.

Announced on 1 September, the EHR integration allows clinicians to bring authorised patient information from Epic environments into ChatGPT to review changes since a patient's last visit, check recent lab results, and identify medication changes or unresolved referrals. In supported deployments, ChatGPT can also be embedded directly within an EHR layout so clinicians can access it without leaving the patient chart.

The Healthcare Public Data plugin lets teams work with specific records and identifiers from sources such as CMS Coverage and RxNorm without searching each database separately.

OpenAI said it partners with physicians across 60 countries, 49 languages and 26 medical specialties, who have reviewed more than 700,000 model responses to date to help define and improve healthcare-specific model behaviour. On the new tools specifically, physicians evaluated 27 use cases involving EHR context, rating 99.1% of 4,363 responses as safe. In a separate evaluation of the public data sources, more than 93% of responses per source were rated "good" or better for accuracy.

Beyond clinical use, OpenAI said the same governed workspace lets clinical and business teams use ChatGPT Work to turn connected healthcare information into reports, analyses and presentations, while technical teams can use its coding tool Codex to build supporting software. Enterprise plugins for Microsoft SharePoint, Google Drive, Salesforce and Slack are also available within the workspace, alongside existing permission controls.

Healthcare launch partners include AdventHealth, Baylor Scott & White Health, Boston Children's Hospital, Cedars-Sinai, HCA Healthcare, Memorial Sloan Kettering Cancer Center and UCSF.


Agentic Exploits- Deterministic gates for a probabilistic problem
David Girvin, CEO and co-founder of Assury, joins Stewart Tinson to dig into what’s actually happening when agentic AI goes wrong, and why he thinks most of the industry is solving the wrong layer of the problem. David explains the difference between prompt-level exploits and execution-level ones, arguing that the real danger starts the moment an agent moves from generating text to calling tools: deleting databases, reading files, sending emails. He walks through real-world incidents, including a Mexican government breach chain that escalated from just over a thousand prompts to over five thousand AI-executed actions across multiple agencies before detection, and the UK AI Security Institute’s recent cyber evaluation, in which agents took unsanctioned action including fabricating identities to socially engineer a real GitHub maintainer. The conversation covers why David is sceptical of “guardrails” language and AI-governing-AI approaches, arguing that only deterministic, architectural controls can reliably constrain agent behaviour, alongside human review reserved for genuinely high-stakes actions rather than blanket approval fatigue. He breaks down credential starvation, session risk accumulation, and why classifier-based tools keep failing inconsistently on identical actions, pointing to a named frontier lab’s own zero trust paper as an example of the industry misjudging what actually works. Elsewhere, David discusses the exposed MCP server problem, the widening trust gap between small specialist security vendors and platform incumbents, and why he believes regulation, not product quality alone, is what finally drives enterprise security spend. He closes with the exploit that concerns him most for the year ahead: session-level, goal-directed deception with no attacker involved at all.
Share this post
The link has been copied!