Epic Sepsis Model
The Epic Sepsis Model is a proprietary sepsis prediction model built into the Epic electronic health record, scoring hospitalised patients continuously and firing an advisory to clinicians above a threshold Epic recommends setting at 6. It has been deployed at hundreds of United States hospitals, which makes it almost certainly the most widely used clinical prediction model in existence. It is also the most externally validated, and that history is the reason this record matters. Epic reported hospital level performance for the original model at an area under the curve of 0.76 to 0.83. In 2021 Wong and colleagues at Michigan Medicine published an external validation in JAMA Internal Medicine covering 38,455 hospitalisations, and found an area under the curve of 0.63, sensitivity of 33 percent, specificity of 83 percent and positive predictive value of 12 percent. An accompanying editorial was titled The Epic Sepsis Model Falls Short. A separate study of 145,885 encounters across two county emergency departments later reported sensitivity of 14.7 percent and, more strikingly, a median alert lead time of zero minutes, meaning half of all alerts arrived at or after the point clinicians had already recognised sepsis. Epic subsequently rebuilt the model. In February 2026 the same lead author published a multicentre prospective validation of Epic Sepsis Model version 2 in JAMA Network Open, covering 227,091 inpatient encounters across four major United States health systems, reporting an area under the curve between 0.82 and 0.92. Discrimination improved substantially. The paper also found high institutional variability, low positive predictive value and high alert burden, and recommended that institutions run local validation, integrate workflows to handle false positives, and adopt alert silencing strategies. This record is scoped to the sepsis model and is not an assessment of Epic Systems or its other AI features.
Capability Axes
Platform not algorithm, with one distinction from Epic's other AI features worth recording. Unlike In Basket Art, which runs on a licensed third party language model, the Sepsis Model is Epic's own proprietary model, so the company did build this one. It is still a feature inside an electronic health record, and no organisation buys or keeps Epic because of it. What makes the model possible is the same thing that makes it hard to displace: Epic already holds the continuous vitals, laboratory and order data the model consumes, so the moat is data access and installed position rather than modelling. Graded C on mechanism. A buyer should note that the commercial dynamic here is unusual for this category, since the incumbent's model arrives already switched on while every competitor has to be procured, integrated and justified against it.
The architecture is advisory only and nothing acts autonomously, and in this category that is not sufficient. The model scores continuously and surfaces a best practice advisory to a clinician who decides; no order is placed and no treatment is initiated. But the failure mode this category exists to measure is an alert that arrives too often or too late to be acted on, and the published record on both is poor. Positive predictive value was 12 percent in the Michigan validation of version 1 and 7.6 percent in the county emergency department study, and the multicentre validation of version 2 explicitly names low positive predictive value and high alert burden despite much better discrimination. The lead time finding is the sharpest: in the county emergency department cohort the median alert lead time was zero minutes, so half of alerts fired at or after clinicians had already recognised sepsis, and that study concluded the alert was adding little to clinician judgment in that population. Epic publishes a recommended threshold of 6 and, so far as public materials show, no expected alert burden per patient day, no lead time distribution and no guidance on what silencing is appropriate. The version 2 investigators had to recommend alert silencing strategies themselves, which places the burden of making the tool usable on the deploying institution.
The lowest transparency grade in this category and the reason is structural rather than a matter of missing paperwork. The model is proprietary and closed: no model card, no feature list, no training population description, no calibration data, and no published methodology behind Epic's own reported area under the curve of 0.76 to 0.83 for the original version. That figure could not be independently reproduced, and when external researchers measured performance in a real deployment they obtained 0.63. A buyer cannot audit where the model degrades, cannot know which variables drive a given score, and cannot verify the vendor's own performance claim, which is the condition this index has described elsewhere as unfalsifiable from outside, where closedness converts an ordinary technical limitation into a governance problem. Two counterweights belong on the record. Epic did rebuild the model after the 2021 finding, and version 2 has now been prospectively validated across four health systems, which is a materially better evidence position even though the underlying disclosure has not changed. And methodological criticism of the 2021 analysis exists, including the argument that discrimination alone is an incomplete way to judge a deployed alerting tool. Neither counterweight gives a buyer the ability to inspect the model.
