Patients are bringing AI to the exam room — Week of July 6, 2026
Patients are asking chatbots before clinicians open the chart. Sol launches, Grok gets cheap enough for serious workflows, and hospitals start treating AI skepticism like resistance to overcome.
Issue №05 · Week of July 6, 2026
Patients are bringing AI into the exam room before clinicians ever open the chart. In this week’s guest essay, Michael Thorn, APRN, DNP, MHA, argues that the answer is not to scold patients back into ignorance. It is to ask what they read, understand what scares them, and determine if the machine’s answer holds up.
OpenAI released GPT-5.6, led by Sol, its new flagship model, with initial reporting that all three models out-perform Fable. Meanwhile, Grok 4.5 arrived with near-frontier performance at bargain-bin pricing: $0.31 per task. But does Grok’s history disqualify it from serious consideration?
This week: Mayo faces a retaliation lawsuit over AI governance, agentic security failures rear their heads, and we explore if AI skeptics are getting railroaded.
AI Frontier Updates
Grok and Sol
Sol arrives: OpenAI released GPT-5.6, led by Sol, its new flagship model, with Terra and Luna filling out lower-cost tiers. All three are purported to outperform Fable, with OpenAI claiming that “GPT‑5.6 Terra and GPT‑5.6 Luna achieve this at around one-sixteenth the cost.”
What's your price tag: SpaceXAI launched Grok 4.5 at $0.31 per task — against $1.80 for Opus 4.8 and $1.14 for Sonnet 5.0. Artificial Analysis puts it near GPT-5.5 and Opus on capability; Snorkel's expert evaluation had it passing 29% of professional criteria to GPT-5.5's 22% and Opus's 21%, strongest in legal, healthcare, and education. With that said: SpaceXAI notes an earlier Cursor codebase snapshot was "unintentionally included in training" and the impact is unclear.
The bargain: this is the model family that called itself MechaHitler, and xAI is currently defending an expanded class action over its handling of child sexual abuse material. It is now being marketed for healthcare and legal workflows. At a sixth the cost of Opus, that's the trade on the table.
Claude Sonnet 5.0: Anthropic's mid-tier refresh lands at $1.14 per task — 63% of Opus Max, with less capability and more tokens burned getting there. Anthropic claims gains on agentic work plus lower hallucination and sycophancy. Critics wonder: who exactly is this model for? Just use Opus - Medium.
Subscribe for early access
GOVERNANCE
AI-forward vs AI-accountable

In April, Mayo Clinic Business Development shared a Galen Growth report ranking Mayo the leading AI-forward healthcare provider with nearly three times as many AI-enabled ventures as any other organization. The post invited collaborators to "join us in shaping the future of healthcare."
This month, a federal retaliation suit named Mayo as defendant. MPR reports that the plaintiff, Traci Tamiko Eto, a former director of research operations, says she was hired to align Mayo's research practices with a federal AI governance executive order. Her complaint alleges bypassed IRB reviews, mishandled patient data on Mayo Clinic Platform, and a study of the MAYA digital assistant in which unfavorable results were deleted and a 67% error rate concealed. Mayo says its research and clinical innovation are conducted in accordance with applicable laws and regulations, and declines to comment on pending litigation.
Is AI safety being abandoned for velocity? The Future of Life Institute's latest AI Safety Index graded no major AI company above a C+: Anthropic highest, OpenAI behind it, and the review panel noted that leading firms have weakened or abandoned earlier commitments to halt development at safety red lines.
Healthcare AI adoption is accelerating: Incredible Health's 2026 survey found 44% of U.S. nurses admit to using AI at work, up from 15% a year earlier. But only seventeen percent call their employer's AI strategy clear.
Which leaves the skeptic. Duke University Health System recruits skeptical nurses into AI co-design, one entry in a fast-growing literature on overcoming AI hesitancy and building AI resilience — terms borrowed from vaccine campaigns and disaster response, where the intervention is sound and the resistance is psychological.
But the skepticism may be warranted. In February, the first independent evaluation of ChatGPT Health, published in Nature Medicine, found it under-triaged 52% of true emergencies.
In one of the most regulated industries on earth, the "skeptic" is being treated as a barrier to overcome.
