# Epic's AI rollout
Epic unveiled a wave of clinician-facing AI features at its 2026 Users Group Meeting—tools that draft visit notes, suggest orders, summarize patient histories, and speed up information retrieval. Early adopter sites report reduced documentation burden, less after-hours work, and improved clinician satisfaction. Those clinical results are encouraging but they raise a familiar question for IT teams: is our infrastructure secure and compliant enough to run this?
If your organization uses VMware Cloud Foundation (VCF), the infrastructure answer is effectively yes. VCF arrives with a set of controls and operational capabilities aimed at meeting healthcare security and compliance needs out of the box, which shortens the time IT must spend preparing platforms for Epic AI workloads.
# Epic AI
VCF includes technical controls commonly required for protected health information and regulated environments:
- Encryption that meets HIPAA expectations by default.
- Role-based access controls to limit who can view and act on PHI.
- Network isolation between workloads to reduce lateral exposure risks.
- Continuous compliance monitoring and audit-ready reporting to support regulators and internal audits.
- Automated, non-disruptive patching and redundant storage to keep EHR and AI features available during maintenance.
Those elements address the second major hurdle organizations face when adopting Epic's AI: the environment the AI runs in. The first hurdle—clinical questions about accuracy, fairness, workflow fit, and ROI—remains a governance and informatics responsibility for each health system.
# How this changes the project timeline and focus
Concretely, that means teams can spend less time building or validating encryption, access controls, and audit trails, and more time on
- testing AI outputs against clinical standards,
- running clinician usability pilots,
- measuring documentation and workflow impacts, and
- calculating ROI and staffing effects.
Operational risk is also lower. Live patching and built-in redundancy reduce the chance that maintenance will disrupt clinicians using the EHR and its AI features. Protecting PHI remains the organization's responsibility, but keeping PHI inside an on-premises VCF deployment or similarly controlled environment limits data exposure risks compared with some external hosting models.
# Bottom line for health system leaders
VCF does the heavy lifting on infrastructure compliance and operational availability so IT and clinical leaders can focus on whether Epic's AI features improve care and clinician workflows. The infrastructure question—one of the most time-consuming hurdles in new EHR deployments—is largely off the critical path for VCF customers. That clarity shortens evaluation cycles and helps get useful AI features into clinician hands faster and with lower operational risk.
# Practical next steps for teams
- Confirm your VCF deployment's configuration aligns with your organization's compliance policies and Epic's integration requirements.
- Prioritize clinical governance work: evaluation protocols, safety checks, and pilot designs for AI features.
- Plan change management and clinician training so early adopters can test and report on real-world impacts.
Those steps keep the work focused on clinical value while VCF handles the underlying security and availability requirements.