The most externally validated clinical prediction model in this index, and the grade describes the existence and quality of the evidence rather than the performance it revealed. Performance is graded on the transparency and autonomy axes; this axis asks whether anyone outside the vendor has measured the thing, and here several parties have, repeatedly, at scale, in major journals, with unflattering results published in full. Wong and colleagues, JAMA Internal Medicine, 2021, volume 181, pages 1065 to 1070: external validation across 38,455 hospitalisations at Michigan Medicine between December 2018 and October 2019, reporting an area under the curve of 0.63 with a 95 percent confidence interval of 0.62 to 0.64, sensitivity 33 percent, specificity 83 percent, positive predictive value 12 percent, negative predictive value 95 percent, with an accompanying editorial by Habib, Lin and Grant titled The Epic Sepsis Model Falls Short. A separate retrospective cohort across two county emergency departments covering 145,885 encounters in 2023 reported sensitivity 14.7 percent, specificity 95.3 percent, positive predictive value 7.6 percent and a median lead time of zero minutes. Then Wong and colleagues again, JAMA Network Open, February 2026: a multicentre prospective validation of version 2 across 227,091 inpatient encounters at four major United States health systems, reporting an area under the curve between 0.82 and 0.92 alongside high institutional variability, low positive predictive value and high alert burden, and comparing the model against both its predecessor and clinician recognition. Note what this sequence demonstrates, because it is the argument for the whole practice: independent validation identified a problem, the vendor rebuilt the model, and independent validation measured the rebuild.
Structurally the strongest position available in this category and thinly documented, as with Epic's other features. The model runs inside the health system's own Epic environment on data Epic already holds as the system of record, and unlike Epic's generative features there is no external model provider in the path, so no third party receives patient data and no new custodian is introduced. That removes the largest exposure most competitors in this category carry, since a monitoring vendor ordinarily requires a continuous feed of vitals and laboratory results to leave the institution. Held at B because Epic publishes no specific position on retention of model scores, whether score histories are used for model development, or how deployment data flows to Epic, and those questions should be answered in writing rather than inferred from the architecture.
Governed by the organisation's existing Epic agreement, with no new vendor relationship and, unlike Epic's generative features, no third party subprocessor introduced into the data path. That is a cleaner position than In Basket Art on this axis, since the subprocessor question that record raises does not arise here. Held at B rather than A only because Epic publishes nothing about it, so a buyer is relying on the general shape of their existing agreement rather than on any stated terms specific to the model.
No publicly verifiable attestation or trust centre specific to the Sepsis Model was located. Epic distributes compliance documentation to customers through its customer portal rather than publishing it, and every deploying organisation runs the model through its own enterprise review. Not Rated should be read as no public evidence located rather than as a finding about the underlying posture.
No device authorisation, and the model operates under the clinical decision support exclusions in the 21st Century Cures Act. The tension between that position and the transparency record is worth stating plainly, because it is the sharpest regulatory question in this category. The exclusion turns on whether the clinician can independently review the BASIS for the software's recommendation rather than relying on it. The Epic Sepsis Model is proprietary: the features, weights and reasoning behind a given score are not disclosed to the clinician receiving the alert or to the institution deploying it. A clinician cannot in any meaningful sense review the basis for a score they cannot see. That does not settle the regulatory question, which turns on statutory interpretation rather than on this index's view, but a buyer should understand that the argument for exclusion rests on a reviewability the product does not obviously provide, and should ask Epic for its documented analysis.
No fairness, subgroup or performance variation disclosure from Epic was located, at a scale where that absence propagates nationally rather than within one institution. The published record supplies a specific governance finding that Epic does not: the version 2 multicentre validation reported HIGH INSTITUTIONAL VARIABILITY, meaning the same model performs materially differently at different hospitals. That is the finding with the most operational consequence in this whole record, because it means no institution can infer its own performance from anyone else's, and the investigators accordingly recommended that institutions conduct local validation studies. The burden of discovering whether the model works at your hospital therefore sits with your hospital, and few are equipped to carry it. Sepsis recognition and treatment disparities are documented in the clinical literature, and a model trained on historical recognition patterns can reproduce them; no subgroup performance data exists publicly to establish whether this one does. The alert burden also falls disproportionately on nursing staff, who receive and triage the advisories.
