Records / practical guide / updated august 2026
Getting your record out of Epic and into Claude
Your hospital will hand you fourteen years of your own medical history in a format designed to be unreadable. Here’s how to fix that — and what not to trust once you have.
The one-paragraph version
Your hospital’s Epic patient portal — almost always branded MyChart — can hand you your own records in two useful shapes: a readable PDF, and a folder of machine-readable XML. You download those to a computer, decide how much personal detail to strip out, upload them, and ask specific questions. The value isn’t “diagnose me.” The value is finding what fell through the cracks: a lab that drifted, a follow-up nobody scheduled, a medication list that doesn’t match reality.
Getting the files out of Epic
First, understand what you’re dealing with
There is no single national MyChart account. Every health system running Epic operates its own MyChart with its own login. Two hospitals and an independent clinic can mean three separate portals, each holding only its own slice of your history. Some portals display records from linked systems in one combined view, but that view is for reading — it doesn’t bundle everything into one download. You export from each system separately and stitch the pieces together yourself.
Do this on a computer, not your phone. A full export arrives as a ZIP full of clinical XML, phones handle that badly, and several portals restrict the complete-record flow to the website anyway.
Path A — the fast way (5 minutes): the Lucy Summary
“Lucy” is Epic’s oddly-named portable snapshot of your whole chart — allergies, medications, current health issues, procedures, test results, immunizations, in one file. It’s the most useful self-serve download there is.
1 Main menu
2 Submenu
3 Tabs
Expires in ~30 days
Institution-specific walkthroughs, with their own real screenshots:
Cleveland Clinic,
Johns Hopkins,
Duke, and
a short video walkthrough.
Known gap
Clinical notes and after-visit summaries are generally not included in a Lucy Summary. It’s the skeleton, not the narrative. For a doctor’s actual written reasoning, you need Path B.
Path B — the complete way (a few days): request a formal copy
This is what you want for a second opinion, a move to a new health system, or building a real longitudinal record.
- Look for the option to request a formal copy of your health record. Some portals file it under a Sharing Hub, some under Record Request, some behind a release-of-information form.
- Choose everything — and if you’re offered a computer-readable format, take it. Request both that and the PDF. They serve different readers.
- Wait. Health information management prepares it, usually over a few days.
- Download it the day you’re notified. Requested copies expire — Cleveland Clinic’s MyChart holds one for about 30 days, then deletes it and you start over.
Epic’s own patient-facing page: mychart.org/Sharing-Your-Medical-Record.
Path C — the narrow way: one document at a time
Need only the latest labs or an immunization record for a school form? Open that single result and save it. Wrong tool for a complete record; right tool for a single page.
What’s actually inside the ZIP
Unzip it first. This is the folder that makes people give up and keep only the PDF.
What’s a C-CDA file, in plain English?
Consolidated Clinical Document Architecture — an HL7 standard every certified US electronic health record is required to be able to produce. Think of it as your record written in a shared language computers can parse: medications, allergies, problems, labs, vitals, immunizations, each with standardized codes attached.
The reframe that makes the folder make sense: the PDF was written for you; the XML was written for whatever reads your record next. A medical record spends its life being handed off, and you can’t know in advance whether the next reader is a person or a program. Keep both.
What the export leaves out
- Actual imaging files. The scan images usually come from radiology on a disc or a separate imaging portal. The reports are typically in the export; the pictures aren’t.
- Some clinician notes.
- Records predating your health system’s switch to Epic.
- Psychotherapy notes, which get special legal treatment.
If the portal won’t give you what you need
Federal law backs you. Under your HIPAA right of access (45 CFR § 164.524), a provider must act on a records request within 30 days — with at most one 30-day extension — and must give you an electronic copy in the form and format you ask for when it’s readily producible, charging only a reasonable cost-based fee. That right is broader than whatever button the portal happens to offer. ONC’s plain-language version: healthit.gov.
Send through portal messaging
Under my HIPAA right of access, I request an electronic copy of my complete designated record set — including visit notes, lab and imaging reports, medication and problem lists, and immunizations — in a computer-readable (C-CDA) format if readily producible.
If you’re requesting for a parent
I hold [proxy access / a signed HIPAA authorization / medical power of attorney] for [name], date of birth [DOB], and am requesting an electronic copy of their complete record on their behalf.
Read this before you upload anything
This is the part most how-to guides skip, and the part where you can actually get hurt.
