OpenAI connected ChatGPT to Epic earlier this month. Read the coverage and you'll find two of the three governance layers discussed at length.
The third is the only one a hospital actually controls.
Clinicians can now pull notes, labs, medications and specialist documentation into a chat without leaving the patient's chart. Access is read-only — the model can't write back to the record.
That's a real decision, and a good one. It's also a decision made entirely by the vendor.
In July, I wrote that using AI responsibly has to live in three layers at once. The systems layer: what the model's makers build and constrain, the limits no user should be able to switch off. The local layer: the judgment of the person at the keyboard in a specific moment, where the real context lives. And the organizational layer in between — the one your business actually owns, and the one most companies skip.
Read the Epic coverage against that. Read-only is the systems layer. Whether a clinician verifies a summary against the chart is the local layer, and health system CIOs are asking for exactly that — grounded in the source record, easy to check.
The middle layer is barely in the conversation.
It's where the decisions actually sit. The business associate agreement covers only the functionality on the vendor's eligible list, so somebody has to read the list. Improved memory sits outside it — disabled by default, not covered, PHI not permitted. Which makes it a setting. Then retention. Residency. Audit logs. Who is allowed to turn on what, and who notices when something changes.
None of that is the vendor's call. All of it is someone's job inside the hospital, and no announcement is going to tell you whose.
What I keep taking from it: the systems layer gets designed in public and the local layer gets argued about in public, so it feels like the subject is covered. It isn't. The layer between them is the one you own, and it stays quiet because nobody outside your building is going to raise it.
This isn't the large systems' problem. They have CIOs on the record asking about audit logs and minimum-necessary access. It's the forty-provider specialty group where the admin is also the practice manager, and a feature gets switched on because it looked useful.
Seven weeks ago the middle layer was a diagram. This week it's a checkbox in a chart.
Where does your operation actually stand?
The AI Operational Readiness Assessment asks about the foundation underneath the tools: how work is documented, who the operation depends on, and what happens when something goes wrong. Roughly 30 questions, free, and you get the analysis.
Take the assessment