Back Wpr Epic used AI to find potential security flaws that could expose patient health records
Verona-based Epic Systems recently revealed it used an artificial intelligence tool to patch security risks that could give hackers undetectable access to patient health data — the latest in the back-and-forth between health companies and hackers in the AI era.
Epic Chief Executive Judy Faulkner revealed the security vulnerabilities and the tool’s use at a conference last month, according to The New York Times. The electronic health systems vendor used Anthropic’s Claude Mythos AI model that’s built for advanced cybersecurity and biology research.
New York Times reporter Christopher Rowland told WPR’s “ Wisconsin Today ” that the tool found bad actors could potentially access health data undetected. While the AI tool did not verify if health records could be changed, he said the ability to do so is of particular concern.
Understanding Wisconsin, Together.
WPR’s “Wisconsin Today” keeps you connected to the state you love without feeling overwhelmed. No paywall. No agenda. No corporate filter.
“Imagine if a hacker got in and changed health records to wipe away any indication that someone was allergic to penicillin,” Rowland said. “Say they did that to thousands of patients, and suddenly you have a very deadly risk embedded in your records, but you don’t know where it is because the hackers were able to do it without leaving a trace.”
Faulkner announced that Epic had paused certain new elements of product development to implement patches the AI agent identified.
Epic Systems utilizes artificial intelligence in other ways. The company created Cosmos , a data aggregation tool that examines medical records and is meant to help in clinical decision-making.
“But AI has its downside. It gives these hackers a huge leg up, so they can — with less expertise on their part and much faster — operate and make attacks on your system,” Rowland said.
AI adds new challenges to health care cybersecurity
Rahul Gomes is department chair and associate professor of computer science at UW-Eau Claire. Gomes told WPR the proliferation of AI tools have accelerated how quickly companies like Epic and attackers move on cybersecurity issues.
“In the past, we would have software vulnerabilities that an experienced researcher would spend days and weeks reading the code, testing out different configurations, trying to understand these complex systems,” Gomes said. “With AI, you know, that process has become much quicker.”
Gomes said prioritizing patient safety adds new challenges to keeping health systems secure.
“If you look at a bank, for example. A bank might shut off the system for an hour for an update. With healthcare, we can’t do that,” Gomes said. “The problems are: how do we keep it updated, and at the same time allow doctors to access these resources?”
Epic Systems controlled nearly 44 percent of the market for acute care electronic health records last year, according to KLAS Research. An analysis from Definitive Healthcare finds just three companies — Epic Systems, Oracle Cerner and MEDITECH — account for nearly 75 percent of the electronic health record market in the United States.
Gomes said there are cybersecurity trade-offs with just a few companies making up a vast majority of electronic health record systems. “Epic (is) able to use these high-end models in order to detect these attacks, which is really helpful, right? They have the resources to do this. They can standardize their process, but it also poses these problems where the weakness is that it’s the same platform. So, if an attacker can gain access to that one common platform, then it can bring everything down,” Gomes said.
“Whereas if there are different systems, then that can take some time,” Gomes continued. “(But) having access to the most up-to-date models will give the cybersecurity folks much more exposure to the variety of attacks that can happen, increasing the odds of defending the patient data from these kinds of attacks.”
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