Consumer Claude is not a HIPAA-covered service
HIPAA governs providers and their business associates — not you. You are legally free to share your own medical record with anyone, including an AI company. But none of HIPAA’s protections travel with the data once you upload it. HIPAA-eligible service with a Business Associate Agreement is a commercial arrangement; it does not apply to a personal Free, Pro, or Max account.
Translation: you are making a privacy trade, consciously. That may well be a trade worth making. Make it on purpose.
Check your training setting first
Anthropic’s September 2025 consumer terms update introduced a model-training choice for Free, Pro, and Max accounts. Per Anthropic’s own announcement: allowing your data to be used for training extends retention to five years; declining keeps the existing 30-day retention. Deleted conversations are not used for future training.
Go look at yours: Settings → Privacy. Don’t assume.
Sourcing conflict — worth knowing
Third-party coverage of this change disagrees with itself. Some outlets describe the toggle as opt-in and voluntary; at least one describes the pop-up toggle as pre-set to “on.” I can’t resolve which is accurate from available sources, and it may have varied by rollout. Don’t take anyone’s word for it — open your own settings and read what it says today.
Reduce what you upload
You don’t need to upload a document carrying your name, address, medical record number, insurance ID, and date of birth to get useful analysis.
Easiest method: open the PDF, copy the text into a plain text file, find-and-replace the identifiers, upload that. Tedious for a 300-page export; very doable for a lab panel or a single visit summary.
Other hygiene: use a fresh chat for medical work, delete the conversation when you’re done, and if you’re doing this for a family member, ask them first. Obvious, and routinely skipped.
Getting files in, in a form Claude can use
| Upload | When | Trade-off |
|---|---|---|
| Health summary PDF | Start here, always | Highest signal per unit of effort |
| Single lab or visit PDF | Focused questions | Narrow but fast and easy to verify |
| C-CDA XML | PDF is missing something | Verbose — eats context for little added content |
| Text file you built | Maximum privacy control | Most manual work |
If the file is too big
Export files get large fast. Limits change, so rather than quote a number I’d be wrong about: if an upload gets rejected, split by year or by category (labs / notes / imaging reports / medications), upload the PDF instead of the XML, or ask for section-by-section work with a running summary.
The XML trick worth knowing
If you have the C-CDA files and don’t want to read XML, upload one and ask for extraction first. Extraction is a good opening move because errors are easy for you to spot.
Turn XML into a spreadsheet
These are C-CDA XML files from my Epic export. Parse them and produce a clean table of every lab result: test name, value, units, reference range, date, and whether it was flagged out of range. Output as CSV. Don’t interpret anything yet — just extract.
The prompts
Ordered roughly as I’d actually run them. Copy, paste, edit.
1. Orientation — start here
Inventory before interpretation
I’m uploading my medical record export. Before analyzing anything, give me an inventory: what date range does this cover, what types of documents are included, which sections appear incomplete or truncated, and what’s obviously missing that you’d expect to see in a record like this. Don’t interpret findings yet.
Half the value of the whole exercise is discovering your record has a two-year hole in it.
2. Build the timeline
Chronology
From these records, build a chronological timeline of my medical history: diagnoses with dates, procedures, hospitalizations, and major medication changes. Where the record is ambiguous about timing, say so rather than guessing. Format as a table sorted oldest to newest.
3. Lab trends — the highest-yield analysis
Movement, not snapshots
Extract every lab result across all dates. For any test measured three or more times, show me the trend over time and flag anything that is: (a) currently out of range, (b) trending toward a reference-range boundary even while still normal, or (c) has changed more than 20% from its earliest value. Show your work as a table with actual values and dates. Do not tell me what any of this means clinically yet.
A single value in isolation is what a busy visit produces. A trend across four years is something almost nobody looks at — and it’s the thing a document-reading tool is genuinely good at.
4. The dropped-thread prompt
The one that earns its keep
Go through these records and find every instance where a follow-up was recommended but there’s no evidence in the record that it happened. This includes: radiologist recommendations for repeat imaging, referrals that were placed, tests that were ordered, “recheck in 3 months” instructions, and abnormal results with no subsequent retest. List each one with the date it was recommended and the exact text where you found it.
Why this one matters most: a 2024 NYU Langone study in JAMIA reviewed 430 emergency-department radiology reports and found that among cases with a definitely-actionable incidental finding, only 55.7% had any documentation that anyone told the patient (study). The radiologist saw it, wrote it down, and it still didn’t reach the patient in roughly 44% of cases. That’s not a diagnostic gap — it’s a communication gap, sitting in a document, waiting to be found.
