Epic vs Oracle Health: what the EHR duopoly means for health data trust
Epic and Oracle Health now control over 75% of U.S. hospital EHR installations, creating a duopoly where health data quality and trust standards are set by two vendors with fundamentally different architectures and business models. The concentration of clinical data in two proprietary systems does not guarantee that the data inside them is trustworthy, complete, or ready for AI.
Epic and Oracle Health (formerly Cerner) together account for more than 75% of U.S. acute care hospital EHR installations. That number is not slowing down. Every year, mid-size health systems that once ran MEDITECH, Allscripts, or homegrown platforms migrate to one of these two vendors. The result is a duopoly that determines how most clinical data in America gets created, stored, structured, and exchanged.
But market dominance is not a proxy for data trustworthiness. A record created in Epic is not inherently more reliable than one created in Oracle Health, and neither vendor solves the fundamental problem: the data inside their systems has no independent trust score.
What the EHR duopoly actually looks like
Epic holds roughly 38% of the U.S. hospital EHR market by number of hospitals and a significantly larger share by patient volume, given its dominance at large academic medical centers and integrated delivery networks. Oracle Health holds approximately 22-25% of hospital installations, with particular strength in federal health (the VA's troubled migration to Oracle Health Millennium is the largest EHR deployment in government history) and mid-market community hospitals.
Behind those two, MEDITECH holds roughly 15-16% of the market, concentrated in smaller community hospitals and critical access facilities. Everyone else, including Veradigm (formerly Allscripts), athenahealth, and niche specialty vendors, splits the remainder.
So when people ask "what are the top 3 EHR systems in healthcare," the answer is Epic, Oracle Health, and MEDITECH, in that order by installed base. But the gap between the top two and number three is enormous and growing.
Is EHR and Epic the same thing?
No. An EHR (electronic health record) is a category of software. Epic is one vendor that makes an EHR product. Conflating the two is surprisingly common, especially among patients who see the MyChart portal and assume "Epic" and "my medical record" are synonymous.
This matters for data trust because when patients believe Epic is their health record, they do not question whether the data inside it is complete, current, or correctly coded. They assume the system handles that. It does not. EHR systems are transactional platforms. They store what clinicians enter. They do not validate whether a medication list is reconciled, whether a diagnosis code matches the clinical note, or whether consent for secondary data use was properly captured.
What are the key differences between Oracle Health EHR and Epic EHR systems?
The architectural differences between these two systems create distinct data trust profiles.
Data model philosophy. Epic uses a proprietary, tightly integrated data model. Everything from scheduling to clinical documentation to billing runs on a single database architecture called Chronicles. Oracle Health (Millennium) uses a more modular architecture, with separate domains that communicate through internal APIs. This means Epic data tends to be more internally consistent but harder to extract. Oracle Health data is more modular but more prone to integration seams where data quality degrades.
Interoperability approach. Epic has invested heavily in its Care Everywhere network, which connects Epic-to-Epic data exchange with relatively high fidelity. Cross-vendor exchange (Epic to Oracle Health, for example) relies on industry standards like C-CDA documents and FHIR APIs, where data quality drops significantly. Oracle Health has been more standards-forward historically but has struggled with implementation consistency, particularly during the VA rollout.
Cloud strategy. Oracle Health is migrating aggressively to Oracle Cloud Infrastructure (OCI), which introduces new questions about data residency, access controls, and multi-tenancy. Epic remains primarily on-premises or hosted in Epic-managed data centers, giving health systems more direct control over their data but creating scalability constraints.
AI positioning. Both vendors are racing to embed AI into clinical workflows. Epic has partnered with Microsoft and Nuance for ambient documentation and is building predictive models trained on data from its customer base. Oracle Health is integrating Oracle's broader AI capabilities, including generative AI through OCI. Neither vendor publishes the trust scores or provenance chains of the training data behind these models.
Who is Epic's biggest competitor?
Oracle Health is Epic's biggest competitor in the acute care hospital market. That was true when Cerner was independent, and it became more consequential after Oracle acquired Cerner for $28.3 billion in 2022.
Oracle brought something Cerner lacked: cloud infrastructure, enterprise software scale, and Larry Ellison's stated ambition to build a national health data platform. The acquisition reframed the competition from "two EHR vendors fighting for hospital contracts" to "two fundamentally different visions for who controls health data infrastructure."
Epic's vision is a federated network where each health system owns its data but exchanges it through Epic-controlled rails. Oracle's vision is a centralized cloud where data aggregation happens at the platform level. Both visions have serious implications for data trust.
The data trust gap neither vendor addresses
Here is what the current ranking articles miss. The existing content at the top of search results focuses on market share, monopoly dynamics, and competitive positioning. None of it asks the question that matters most for health AI: is the data inside these systems trustworthy enough to train models on?
The answer, based on what we see when we score EHR-origin data through the Data Trust Index, is consistently sobering.
Provenance gaps. EHR data rarely carries complete provenance metadata. A lab result in Epic may show the ordering provider and the result value, but the chain from specimen collection to analyzer to interface engine to EHR storage is not tracked as a provenance chain. When that data gets extracted for AI training, nobody knows which steps in the pipeline introduced errors.
Consent ambiguity. Both Epic and Oracle Health store consent records, but consent for treatment is not consent for secondary data use, model training, or commercial analytics. The consent layer in most EHR implementations is binary (yes/no) rather than granular. This creates legal and ethical exposure when health systems share data with AI vendors.
