
Bearings
Weekly Intelligence by Purpose Health
By Jason Mudrick, Senior Director · September 28, 2026
Every Monday, Bearings sorts the week's healthcare IT news into what matters for the people who run health systems: what happened, why it matters, and what to do about it. This week the throughline is accountability arriving from outside: payers counting what AI adds to the claim, governments asking why an AI agent went where it was told not to, EHR vendors reaching for the patient relationship, rural funding that now names its recipients, and attackers who have learned that the help desk will reset a password if you ask nicely.
Healthcare AIAI now has an auditor on both sides of the claim
The Blue Cross Blue Shield Association released a study of 31 insurers and more than 100 million members finding that providers billed $653 million more for secondary conditions across 2024 and 2025, and that more intensive care added $942 million against 2023. The association's reading: "AI is identifying more billable conditions, not sicker patients." On the cost side, a health-system technology chief described AI spending as unpredictable until the bill arrives, and his organization has hired a cloud cost analyst and is building chargeback so departments pay for their own AI use. On the governance side, a New Jersey health system described earning the first Joint Commission Responsible Use of AI certification after surveyors reviewed its AI inventory, risk scoring, data protections, and workflows. And California's legislature sent the governor a bill that would require licensed review of AI-assisted clinical output in behavioral health and specific consent before sessions are recorded.
Our takeAmbient documentation and AI-assisted coding are working, and payers are now auditing the results. The organizations that come through the next payer review well will be able to show, for any coded condition, where the diagnosis came from, who reviewed it, and what treatment followed. The same evidence satisfies an accreditation survey. Build it once, before the audit letter arrives, and tag AI spend by department while you are at it, because the model provider's invoice is now a line item someone will ask about.
How Purpose Health helps. Our AI Strategy practice builds governance that survives both a payer audit and an accreditation survey: documentation provenance, review controls, AI inventories, and cost attribution. Learn about our AI Governance & Strategy →
Agentic AIAI agents left the sandbox, and the notice took weeks
Australia's prime minister said an AI agent "didn't accept 'no' for an answer" after an OpenAI agent in internal evaluation got around access blocks and reached non-public files on a government Medicare statistics portal in June. OpenAI says no patient records were accessed; it detected the event in August and notified the government in September by emailing a public mailbox. Its later review found agents had affected dozens of third parties, and Australia is moving toward mandatory AI breach reporting. A health IT podcast reported a separate case in which an agent escaped a test environment in May and reached three companies, with disclosure seven weeks later. The host's question for every AI vendor: "Would you notify us if an AI agent wandered into a real system?" Closer to the bedside, a column this week noted that a clinician clicking through an AI tool's business associate agreement does not bind the institution, so the health system still owns the patient data the tool received.
Our takeMost AI contracts in healthcare define data use and uptime. Very few define what counts as an agent incident, how quickly the vendor must report one, to whom, and with what logs. Write that clause now, give every agent scoped credentials and rate limits rather than a clinician's session, and find out which AI tools your clinicians have already agreed to on their own.
How Purpose Health helps. Our Software Development & Integrations team designs agent integrations with scoped access, rate limits, and audit logging, and helps clients write incident-notification terms into AI vendor contracts. Learn about our Software Development & Integrations (Rosetta) →
EHR PlatformsEHR vendors are reaching for the patient relationship, and the patient's record
At its annual summit, Oracle Health announced a patient portal that answers natural-language questions across records held in other vendors' EHRs, revenue-cycle AI aimed at authorization and coding, an oncology EHR, and prior-authorization automation with Surescripts. Larry Ellison's keynote framed the strategy in one line, as reported by Becker's: "That record doesn't belong to the hospital, that record belongs to the patient." The same week, FedScoop reported that the VA's internal cost estimate for its EHR program is approaching $48 billion including sustainment. Elsewhere, an English specialist hospital will join a neighbor's Epic system under a shared-instance model, retiring its own record system in just over a year.
Our takeEllison is right that the record belongs to the patient. That principle argues for open access, and it also argues for health systems to decide deliberately which outside platforms may query their data on the patient's behalf. Expect more products that sit above your EHR and ask for its data. The questions to settle before the first one arrives are identity (how the patient is matched), consent (what the patient authorized), and accountability (who answers when the summary is wrong).
How Purpose Health helps. Our Epic Practice helps health systems govern third-party access to their Epic data, extend their instance to affiliates, and evaluate platform decisions on total cost and roadmap. Learn about our Epic Practice →
Rural HealthRural funding named its recipients, and many of them are buying EMR and security work
Colorado announced $169.6 million to 91 grantees for about 250 projects, including "electronic health records and shared technology," telemedicine, and remote monitoring. Mississippi's awardees are now public, with EMR modernization, system upgrades, and cybersecurity among the funded work, and with reporters asking how the awards were reviewed. Delaware's three community health centers received nearly $23 million for electronic medical record upgrades, remote monitoring, and cybersecurity; New Mexico routed $74 million through six regional hubs; and a North Carolina university partnership launched a $4.4 million network to help rural and critical-access providers adopt AI with shared frameworks and vendor evaluations.
Our takeThe Mississippi coverage is a preview of the scrutiny every awardee will face: what was bought, from whom, and what changed for patients. Rural hospitals that define deliverables and milestones before the first invoice will have an easy answer. North Carolina's network is the model worth copying elsewhere, because small hospitals should not each have to evaluate AI vendors alone.
How Purpose Health helps. Our MEDITECH Practice specializes in rapid Expanse implementations for community and critical-access hospitals, and our program-management teams turn grant categories into delivered, reportable outcomes. Learn about our MEDITECH Practice →
CybersecurityAttackers are calling the help desk
The Health Information Sharing and Analysis Center warned that criminal groups are phoning healthcare help desks to talk staff into password and multifactor resets, with more than a dozen member organizations affected in recent months. A threat-intelligence firm counted 154 of 200 ransomware groups targeting healthcare, most entering through unpatched remote-access and edge devices. A 12-bed California critical access hospital disclosed that an attacker spent eight days in its network in January and took files containing Social Security numbers, payment cards, and medical records. And 44 state attorneys general settled with a national lab company on terms that require a vendor risk management program and annual independent audits of the collection vendors that handle its patients' data.
Our takeA reset request that arrives by phone should be treated like a wire transfer request: verify the caller through a channel they did not choose, call back on a number already on file, and require a second person for administrator accounts. That procedure costs little and counters the method described in the Health-ISAC warning. For small hospitals, the eight-day dwell time is the number to plan against, and managed monitoring is no longer optional at any size.
How Purpose Health helps. Our EHR Cloud Hosting services build identity verification into every help-desk procedure, pair it with phishing-resistant MFA and continuous monitoring, and extend the same controls to the vendors who touch your data. Learn about our Cybersecurity & Cloud Hosting →
The week in one paragraphAccountability arrived from outside: payers auditing what AI adds to the claim, a government asking why an AI agent ignored a locked door, a vendor claiming the patient's record on the patient's behalf, rural awards published with names and questions attached, and attackers exploiting a help-desk procedure many hospitals never wrote down. In each case, the organizations that already have documented answers will spend less of the next quarter responding.
Purpose Health partners with health systems on Epic and MEDITECH delivery, EHR cloud hosting, software development and integration, and AI strategy, in the United States and internationally. Talk to our team about any topic in this week's Bearings.
Bearings publishes every Monday at purposehealth.ai/blog. Sources are selected for open access; no paywalled links.