5. Medication reconciliation
Cross-check the lists
Compare the medication lists across every document in this export. Show me: medications that appear in some documents but not others, dose changes over time, anything listed as active that also appears as discontinued elsewhere, and any drug pairs that are commonly flagged for interaction. Cite the specific document and date for each discrepancy.
6. Appointment prep
Questions grounded in your own history
I have an appointment with a [specialty] doctor on [date] about [issue]. Based on my records, draft five specific questions worth asking — questions grounded in something actually in my history, not generic ones. For each, note which record it comes from so I can point to it.
KFF Health News reporting found that framing matters: telling the model to take on a clinician’s persona, and asking one question at a time, improved accuracy in testing. So a useful wrapper on any of these:
Wrapper
Answer as an experienced internist reviewing a new patient’s chart for the first time. Take one question at a time and wait for me before moving on.
7. Plain-language translation
Simplify without losing content
Translate this visit note into plain English at about an eighth-grade reading level. Keep every clinical fact intact — don’t simplify away specifics like measurements, drug names, or dates. Where a term has no good plain-English equivalent, give the term and then explain it.
8. The stress test — run this on Claude’s own output
Adversarial second pass
You just told me [X]. Now argue the opposite. What in my records contradicts or weakens that reading? What’s the most likely benign explanation for the pattern you flagged? What would a skeptical specialist say?
9. The anti-invention guardrail — attach this to everything
Standing rules
Rules for this entire conversation: (1) Every factual claim about my health must quote the exact line from my records it came from. (2) If something isn’t in the records, say “not in the record” — never fill the gap with what’s typical. (3) Distinguish clearly between what my records say and what you know from medical literature. (4) If you’re unsure, say so and rate your confidence.
Use it. It’s the single highest-value habit here.
10. What to actually do next
Questions, not orders
Based on everything we’ve reviewed: what’s worth raising with a doctor at my next appointment, in priority order? For each item, tell me why it matters and what the doctor would likely want to look at. Do not recommend specific tests — frame these as questions to raise, not orders to place.
That last constraint is deliberate. Here’s why.
How this goes wrong
It will want to order tests. A lot of them.
A simulated-patient study in npj Digital Medicine ran 384 patient-AI consultations and reports an unnecessary-test rate around 92% for the primary model tested, with GPT-4o near 93% and DeepSeek R1 higher still in the same design (study). Different models, simulated rather than real patients, Chinese healthcare context — treat it as directional. The direction is unambiguous: these systems are biased toward “get another test,” and that bias costs money, causes anxiety, and generates its own cascade of incidental findings.
It can be confidently, fluently wrong
The largest real-world user study to date — Oxford’s Internet Institute and Nuffield Department of Primary Care, in Nature Medicine — found that chatbots performing well on standardized medical exams gave real users unsafe or incorrect advice, and were no more effective than traditional information sources at helping people pick the right next step (summary). Responses frequently blended good and bad recommendations in the same answer. That’s the hard part: it isn’t that it’s wrong, it’s that the wrong part is stapled to the right part.
It’s on the official hazard list
ECRI, the patient-safety nonprofit, named AI chatbots in medicine the top health technology hazard for 2026, citing confidently wrong diagnoses, invented anatomy, unnecessary or dangerous recommendations, and reinforced bias (coverage). Separately, researchers found chatbots presenting unproven treatments with roughly the same weight as evidence-based ones — “false balance” — which oncologists called actively harmful when it displaces real treatment (coverage).
Practical defenses
- Demand citations to your own record. If it can’t quote the line, treat the claim as invented.
- Ask the same question twice, in separate chats. Divergent answers mean low confidence.
- Run it past a second model. Cross-checking catches a real fraction of errors.
- Verify anything numeric yourself against the source document.
- Bring findings as questions, not conclusions. Physicians in the KFF reporting said they welcome patients showing them how they used AI — it opens a conversation. What doesn’t go well is arriving with a diagnosis.
The honest summary
This works best as a document-search and preparation tool, not a diagnostic one. The strongest published evidence supports exactly that narrow use: finding the actionable thing that was written down and never followed up. The weakest evidence — actively negative, in the controlled studies — is for “tell me what’s wrong with me.”
Upload the record. Ask it to find what got dropped. Build the timeline. Draft the questions. Then go see a person.