HeadlinesBriefing favicon HeadlinesBriefing.com

AI Tool Exposes Flaws in Epic Systems Patient Privacy

New York Times Business •
×

Epic Systems, the nation’s largest medical records vendor relied on by thousands of hospitals, is using artificial intelligence tools to patch security risks that could give hackers undetectable access to patient health data. Judy Faulkner, Epic’s chief executive, revealed the weakness and a six-week plan to shore up gaps at an industry conference last week. Epic deployed Anthropic’s Claude Mythos artificial intelligence agent to stress-test its systems and hunt for ways hackers could unlock confidential patient records.

The security weaknesses pose a particularly acute threat for Epic, which maintains records of 325 million patients. The company is developing intelligent tools to help hospitals and researchers, while hackers employ AI in an accelerating cybersecurity arms race. Epic has also been dealing with a phishing scam targeting users of its My Chart portal. Health networks were the most frequently targeted in 2025 of all critical sectors, with 460 ransomware attacks and 182 data breaches, according to F.B.I. data.

Using Mythos, Epic learned that certain software configurations might permit someone to see sensitive patient records without the intrusion being reflected in a digital audit trail, Stirling Martin, Epic’s senior vice president and chief security officer, said. Although Mythos did not determine whether a hacker could alter records, the test raised such a possibility. Unless defenses are built, entering and changing patient records would represent a dangerous new frontier.