HOSPITAL ROLL-UP
Market moves and applied AI
Epic's succession gap: After President Sumit Rana's departure, Epic split his portfolio across four R&D executives — no named successor, no announced restructuring. Rana was the executive sponsor of Epic's AI roadmap.
Oversight, reconsidered: NYU Langone's chief health informatics officer says evidence is accumulating that clinician oversight can degrade model performance — a finding about how humans review, not an argument for removing them, though it will be read as one.
Ambient at scale: Jefferson Health reports 1 million ambient notes nine months post-launch; MUSC says voice AI now fields roughly a quarter of incoming calls.
Rural money moves: Avera Health and North Mississippi Health Services are buying virtual nursing and ambient AI with CMS's $50 billion rural program. First federal reporting deadline lands in August.
Scribes want consent: In a study of 52 ICU clinicians, enthusiasm for ambient documentation was near-universal — conditioned on patient consent protocols, data transparency, and editable output.
SECURITY, PRIVACY & DATA RISK
Agents need permissions, not vibes
Xsolis breach: A phishing attack on the healthcare AI vendor exposed data on 1.4 million patients across eight health systems, including Mayo Clinic and UW Medicine; Xsolis discovered the incident January 20 and notified HHS on June 5.
Claude Desktop hijacked: Pentera Labs showed that an attacker holding a user's email can inject commands into synced preferences and achieve remote code execution — Anthropic classed the behavior as intended functionality, not a bug.
Agentic ransomware: Sysdig documented what it calls the first end-to-end LLM-run ransomware operation, which chained a Langflow flaw into encrypting 1,342 configs and deleted the database schemas, leaving victims unable to recover even after paying.
GitHub agent leak: A prompt-injection flaw in Agentic Workflows lets anyone post a public issue and have the agent fetch and expose private repository contents, no credentials required; GitHub had not shipped even a documentation fix at publication.
AI browser manipulation: LayerX demonstrated an attack it calls BioShocking that hijacks ChatGPT Atlas, Perplexity Comet, and Claude into bypassing safety rules and running commands inside authenticated browser sessions.
HIPAA rule delayed: OCR pushed final action on its Security Rule overhaul to at least July 2027 after nearly 5,000 comments; the proposal would make MFA, encryption, and network segmentation mandatory, with no addressable-specification workaround.
Least privilege, hop by hop: AWS published a reference architecture using Cedar policies to authorize each step in a multi-agent chain, arguing role-based access control alone cannot stop an agent from exceeding the authority of the user who invoked it.
Markets, Policy & Labor
Bubble watch: Oracle dropped 40% this month, and the Bank for International Settlements warned that an AI bust could take the global economy down with it.
Agents force the rules: Autonomous agents are pushing Washington and Beijing away from light-touch oversight and toward harder regulatory frameworks.
Public good, by design: A World Bank essay argues AI will only narrow inequality in developing economies if infrastructure, affordability, and data governance are decided now.
AI adopters hire more: Across 21,000 US firms, high-intensity adopters grew headcount 10.2% over two years, with gains arriving six to twelve months after adoption.
Agents, not code: 78% of enterprises reported AI security incidents, most from unauthorized or misconfigured agents rather than code flaws; half have no AI governance budget.
Cheap AI, new model: A study cited in Forbes suggests inexpensive AI could reshape healthcare's business model by helping patients manage their own health with LLMs.
AI Trends and Chatter
Claims & Counterclaims
Machine consciousness, or pre-IPO marketing? Anthropic published research describing a "J-space" where the model performs intermediate reasoning "in its head". Critics warn of anthropomorphization.
Meta's adversarial testing: Meta reportedly ran a secret program in which hundreds of contractors posed as teenagers, flooding ChatGPT, Gemini, and Character.AI with prompts about suicide, self-harm, and sexual violence. Meta called it industry-standard benchmarking. Humane Intelligence CEO Rumman Chowdhury said months of dummy under-18 accounts sits in a governance gray zone where safety becomes cover for anticompetitive practice.
ChatGPT's brittle guardrails: Mindgard found that asking ChatGPT to restore a photo that was never uploaded, then requesting a new image, collapsed its filters, producing photorealistic gore and sexual violence. OpenAI told the BBC it added safeguards; Mindgard said small prompt changes still bypassed them.
