Build1 distinct publisher3 min readPublished
OpenAI says ChatGPT can now reach health-system records, but the announcement names no EHR vendor, region, role or price, which leaves a 30-day deletion window as the only number a compliance review can test.
The Engineer · Build desk

Compiled by The EngineerSomething wrong?How this is made
Before a connected summary can render a single line, it has to resolve which records this user may read, right now. The chat surface does not answer that. According to the dev.to write-up of OpenAI's announcement, clinical use, data access and the exact interface will be determined by the health system and the integration available to it [6]. Access follows from that clause: entitlement stays in the source system, so whatever your EHR grants a role today is the ceiling on what an assistant running in that context can pull tomorrow.
This is why the workspace posture stops being the interesting artifact. HIPAA-compliant workspaces are part of the existing ChatGPT for Healthcare offering [2], and a compliant workspace is a claim about the vendor relationship and the tenant boundary. It does not decide whether a covering clinician can summarise a chart they would not otherwise have opened. That decision lives in role definitions and break-glass rules you already own, and it now gets exercised by a text box instead of a human clicking through a chart.
The one hard number is retention. OpenAI says data synced from connected health sources is deleted from its systems within 30 days [5]. Synced means copied: connected record data exists outside the source system for a window bounded at 30 days [1]. Anything you do with breach scope, disclosure logging and retention policy now covers a store you do not operate, for up to a month per sync. Whether 30 days is a fixed TTL or a ceiling is not stated.
The training exclusion has the same shape. OpenAI says data connected to Health features can be configured so it is not used to train its foundation models [4]. Configurable means the setting has to be checked, per workspace, and checked again after anyone touches settings [2]. That is a verification task, not a property of the product.
The demo would need several things to hold true before it transfers to your shop, and none of them appear in the announcement: your EHR on a supported list, your region covered, entitlements resolved per user rather than per workspace, and a price. The initial communications do not exhaustively identify compatible EHR vendors, regional coverage, user permissions or commercial terms, and availability depends on deployment-specific arrangements and enterprise partnerships [3]. A compatibility claim with no vendor named is difficult to put in a change ticket.
Note also that the listed workflows, including note drafting and patient summarisation, are examples the high-level description points toward rather than guarantees for any given deployment [7]. dev.to's own advice is a narrow first use case for smaller providers and specialist practices [11], which happens to be the only kind of scope today's public information can support. The standing cost is review: the announcement positions the assistant as help inside the workflow, not a replacement for clinicians, which means someone reads every draft before it counts [8].
Ranked by verification strength, evidence, and original report placement.
The initial communications do not provide an exhaustive list of supported EHR vendors, regions, user roles or pricing, and availability will depend on deployment-specific arrangements and enterprise partnerships.
dev.to says healthcare organizations still need to understand which information is connected, who can access the feature, how the integration behaves within the existing EHR environment and what local policies apply, and that the public information does not fully specify those implementation details.
OpenAI is enabling direct interoperability between ChatGPT and health-system data sources, including electronic health records, in supported deployments, so AI-assisted work happens inside clinical workflows instead of a separate tool.
The change expands OpenAI's ChatGPT for Healthcare direction, which includes HIPAA-compliant workspaces and responses backed by trusted medical sources.
OpenAI says data connected to Health features can be configured so it is not used to train the company's foundation models.
OpenAI says data synced from connected health sources is deleted from OpenAI's systems within 30 days.
Distinct publishers with included, body-backed reporting in this cluster.
dev.to
1 article · September 1, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
build
GPT-5.6 ships as three models, and that makes model choice a deployment decision1 distinct publisher
build
ChatGPT tops Google's paid-click share at 4.75%, and growth teams should reprice the auction1 distinct publisher
build
OpenAI moves its inference onto a chip nobody outside OpenAI can buy or benchmark1 distinct publisher
build
ChatGPT Ads opens to all US advertisers, and the search measurement stack does not come with it1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One relay of one vendor statement
Every factual assertion here — the connection itself, the HIPAA workspaces, the training exclusion, the deletion window — originates with OpenAI and reaches us through a single dev.to write-up that quotes no primary documentation and no customer. The only claim a compliance reviewer could actually test is the 30-day window. Everything a reviewer would test next is missing by dev.to's own admission.
Announced, nowhere observed
An announcement exists and that is the whole of it. Not one health system, EHR vendor or region is named, access is described as flowing through unspecified enterprise partnerships, and dev.to's advice to start with a single narrow use case reads as guidance for organisations that have not begun rather than a report on ones that have.
Headline arrives before the specifics do
The framing — ChatGPT connects to health records — is a wider promise than the body can keep, and dev.to knows it, hedging the workflow list as illustrative and reminding readers that scope is whatever the health system's integration allows. The overstatement is in the packaging rather than the argument, so the gap is real but modest; a piece that walks back its own title four times is not selling hard.
Vendor supplies the facts, publisher supplies the invoice
Two interests point the same way. OpenAI is the sole origin of every favourable detail, including the privacy assurances it would most want repeated. And dev.to's piece resolves into a pitch for Scalevise's AI consultancy to map systems and build the implementation plan — arriving directly after the passage arguing that providers cannot evaluate this alone. The cautious tone is genuine and also commercially useful.
Direction believable, details unauditable
That OpenAI is pushing ChatGPT toward the chart is credible and consistent with its stated healthcare programme, so the shape of the story is probably right. What cannot be relied on is anything an implementation decision would need: which systems, whose permissions, at what price, under which agreement. Confidence here reflects a trustworthy direction sitting on an unverifiable base.