The Collapse of the EHR Walled Garden

Nitin Goel
CTO
Sep 14, 2026
5 minutes
CTO
Physician with tablet showing AI

OpenAI just moved the patient chart into the chat window. Nothing that governed the chart came with it.

On September 1, 2026, OpenAI announced that health systems can connect their Epic environments to ChatGPT for Healthcare. A clinician can pull a patient's notes, labs, medications, and specialist documentation into a ChatGPT conversation, or run ChatGPT inside the Epic layout without leaving the chart. The commentary since then has been about product overlap: a third chart summarizer next to Epic's own and the ambient documentation vendors', and whether CIOs will pay for one more.

That's the wrong debate. The right one is about a wall that just came down.

The wall was the point

For as long as health systems have run electronic health records (EHRs), security has meant one thing: the chart stays inside. Clinicians came to the data. They logged into Epic, moved through screens Epic designed, saw what their role allowed, and triggered a break-the-glass prompt when they reached for something they shouldn't. Every view was logged. Exports were gated. When a privacy officer needed to know who touched a patient's record, one system held the answer.

Call it a "walled garden" if you like. The industry has, usually as a complaint. But the wall was never incidental. It was the control. PHI could be governed because it had one home, and everything that could happen to it happened under one roof.

What OpenAI announced is a gate in that wall. It's a sanctioned gate, with a Business Associate Agreement, and it opens onto a general-purpose AI workspace.

The gate Epic can see

Epic's response deserves a direct quote, because it's correct and because it's the whole problem. A spokesperson told TechTarget:

"Our software is open and interoperable, and OpenAI's app for clinicians is one of nearly 3,000 apps that connect to the Epic EHR through the FHIR APIs available to any developer for free on open.epic. Health systems choose which apps to connect to their EHR and how those apps are used."

The first sentence is a real control. Nothing connects until your Epic team authorizes the app, decides which users get it, and decides which FHIR resources it may read. Epic logs each read. As reported, access is read-only and nothing writes back. That is the same gate every FHIR app passes through, and it is a good gate.

The second sentence is where it breaks. "How those apps are used" is not something Epic can see. Call the point where a FHIR response leaves Epic's API the FHIR boundary. Every control Epic gives you, the roles, the break-the-glass prompt, the access log, lives on the near side of that boundary. What the log will show is that a clinician pulled a patient's data into an application called ChatGPT. Everything after that, Epic cannot know, and Epic has just told you it's your job.

What's on the other side

The other side is not a clinical application. OpenAI is direct about that. With an applicable BAA, "customers can use ChatGPT Work, Codex, apps, and plugins in the same workspace." The workspace where a clinician now reviews a chart is the workspace where business teams write reports, where engineers write code, and where connectors reach SharePoint, Google Drive, Slack, and Outlook. It's also where the new Healthcare Public Data plugin lives, with connectors to nine public sources including CMS Coverage, PubMed, RxNorm, and DailyMed.

In ChatGPT Enterprise, connectors are off until an admin turns them on, and admins can limit what each one may do. So none of this happens by accident. It happens because it's the point. A clinician who pulls a patient's history into a conversation, asks it to check a coverage question against CMS, and drafts a note for the referring practice is using the product exactly as designed. In that one exchange, PHI from Epic, a document from a shared drive, and text generated from a public data source have been combined into something that never existed in the chart, and the result can go wherever the clinician's other tools go.

Inside the garden, that sequence was three separate systems, three separate logins, and at least one export that somebody had to approve. Outside it, it's a sentence.

This is what the product intends. It also means the perimeter that used to be the EHR is now the workspace, and the question a CISO has to answer has changed. It used to be: "Who can see this chart?" It's now "What may this chart be combined with, where may the result go, and can I reconstruct all of it later?"

The record you get, and the control you do not

To be fair to OpenAI, they give you more than most SaaS vendors would. ChatGPT for Healthcare comes with role-based access, single sign-on, and audit logs. ChatGPT Enterprise has a Compliance API that streams append-only log events to Microsoft Purview, Netskope, Zscaler, Cyberhaven, Relativity, and a dozen other tools, with a thirty-day retention window on OpenAI's side. Wire it up and you can get the conversation back.

Every one of those controls acts after the fact. There's nothing in ChatGPT today that lets a health system evaluate a request before the model runs on it.

Last week I wrote about Anthropic's Inference Hooks, which do exactly that for Claude Enterprise: a governance endpoint the customer hosts sees the prompt and every tool result and answers allow or deny before inference. OpenAI has no equivalent.  

For ChatGPT, a health system's controls are the gate on the way in and the record on the way out, and nothing stands between them. Worse, the gate and the record live in two vendors' systems. Following one patient's data from the FHIR read to the prompt to wherever the output went means joining Epic's access log to OpenAI's compliance log yourself. Neither vendor is offering to do it.

The evaluation OpenAI published belongs in the same category. Physicians rated 99.1% of 4,363 responses safe across 27 clinical use cases, and for each of the five public data sources tested, more than 93% of responses were rated good or better on accuracy. Useful numbers. Also the vendor's numbers, with no published methodology, measured on the product rather than on your workflows with your patients' charts in the context window.

The chart used to arrive with the EHR vendor's validation attached. Now it arrives in a window where the model's answer, a CMS lookup, and a SharePoint document all look the same, and telling them apart is on the clinician.

Governance has to leave the garden, too

The wall didn't fall to an attacker. It was opened by the vendor's front door, through the EHR vendor's standard APIs, under a BAA the health system signed. That's what makes this different from shadow AI, and in one way harder. Blocking is not an option when the CMIO sponsored the rollout. The only option is to govern the place the data now lives.

So, treat the ChatGPT workspace the way you've always treated the EHR: as a PHI environment with its own policy, its own access review, and its own record.

Decide, before your Epic team authorizes the app, which connectors may share a workspace with chart data and which actions stay off. Pull the Compliance API into the log platform you already trust and join it to the FHIR access log. Then ask OpenAI for the control point Anthropic already ships, and evaluate a vendor that will not offer one accordingly.

Epic said the health system decides how these apps are used. That's the right answer. It isn't one the health system can make true from inside Epic anymore. The chart was safe because it never left. Now it leaves, and the governance has to go with it.

Nitin Goel is CTO of Vitea, an AI governance platform for healthcare. Vitea helps health systems see, control, and prove how AI is used across their organization.

Suggested for You

Inspired by what you’ve recently viewed.

Bring AI under control
without slowing innovation.
We're here to help you innovate and transform
Discover every AI in use, including shadow AI
Enforce 100+ out-of-the-box policies in real time
Stop risky AI activity before sensitive data is exposed
Continuously monitor AI performance and prove governance on demand
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.