Coding inconsistency. ICD-10 codes in Epic and Oracle Health are entered by different clinical teams with different documentation practices, different CDI (clinical documentation integrity) programs, and different payer pressures. The same clinical scenario coded at two different hospitals, even on the same EHR platform, produces different structured data. This is not a bug in the EHR. It is a feature of how billing-driven documentation works.
Temporal drift. Problem lists in both systems are notoriously stale. A diagnosis added during an inpatient stay in 2019 may still appear as an active problem in 2025 because nobody reviewed and reconciled the list. When AI models ingest this data, they treat resolved conditions as current, which corrupts risk predictions and cohort definitions.
Key statistics
Why market concentration makes data trust harder, not easier
Conventional wisdom says that having fewer EHR vendors should simplify interoperability and data quality. If everyone runs Epic or Oracle Health, data exchange should be straightforward.
The opposite is true.
When two vendors control most of the market, they have diminished incentive to adopt open standards aggressively. Epic's Care Everywhere works best Epic-to-Epic. Oracle Health's internal data exchange works best within Millennium. Cross-vendor exchange still relies on C-CDA documents, which are structurally lossy. We have written about this specific problem in detail: The CCD document quality problem: hidden trust failures in care summary exchange.
The duopoly also creates a false sense of standardization. Health system executives assume that because they run Epic, their data is "Epic quality." But Epic is a platform, not a quality standard. Two Epic installations configured differently, with different order sets, different documentation templates, and different interface engines, produce structurally different data. The same is true for Oracle Health.
This is why EHR data needs a trust score before any AI model trains on it. The vendor label is not a trust signal.
The interoperability illusion
The 21st Century Cures Act and the ONC's information blocking rules were supposed to force EHR vendors to open their data. TEFCA (the Trusted Exchange Framework and Common Agreement) is supposed to create a national interoperability network. FHIR APIs are supposed to make data accessible.
All of these are real progress. None of them solve the trust problem.
FHIR APIs expose data. They do not score it. A FHIR Patient resource returned from Epic has the same API structure as one returned from Oracle Health, but the completeness, accuracy, and provenance of the data inside that resource varies wildly. A medication list pulled via FHIR may be missing discontinued medications, may include duplicates from different care settings, or may use NDC codes that do not map cleanly to RxNorm.
We have covered the technical details of this problem in SMART on FHIR and the data trust surface area for third-party app access and FHIR R4 vs FHIR R5: what the version change means for data trust architecture.
Interoperability without trust scoring is data movement without data accountability.
What Oracle's cloud ambition means for centralized data risk
Oracle's acquisition of Cerner was not primarily about selling EHR software. It was about building a cloud-based health data platform that aggregates clinical, claims, and operational data at scale.
This introduces a concentration risk that did not exist when Cerner was independent. Oracle now controls the EHR application layer, the cloud infrastructure layer, and the database layer for a significant portion of U.S. health data. If Oracle builds AI products trained on aggregated Oracle Health data, the questions about data provenance, consent, and secondary use become urgent.
This is the same structural concern we have analyzed in the context of other vertically integrated health data companies. See Optum data assets and the trust question for competing health systems and CVS Health and Aetna data integration: what vertical integration means for data trust.
The question is not whether Oracle or Epic will build AI. Both will. The question is whether any independent layer exists to verify that the data feeding those AI models meets a minimum trust threshold.
What health systems should do right now
If your organization runs Epic or Oracle Health, you are not exempt from the data trust problem. You are at the center of it.
Three immediate actions:
1. Score your data before you train on it. Do not assume that because data lives in a Tier 1 EHR, it is ready for AI. Extract a representative sample and score it across provenance, consent, recency, quality, concordance, validation, breadth, and stability. The DTI framework provides a 0-100 score across all eight dimensions.
2. Audit your consent layer. Most EHR consent records cover treatment authorization, not secondary use. Before sharing data with AI vendors, analytics partners, or research collaborators, verify that your consent architecture supports the actual use cases. Binary consent is not enough for a world where data gets used in ways patients never anticipated.
3. Establish vendor-independent trust standards. Your EHR vendor should not be the entity that certifies the trustworthiness of the data inside its own system. That is a conflict of interest. Independent trust scoring creates accountability that vendor self-certification cannot.
The duopoly is not going away. Epic and Oracle Health will continue to consolidate the market. The question for health system leaders is whether they will let two vendors define what "good enough" data looks like, or whether they will adopt an independent standard that holds all data, regardless of source system, to the same bar.
SuperTruth scores incoming EHR data at the point of ingestion, before it reaches a model. If your system is deploying clinical AI and needs to answer an auditor's questions about data provenance, consent coverage, and quality thresholds, contact Louis Simeonidis at louis@supertruth.ai or (215) 918-4140.
Further reading:

Jason Alan Snyder
Co-founder of SuperTruth and Artists & Robots, and an inventor on the Data Trust Index patents. Twenty-plus years building technology inside Interpublic Group. He writes here nearly every day on data trust, provenance, and what AI should be allowed to act on, and publishes essays on his Substack.
About SuperTruth · LinkedIn · Substack · jasonalansnyder.com
See it in practice
EHR data scored before any AI model sees it.
DTI integrates with Epic, Cerner, and all major EHR systems.