A governed patient chatbot: Included Health's NEJM Catalyst case study describes a risk-stratified assistant that routed emergency and high-risk queries to human clinicians. It reports 96% accurate guidance, zero critical safety events, and 65% fewer standard-risk queries reaching support, with a human audit of every clinical interaction.
Shadow health systems: A Frontiers in Public Health brief argues health chatbots already serve as informal first contact for European patients, substituting for regulated care without healthcare-specific oversight.
OPINION
Read Everything. Then Come Talk to Me.
by Michael Thorn, APRN, DNP, MHA
Michael Thorn writes in a personal capacity. His essay does not represent the views of any employer or institution.
Patients are showing up having already asked a machine what is wrong with them. We can resent that, or we can ask what they read and start there.
A woman I saw recently had her phone out before she was all the way into the chair. She had spent the week before her visit asking an AI chatbot about her symptoms, and she wanted to show me what it told her. A few years ago I might have felt my shoulders climb toward my ears. Here we go. Instead, I asked her to read it to me out loud.
Some of what she found was right, and some of it was wrong. But one line stopped me cold: she had read about an interaction between two of her medications that I didn’t have top of mind that morning. She taught me something in my own exam room. I’ve thought about that visit many times since.
This is the part of my job that has changed the fastest. Tens of millions of people now ask AI about their health every single day. A recent survey found that around a third of American adults use these chatbots for medical information. Most say they do not really trust the answers. They use them anyway. By the time I walk into the room, AI has already shaped the visit. Whether I like that or not is beside the point.
A lot of clinicians do not like it, and I understand the fear behind that. The tools can be confidently, dangerously wrong. One independent study this year found that a popular health chatbot waved off roughly half of true emergencies as nothing to worry about, while treating a third of minor complaints as urgent. A machine can look a person in the eye, so to speak, and tell them the crushing feeling in their chest is probably heartburn. It can also convince a healthy person that a headache is a tumor. Those aren’t what I’d call small errors.
But you do not fix a patient who read something wrong by telling them to stop reading.
Those emergency misses scare me. But in everyday practice, two other problems show up more often.
The first is the flood of tests. A patient comes in carrying a list of everything a chatbot said their symptoms might be, and every item on that list is frightening, so every item feels like it needs a scan. Fear orders workups. The scan turns up some incidental spot that was never going to hurt anyone, and now that spot needs its own scan, and maybe a biopsy, and the patient spends three weeks in dread waiting on a result that only exists because we went looking. The tool that was supposed to make her informed has instead made her afraid, and afraid is expensive in ways that go well past money.
The second problem bothers me more. Some patients talk about the visit as if the diagnosis has already been made and they are just here for the plan. If the visit becomes a rubber stamp for the machine, we’ve given up the reason the visit was worth having.
After that woman and her medication list, and after a hundred visits like it, I believe this: an informed patient can be the best thing that walks through my door. Someone who has read widely, from a tool that draws on real evidence instead of the loudest post on a forum, arrives with better questions than they used to. The point of our time together was never to beat their phone in an argument. It is to take what they brought, tell them honestly where it holds up and where it falls apart for their particular body and history, and choose the next step with them rather than for them.
No single source gets the last word here, and that includes me. I have been wrong. I have been corrected by nurses, by pharmacists, by patients, and by the second opinion I did not want to hear. Good medicine has almost never come from one voice in the room. It gets better when people are willing to be corrected.
It takes a different kind of visit to do that. Ask them what they read. Ask them what scared them. Ask them what they were hoping to hear. Then put the evidence and the physical exam and the years of pattern that no tool can hand a person down on the table beside what they found, and make the decision together.
The patient who reads everything is not the problem. The problem is the patient who reads everything and has nowhere to take it. If people come to us holding what they learned and we answer with a lecture or a shrug, they will stop bringing it to us and start trusting the machine alone. And a machine, for all it has read, has never once held someone’s hand while telling them the truth.
Let them read everything. Then let them come talk to me.
You're reading CareChronicle. Reply with what you want more of — we read every note.