Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

Epic’s Security Reckoning: How AI Uncovered Flaws in Systems Holding 320 Million Patient Records

Дата публикации: 02-10-2026 22:52:17

Epic Systems paused most product development for six weeks after Anthropic's Mythos AI uncovered security flaws in MyChart that could allow undetected access to patient records. The vulnerabilities affect configurations used across systems holding data for over 320 million patients. CEO Judy Faulkner and security chief Stirling Martin detailed the risks, highlighting an arms race where AI aids both defenders and attackers. The move underscores mounting pressures on healthcare technology providers.

Основное содержимое страницы с новостью.

Epic Systems commands a commanding share of U.S. hospital records. Its software runs the daily operations for thousands of providers. Yet last month the company took an extraordinary step. It halted most new product work. Engineers shifted focus to close security gaps that could let outsiders view patient data without a trace.

The trigger came from an artificial intelligence tool. Anthropic’s Mythos model, part of a broader cybersecurity project, scanned Epic’s codebase. It surfaced vulnerabilities missed by human reviewers. Judy Faulkner, Epic’s founder and chief executive, disclosed the issue at Modern Healthcare’s Leadership Summit on Sept. 22. She said the security sprint would last about six weeks. Modern Healthcare first reported her remarks.

Faulkner didn’t mince words. “You worry that after a month and a half of working almost primarily on safeguarding the software, that new things will be created by those who are trying to bust the software, and it will be in a never-ending cycle.” Her concern reflects a growing reality. Attackers now wield the same AI capabilities that defenders use. Speed matters. And health data commands high value on the black market.

Stirling Martin, Epic’s chief security officer, offered more specifics to The New York Times. Some customer configurations of MyChart, the patient portal tied to Epic’s records system, could permit access to records. No log entry would record the intrusion. The AI model stopped short of confirming whether records could be changed without detection. Still, the risk justified immediate action. “These are not obvious issues,” Martin had told an audience at Epic’s August users group meeting, “but the nuanced interplay between unrelated parts of the software.”

Short pause. Big implications.

MyChart supports more than 320 million patient records across hospitals and clinics. Epic itself does not store the medical data. Providers do. But a flaw in the software that millions rely on creates widespread exposure. Hospitals already grapple with ransomware and breaches. Recent incidents at Change Healthcare, CareCloud and others have strained operations and eroded trust. A silent access bug in core record systems would amplify those fears.

Epic’s decision stands out. Software giants rarely broadcast development freezes. Faulkner estimated hundreds of projects went on hold. The company later clarified its broader roadmap remains on track. AI features, Agent Factory, EpicOps and interoperability tools for prior authorizations continue advancing, an Epic spokesperson told Fierce Healthcare. Product development would slow but not stop entirely. The message aimed to reassure hospital IT teams who schedule upgrades around Epic’s releases.

Yet the episode reveals tension at the heart of modern health technology. Providers demand constant innovation. Regulators and patients demand ironclad privacy. AI accelerates both. Mythos belongs to Project Glasswing, an initiative that pairs major tech firms with organizations protecting critical infrastructure. Epic participated. It turned the offensive-style AI against its own code. The model found issues at a pace far beyond traditional reviews.

Martin had previewed this approach at the users meeting. “We’re moving fast because speed is the whole game now, and these tools have given us a head start.” He warned customers to expect more urgent security patches. The surge in critical fixes isn’t unique to Epic. Across software, AI-driven discovery has increased the volume of patches this year.

Faulkner has built Epic into a quiet giant. The Wisconsin-based company rarely seeks the spotlight. Its systems power some of the country’s most prestigious medical centers. MyChart lets patients see lab results, message physicians and manage prescriptions. Convenience carries risk. When configuration errors combine with software gaps, the patient portal becomes an entry point.

But the company insists it caught the problems first. No breach has been reported. No evidence of exploitation surfaced. That fact offers cold comfort. In cybersecurity, unknown unknowns dominate. The decision to pause development signals Epic believes the flaws demanded total focus. Resources diverted. Timelines stretched. Hospital administrators now recalibrate their own plans.

And the cycle Faulkner fears? It feels closer than ever. Hackers experiment with open-source AI agents. They probe for exactly the kinds of stealth access Mythos identified. Health systems sit on valuable data troves. Ransomware groups have shown they will lock records and demand payment. Undetected access raises the specter of silent theft or manipulation. Medical decisions based on altered data carry life-or-death consequences.

Industry watchers note the rarity of such a public pause. TechCrunch highlighted how unusual it is for a vendor of Epic’s scale to redirect most development toward remediation. The move buys time. It also buys credibility if regulators or plaintiffs later question diligence. Yet it underscores dependence. When the largest electronic health record provider hits the brakes, the entire delivery system feels the jolt.

Faulkner and Martin have emphasized partnership. Health system IT teams must apply patches quickly. They must review configurations. The vulnerabilities involved customer-side settings as much as core code. Responsibility spreads. Epic provides the platform. Providers secure the instances. That division has long defined the market. Now it faces fresh scrutiny.

Recent coverage shows the story gaining traction. On Oct. 2, multiple outlets picked up the details, linking the AI discovery directly to the development halt. Discussions on X reflected concern mixed with resignation. Healthcare has become a prime target. AI only intensifies the arms race.

Epic says its core AI and interoperability agenda stays intact. The security work runs in parallel. Six weeks from late September points toward early November for resumption at full speed. By then, patches should be deployed. Customers will receive updates. Logs will tighten. Configurations will harden.

The episode offers a case study. AI can defend as powerfully as it can attack. Deployed internally, it exposed subtle flaws in a vast codebase. Hundreds of millions of lines. Nuanced interactions. Human teams alone might have missed them for years. Yet the same technology arms adversaries. The never-ending cycle Faulkner described isn’t speculation. It’s the present reality.

Hospitals will watch closely. So will policymakers. Patient data privacy sits at the center of debates over health technology. Any perception of weakness invites tighter rules or lost confidence. Epic’s transparency, however calibrated, sets a tone. It paused. It fixed. It explained. The test now lies in execution. And in whether the fixes hold against the next wave of AI-assisted threats.

One thing is clear. In health records, security is no longer a feature. It defines the product. When the dominant player redirects its energy there, the message echoes across the industry. Protect first. Innovate after. The patients whose data fill those systems deserve nothing less.

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1Medical records giant Epic pauses product development to fix security bugs that risk patients’ data06.5502-10-2026
2Anthropic Turns Its Secret AI Weapon on Open Source Vulnerabilities015.1709-10-2026
3OpenAI pauses training of advanced AI models over safety concerns — Axios010.3827-09-2026
4OpenAI pauses most powerful AI training after thousands of sandbox escapes uncovered09.9427-09-2026
5AI giants probing tens of thousands of security incidents – Axios09.8327-09-2026
6OpenAI: Konzern pausiert KI-Training nach erneutem Sicherheitszwischenfall014.9327-09-2026
7OpenAI, Anthropic CEOs called to appear at Australian AI probe over health database breach09.8328-09-2026
8Новую модель ИИ не выпустили из-за рисков для безопасности. Что пишут СМИ09.4529-09-2026
9OpenAI apologies for Australian government website hack, pledges to rebuild trust07.0329-09-2026
10OpenAI hack sparks further concern over AI models going rogue07.0128-09-2026

Классификация: Наука. Схожих патентов: 0. Схожих новостей: 10. Тональность: 0. Информативность: 9.04. Источник: www.webpronews.com.