Clinical Inbox & Messaging AI
E

Epic In Basket Art

Art is Epic's generative AI feature inside the MyChart In Basket, drafting replies to patient medical advice messages. The name matters and is frequently miswritten: Art stands for AUGMENTED Response Technology, not Automated Response Technology. Epic's own customer documentation and every peer reviewed study of it use Augmented, and the distinction is the product's central design claim rather than a naming detail. Art never sends anything. It presents a draft; the clinician reviews it, revises it, or discards it and writes from scratch, and authorship of what reaches the patient stays with the clinician. The draft is generated by a large language model, OpenAI's GPT 4 family delivered through Epic's partnership with Microsoft, reading the patient's latest message together with relevant chart context such as current prescriptions and recent results, plus prompts configured by the individual health system. Scale separates this record from everything else in the category. Epic reported the feature in use at roughly 150 health systems and medical groups generating about 1 million drafts per month, and named deployments include Mayo Clinic, which began implementing in early 2023 and extended access across its nursing workforce, and NYU Langone. It is also the only product in this category with independent peer reviewed evidence, none of it commissioned by Epic. That literature is unusually candid about the failure modes, including clinicians reporting that drafts sometimes contained incorrect or inappropriate content and that they too often suggested an appointment. This record is scoped to Art specifically and is not an assessment of Epic Systems or of any other Epic AI feature.

Founded
1979
Headquarters
Verona, Wisconsin
Website
www.epic.com
Categories
clinical-inbox
Assessment

Capability Axes

AI Capability
AI Centrality
C
Vendor Published

The clearest platform not algorithm case in this index, and the grade describes the mechanism rather than the product's importance. Epic is the electronic health record. Art is a feature inside In Basket, and no organisation buys or keeps Epic because of it. The moat is the EHR, the installed base and the fact that the messages already live there. The model is also not Epic's: the drafts are generated by OpenAI's GPT 4 family delivered through Epic's Microsoft partnership. Same reasoning this index applies to ModMed and Elation Health, at a far larger scale. The counterpoint a buyer should weigh is that this weakness on centrality is precisely what makes Art commercially formidable, since it arrives inside a system the organisation has already bought.

Autonomy and Oversight Model
B
Third Party Estimated

The strongest structural position in this category paired with the thinnest self disclosure, which is why it lands at B rather than A. Structurally, Art has no autonomous path at all: it drafts and stops. There is no auto close, no auto send, no configurable threshold above which a message goes out unread, and the clinician must review, revise or discard before anything reaches a patient. Every other product assessed in this category disposes of some items without a human. That difference is the design claim in the product's own name, and Augmented rather than Automated is an accurate description of what it does. Held below A because Epic itself publishes no confidence threshold, no abstention behaviour for a message it cannot handle, and no error or acceptance rate of any kind. Everything known about how often the drafts are wrong comes from independent researchers rather than from the vendor. There is also a documented automation bias concern specific to this design: a draft that is usually right invites less scrutiny than a blank box, and at least one published study deliberately seeded errors into drafts, including outdated and potentially harmful advice, to test whether clinicians catch them. Draft and approve is safer than auto send, but it is not the same as oversight.

Model and Technology Transparency
B
Vendor Published

Better than every pure play in this category on the one question that matters most, because Epic names the model. Art runs on OpenAI's GPT 4 family, delivered through the publicly announced Epic and Microsoft partnership, and the input is described concretely: the patient's most recent message, relevant chart context including current prescriptions and recent results, and prompts configured by the individual health system. Naming the model, the provider and the context window contents is more disclosure than any competitor here offers. Held at B because Epic publishes no model card, no evaluation methodology, no accuracy figure and no version or update policy for the underlying model, and because most detailed documentation sits behind customer login rather than in public, so the public record depends on customers and researchers describing the product rather than on Epic doing so.

