Epic is patching security flaws that could allow undetected access to patient records after testing its software with Anthropic’s Claude Mythos AI model, The New York Times reported.
The EHR giant found that certain software configurations could let someone view sensitive patient records without the access appearing in a digital audit trail, Epic Chief Security Officer Stirling Martin told the Times. Mythos did not determine whether an attacker could also alter records, though Mr. Martin said the testing raised that possibility.
“Whether things can be changed is more complicated, and depends on other parts of the technology and not necessarily Epic’s in that case,” Mr. Martin said in the Sept. 30 story.
Epic used Mythos to probe how hackers could use open-source AI agents to get into confidential patient records, according to the report. The company maintains records for 325 million patients in the U.S. and other countries.
Epic CEO Judy Faulkner disclosed the security weakness and a six-week plan to close the gaps at a recent industry conference, saying most new product development had been paused for the fixes. The company later said its new products remain on track.
Mr. Martin said health systems should prepare for a faster pace of fixes.
“Ultimately they need to get ready to patch, patch, patch,” he told the Times. “As soon as they think they are patching fast enough, they need to patch faster.”
Separately, criminals have been using AI to produce convincing fake MyChart emails aimed at stealing patients’ credit card numbers and login credentials, John Riggi, national advisor for cybersecurity at the American Hospital Association, told the newspaper.
Epic is among the organizations taking part in Anthropic’s Project Glasswing, which gives partners restricted access to Mythos to find and fix software vulnerabilities.