The 2026 Epic Users Group Meeting (UGM) just wrapped up, and we’ve seen two main sentiments pervading nearly every article, blog post, and opinion piece about the event: 1) excitement over Epic’s rapid AI automation capabilities, and 2) anxiety over how to afford and integrate those rapid changes. One notable tool is AI Charting, which drafts visit notes and suggests orders in real time, but several new features are arriving to summarize patient histories, speed up information retrieval, and take repetitive work off clinicians’ plates. Early results from Epic organizations are overall encouraging: less documentation burden, less after-hours work, and higher clinician satisfaction.
For healthcare IT teams, this is exciting and a little daunting. Every new AI feature brings a familiar question. Is our infrastructure secure and compliant enough to run this?
If you’re a VMware Cloud Foundation (VCF) customer, the answer is yes.
Getting over the hurdles
When a health system wants to adopt Epic’s AI tools, they face two separate hurdles. The first is the AI itself. Is it accurate? Is it fair? Does it actually help clinicians? Those are clinical and governance questions for the health system’s committees, informatics teams, and leadership.
The second hurdle is the environment the AI runs in. Is the data encrypted? Is access controlled? Are there audit logs? Is it compliant with HIPAA? Can we prove it to regulators? This is where VCF does the heavy lifting.
Most of the delay in adopting new healthcare technology comes from the second hurdle, but VCF takes that hurdle off the critical path.
A pre-built, AI-ready foundation
Think of it like building a hospital wing for a new kind of surgery. You would not let clinicians start using it in an unrenovated, unequipped space. You would first need the right rooms, the right access controls, the right monitoring, and the right compliance sign-off. Only then does the new procedure become something safe to practice.
VCF is that pre-built wing. It arrives with security and compliance controls already in place: encryption that meets HIPAA standards out of the box, role-based access, network isolation between workloads, automated patching that does not require downtime, continuous compliance monitoring, and audit-ready reporting.
Faster, with lower risk
The pressure to adopt these tools quickly is putting strain on teams that are still trying to qualify and evaluate which tools will make the biggest impact. The necessary reviews can take a long time, but when the infrastructure underneath is already built to support those workloads and integrations securely, the team can focus on qualifying the AI tool’s fit and ROI.
Risk in healthcare IT comes mostly from data exposure and operational disruption. VCF addresses both. Protected health information stays within the organization’s own environment, especially when Epic runs on-premises. Features such as live patching and redundant storage keep the EHR and its new AI features available even during maintenance, so the team doesn’t have to trade security for speed. They get both from the same foundation.
The Bottom Line
VCF takes the “is our infrastructure secure and does it support compliance enough to run AI?” question off the table so teams can focus on evaluating which AI capabilities are even worth using.
For VCF customers watching Epic’s AI roadmap, that is genuinely good news. The foundation is ready, so the conversation can move straight to the work that matters: getting these tools into the hands of clinicians safely and quickly.
P.S. If You’re Building Tools Yourself…
If part of your AI strategy includes building your own fit-for-purpose applications and GenAI tools, take a look at this four-part series, Hands-on Guide to Secure Private AI with Broadcom.
Discover more from VMware Cloud Foundation (VCF) Blog
Subscribe to get the latest posts sent to your email.