Clinical and Operational Evidence
A
Third Party Estimated

The only product in this category with independent peer reviewed evidence, and the evidence is candid about what does not work. None of it was commissioned by Epic. A pilot published in the clinical informatics literature studied 80 users across seven clinics at a large Pennsylvania academic health system: of 52 survey respondents, 66 percent agreed the drafts were useful and 46 percent agreed the feature improved reply quality, with nurses consistently more favourable than physicians. The same study reports the unfavourable half in numbers, which is what earns the A: 34.9 percent of free response respondents said drafts occasionally contained incorrect or inappropriate content, and 27.9 percent said drafts too often suggested an appointment. Separate work from NYU Grossman School of Medicine found model drafted replies to in basket messages comparable to clinician replies on accuracy and rated higher on perceived empathy, and a further study seeded deliberate errors into drafts to observe whether clinicians detected them. Deployment scale reported by Epic is roughly 150 health systems and medical groups producing about 1 million drafts monthly, with Mayo Clinic and NYU Langone among named users. Two honest caveats belong on the record: the studies are single site pilots rather than multi site trials, and the evidence describes the product as deployed at academic centres with their own configured prompts, so results are not necessarily portable to a differently configured organisation.

AI Safety and PHI Stewardship
B
Vendor Published

The structural position is genuinely strong and the published detail is thin. Art runs inside the health system's existing Epic environment, on data Epic already holds as the organisation's system of record, so adopting it introduces no new custodian of patient data and no new party to the chain in the way that bolting on a third party inbox tool does. That is a materially better starting point than any competitor in this category can offer. What is not publicly documented is the part that matters most: the specific data handling terms for the model call itself, including whether message and chart content sent to the language model is retained by the model provider, excluded from training, and processed within a defined boundary. Those terms exist but are supplied to customers rather than published, so a buyer should obtain them in writing and should not assume the answer from Epic's general posture.

Regulatory and Compliance
HIPAA and BAA Posture
B
Vendor Published

The health system's existing Epic agreement is the governing instrument and no separate relationship is created with a new vendor, which removes the procurement step every competitor in this category requires. Held at B rather than A on a specific and answerable question: the drafts are generated by a language model supplied through Epic's Microsoft partnership, which introduces a subprocessor into the flow, and adding a subprocessor ordinarily requires agreement terms that address it. Nothing public states whether enabling Art requires an amendment, a supplementary data processing term or nothing at all. That is the single question to put to Epic before enabling the feature.

Security Certifications and Trust Center
Not rated

No publicly verifiable attestation or trust centre specific to Art was located. This is a documentation access artifact rather than a finding about Epic's security posture: Epic's technical and compliance documentation is distributed to customers through its customer portal rather than published openly, and every deploying health system runs the feature through its own enterprise security review. Not Rated should be read as no public evidence located, not as evidence of weakness. A buyer already running Epic will obtain this material through their existing account channel rather than from a public page.

FDA and Regulatory Status
C
Vendor Published

No clearance and none apparently required, and of everything assessed in this category this is the cleanest case for falling within the software functions excluded from device regulation under the 21st Century Cures Act. The exclusion turns on whether a clinician can independently review the basis for the software's output rather than relying on it, and a product that produces an editable draft the clinician must actively adopt, with the source message and the chart both in front of them, is close to the centre of that exclusion. No published regulatory analysis from Epic was located, so the position is inferred from the design rather than stated by the vendor.

AI Governance and Bias Disclosure
C
Third Party Estimated

No fairness, subgroup, reading level or language performance disclosure from Epic was located, and the scale makes that absence more consequential here than anywhere else in this category. At roughly a million drafts a month across around 150 organisations, any systematic behaviour propagates nationally rather than within one practice. Independent research has already surfaced two emergent behaviours Epic does not report itself. Clinicians described drafts containing incorrect or inappropriate content, and separately described drafts that too often suggested an appointment. That second finding deserves attention: nobody appears to have designed an appointment bias, and it emerged anyway in a product whose output shapes downstream utilisation, which is exactly the kind of drift that only surfaces when someone measures it. Since the prompts are configured per organisation, governance is also partly devolved, which means the health system rather than Epic carries responsibility for what its configuration produces, and few are equipped to audit that.