Maximum depth by construction, with the corresponding absolute lock in. The model is not integrated with the record, it is part of it, consuming vitals, laboratory results, orders and documentation directly with no interface, no feed, no latency and no data egress. For a continuous monitoring product that is a genuine architectural advantage over every competitor in this category, all of which must establish and maintain a real time data pipeline out of the EHR before they can score anything. The inverse is total: the model is unavailable to any organisation not running Epic and cannot be evaluated or purchased separately.
Deployment follows the organisation's existing Epic footprint, which for many health systems means self hosted or customer selected infrastructure rather than a vendor's multi tenant cloud, and inference runs locally against local data with no external model call. For an organisation with data residency obligations that is a materially simpler position than any competitor in this category can offer, since a monitoring vendor ordinarily processes a continuous clinical data stream off premises. Held at B because Epic publishes no specific statement on where model scoring occurs or how model updates are distributed and validated at each site.
Nothing is published. Epic discloses pricing for no product and the Sepsis Model is no exception, so whether it is included in an existing licence or carries incremental cost has no public answer. The commercial comparison in this category is structurally lopsided and buyers should frame it deliberately: the incumbent model arrives inside a platform already purchased and is frequently switched on by default, while every competitor must be procured, integrated into a real time data feed, and justified against a free alternative. That is not a reason to prefer either, but a competing vendor's true comparison is against the Epic model as configured at that institution, and an institution that has never locally validated its own Epic model does not actually know what it is comparing against.
The widest deployment of any product in this index, and unusually the published evidence spans genuinely different settings rather than one favourable one. Deployed at hundreds of United States hospitals across adult inpatient care, with published validation covering a large academic medical centre (Michigan Medicine), four major health systems in the version 2 multicentre study, and two county emergency departments serving a safety net population. That last setting matters because it produced the weakest results, sensitivity of 14.7 percent and zero median lead time, which is exactly the kind of setting specific variation that a single site validation would have concealed and that the version 2 study independently confirmed as high institutional variability. Scope is sepsis prediction specifically; Epic's other deterioration and risk models are separate functions and are not assessed in this record.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
| Entry Price | Pricing Basis | BAA Tier | Implementation | Source |
|---|---|---|---|---|
|
Not published
|
Not disclosed. Epic publishes no pricing. Whether the Sepsis Model is included in an existing Epic licence or carries additional cost is not publicly stated. | Governed by the organisation's existing Epic agreement. Unlike Epic's generative features, no third party model provider is introduced into the data path, so no subprocessor question arises here. | Not published. The model requires no integration work because it runs inside the existing record, but local validation, threshold configuration and alert workflow design are real and recurring costs that fall entirely on the institution, and the published literature recommends all three. | Vendor Published |
Epic publishes no pricing and this record contains no figure. The commercial evaluation in this category is structurally different from a normal vendor comparison and buyers should approach it deliberately. The Epic model typically arrives inside a platform already bought and is often already running, while every competitor must be procured, given a real time data feed and justified against something that appears to cost nothing. THE DECISIVE POINT IS THAT THE COMPARISON IS USUALLY UNINFORMED: the version 2 multicentre validation found high institutional variability and recommended local validation, which means an institution that has never measured its own Epic model's sensitivity, positive predictive value and lead time does not know what the competing vendor is being compared against. Establishing that baseline is the first step in any evaluation in this category, and it costs analyst time rather than licence fees. Questions to put to Epic directly: whether the model carries incremental cost or sits inside the existing licence; what version is currently running at your organisation and when it was last updated; whether Epic will supply your site's own performance characteristics; and what tuning, threshold configuration or suppression options are supported.