THE MED-AI BRIEF

{{current_date_full}}  ·  5-MINUTE READ  ·  Read online

Good morning, {{first_name|Doctor}}. Last issue: what the tool quietly takes from the clinician. This week, what the clinician hands over. On 1 September OpenAI connected ChatGPT to the electronic record used by 43.7% of American hospitals, and the safety case arrived as a single percentage.

In today's Med-AI Brief:

  • 🩺 Deployment: ChatGPT gets read access to the chart

  • ⚖️ Regulation: the MHRA sets up inside an NHS trust

  • 🌍 Use cases: in the Gulf, the record is not allowed to travel

  • 🛠️ Practice: audit the summary for what is missing, not what is wrong

DEPLOYMENT
🩺 ChatGPT gets read access to the chart

Illustration of a patient record folder feeding a one-way arrow into a chat bubble, with a padlock on the return path, representing read-only AI access to the medical record

The brief: On 1 September OpenAI connected ChatGPT for Healthcare to Epic. Clinicians can pull a patient's notes, laboratory results, medications and specialist documentation into the chat, or open ChatGPT inside the chart itself for pre-visit review and building clinical timelines. Read-only: nothing is written back.

The details:

  • Epic holds 43.7% of US acute care hospitals and 56.9% of beds, on KLAS contract data through December 2025. UCSF Health is among the first pilot sites.

  • The safety case: physicians produced 4,363 ratings across 27 clinical use cases with connected record context. 99.1% of responses were rated safe.

  • A second plugin connects nine public sources including PubMed, ClinicalTrials.gov and DailyMed. More than 93% of responses were rated good or better for accuracy, ranging from 93.2% on CMS coverage data to 98.6% on DailyMed.

  • United States only, behind a Business Associate Agreement. No UK or EU release announced. OpenAI's stated position is that the tool is not suitable for diagnosis or treatment.

Why it matters: 99.1% is a rating, not an outcome. Invert it and roughly 39 responses were not rated safe, in a sample assembled by the vendor and graded by clinicians reading text rather than treating the patient in front of them. That is the ceiling of what the figure can carry, and it is being asked to answer a much larger question. Then read the disclaimer again. Software is regulated by its intended purpose, as stated on the labelling and in the promotional material, so "not suitable for diagnosis or treatment" is doing regulatory work while the advertised workflow is pre-visit review and clinical timelines. Your registrar will not read the disclaimer. They will read the summary.

REGULATION
⚖️ The MHRA sets up inside a trust

Illustration of a glass-walled testing chamber holding a medical device and a regulator's clipboard inside a hospital building, representing a regulatory sandbox run within an NHS trust

The brief: On 4 September Manchester University NHS Foundation Trust and the MHRA launched a joint innovation sandbox, testing medical devices and AI in live NHS conditions with the regulator involved from the start.

The details:

  • First tool through: a system that identifies patients at high risk of complications from long-term conditions.

  • MHRA chief executive Lawrence Tallon: "The challenge is understanding how they work in practice and where they can make the biggest difference."

  • Expressions of interest are open to device developers for the next phase, with a roundtable later this year.

Why it matters: Almost every safety claim a UK clinician meets was generated on someone else's patients, in someone else's system. A sandbox inside a trust puts local performance data in front of the regulator before national rollout rather than after it. Note what it is not: not a route to market, and not a substitute for the National Commission's recommendations, which were due by summer and are still unpublished. But if the UK wants to stop importing safety claims wholesale, this is the shape of the mechanism that would do it.

USE CASES
🌍 In the Gulf, the record is not allowed to travel

Illustration of a medical record and server held inside a protective dome over Gulf hospital towers, with a data cable stopping at a closed gate on the boundary and a distant cloud left unconnected, representing health data localisation

The brief: Whether a general-purpose model may read the record is, in the Gulf, downstream of a prior question: where the record is allowed to sit. UAE federal law requires health data to be stored and processed locally, save for defined exceptions.

The details:

  • Federal Law No 2 of 2019 mandates local storage and processing of health data, with exceptions set out in Ministerial Decision No 51 of 2021. Records are retained for a minimum of 25 years. MOHAP registers software as a medical device through a classification-based process aligned to EU and FDA frameworks, so a US clinical product does not arrive pre-cleared.

  • When Abu Dhabi's Department of Health built its emirate-wide surgical AI network across Cleveland Clinic Abu Dhabi, PureHealth, Mediclinic and NMC, the surgical data stayed anonymised inside sovereign infrastructure under DoH governance. Undersecretary Dr Noura Khamis Al Ghaithi: "AI here is decision support, not decision making. The surgeon is always in charge."

Why it matters: The UK and the Gulf will not meet this product on the same terms. In the Gulf, data localisation and device registration answer the question before anyone argues about clinical merit. In the UK there is no announced release and no statutory equivalent, which means the question arrives informally instead, as a tired registrar pasting a discharge summary into a consumer chatbot at two in the morning. Of the two, the second is the one already happening.

PRACTICE
🛠️ Two minutes: audit the omissions, not the errors

Take three patients whose records you already know cold. Give the summariser two minutes on each. Then, instead of checking what it got wrong, list what it left out: the stopped drug, the allergy, the DNACPR conversation, the safeguarding note, the appointment they did not attend.

Errors get caught, because they sit on the screen and they read oddly. Omissions do not, because nothing on the screen tells you something is missing. It is the failure mode a satisfaction rating cannot see, which makes it the most useful thing you can carry into a governance meeting.

QUICK HITS
📰 Everything else

  • Funding: The first four procurement competitions under the government's £100m sovereign AI scheme opened on 7 September. One is an NHS productivity challenge run with DHSC, covering workflow automation, care coordination and clinical decision support.

  • Records: A University of Birmingham spin-out launched on 4 September to extract structured data from electronic records.

  • Data: Leeds Teaching Hospitals will host a cancer data research hub, with the West Midlands secure data environment partnering to widen access to cancer data.

  • Still missing: The National Commission into the Regulation of AI in Healthcare was due to report by summer. Its call for evidence drew 761 responses. Nothing published yet. We will keep counting.

How was today's brief?

Login or Subscribe to participate

✉️ One favour: hit reply and tell me whether anything in your trust or hospital actually stops a colleague pasting a patient summary into a consumer chatbot.

Until next week,
Saeed

Know a colleague who'd use this? Send them your referral link.

Nothing here is clinical or legal advice. Check any tool against your own information-governance rules before it touches patient data.