News
Epic UGM 2026: AI governance tools, small-system accelerators, and new security capabilities take center stage
At its annual Users Group Meeting on August 19, Epic showcased new AI governance dashboards that let health systems monitor model accuracy and usage across their deployment, dedicated accelerator programs for smaller and independent practices, and enhanced cybersecurity capabilities including AI-assisted anomaly detection for unauthorized access patterns.
- Epic
- EHR
- UGM
- AI-governance
- cybersecurity
- small-systems
Three things from Epic UGM worth tracking.
The AI governance dashboard is the most substantively important. Health systems running Epic’s AI features at scale — ambient documentation, sepsis predictors, deterioration alerts — have been flying partly blind on whether individual models are drifting or misfiring post-deployment. The new dashboard surfaces accuracy metrics, usage volume, and override rates by department and provider, giving governance committees something to actually review rather than asking vendors for quarterly reports. This directly addresses the Joint Commission’s emerging RUAIH framework requirement that organizations demonstrate ongoing monitoring of AI performance.
The small-system accelerators reflect a competitive dynamic: Meditech and other mid-market EHR vendors have been positioning against Epic in the independent-hospital segment partly on the argument that Epic’s AI roadmap is built for complex academic medical centers and arrives late (or never) for smaller systems. The accelerator programs — pre-configured AI feature bundles, simplified implementation pathways — are Epic’s counter. Whether the implementations are actually simpler or just simpler to sell is the thing to watch in community-hospital deployments over the next 12 months.
The cybersecurity AI capability is table stakes rather than differentiator at this point, but the integration of anomaly detection into the EHR access log is a meaningful convenience. Health system security teams don’t love managing another vendor console; having the unusual-access flags surface inside the platform clinicians already use for audit is the right architectural choice.
Primary source: Read the full original on Healthcare IT News ↗