Integration and Deployment
EHR and Interoperability Depth
A
Vendor Published

Maximum depth by definition, with the corresponding lock in. Art is not integrated with the EHR, it is part of it, so there is no interface to maintain, no partner review to pass, no version compatibility risk and no separate authentication. It reads chart context directly because the chart is the same system. The inverse is absolute: the product is unavailable to any organisation not running Epic, and it cannot be evaluated, piloted or purchased by anyone on Oracle Health, MEDITECH, athenahealth or any other platform. For an Epic organisation this axis is settled before the evaluation starts; for everyone else the product does not exist.

Deployment Model and Data Residency
B
Vendor Published

Deployment follows the organisation's existing Epic deployment, which for many large health systems means self hosted infrastructure or a customer selected hosting arrangement rather than a vendor's multi tenant cloud. That inherited flexibility is a real advantage over the pure plays in this category, which are uniformly single option cloud services with no stated residency commitment. The qualification is that the language model call is a different question from where the EHR runs, and the processing boundary for that call is not publicly documented, so an organisation with data residency obligations should establish where inference occurs rather than assuming it follows the EHR.

Commercial
Commercial Transparency
C
Vendor Published

Nothing is published. Epic does not disclose pricing for any product and Art is no exception, so the specific question an existing customer needs answered, whether the feature is included in the current licence or carries additional cost, has no public answer. Nor is it public whether any charge scales with draft volume, which would matter at a million drafts a month across the installed base. The commercial evaluation here is genuinely different from the rest of this category: the comparison is not between published rate cards but between an unpriced feature inside a system already bought and a separately procured product with its own contract, and an organisation cannot model that trade off from public information alone.

Setting and Specialty Coverage
A
Third Party Estimated

The broadest deployment in this category by orders of magnitude. Roughly 150 health systems and medical groups, spanning primary care and specialty care, academic medical centres and community organisations, with both physicians and nurses as users. Named deployments in the public record include Mayo Clinic, which extended access across its nursing workforce, NYU Langone and multiple academic health systems appearing in the published literature. The published evidence explicitly covers both primary and specialty care and reports differences between nurse and physician users, which is more setting granularity than any competitor here provides. The one boundary: it addresses patient medical advice messages within the In Basket rather than the full range of inbox work, so results release, refills and document handling are separate Epic functions and are not what this record assesses.

Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

Entry Price Pricing Basis BAA Tier Implementation Source
Not published
Not disclosed. Epic publishes no pricing. Whether Art is included in an existing Epic licence or carries additional cost is not publicly stated. Governed by the organisation's existing Epic agreement rather than by a new instrument, since no additional vendor relationship is created. The open question is whether enabling Art requires supplementary terms to cover the language model subprocessor introduced through Epic's Microsoft partnership. Nothing public answers this and it should be confirmed in writing before enablement. Not published. Enablement is a configuration exercise within the existing Epic environment rather than an integration project, but organisation specific prompt configuration is part of how the feature works and no cost or effort estimate for that work is disclosed. Vendor Published

Epic does not publish pricing for any product and Art is no exception, so this record contains no figure. The commercial evaluation in this category is structurally different from a normal comparison and buyers should frame it accordingly: the choice is not between two rate cards but between an unpriced feature inside a platform already purchased and a separately contracted product with its own line item, and the second only wins if it does something the first does not. Questions to put to Epic directly: whether Art is included in the current licence or carries incremental cost; whether any charge varies with draft volume, which matters at scale; whether enabling it requires professional services for prompt configuration, since prompts are set per organisation and configuration quality materially affects output; and whether the language model consumption cost sits with Epic or is passed through. For organisations not running Epic, none of this applies, because the product cannot be purchased at all.

AI Health Index

An independent reference for evaluating AI vendors in healthcare. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
July 25, 2026
The AI Health Index is an editorial reference, not a regulatory body. Vendor data is verified against published sources and public regulatory filings. Figures labeled “Estimated” have not been confirmed by the vendor. See the Methodology page for evaluation standards and limitations.
© 2026 AI Health Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746