Wpr Epic Systems Uses AI to Address Security Flaws in Patient Data Access
Article Content
- •Epic Systems used AI to identify security vulnerabilities in patient health data access.
- •The AI tool revealed risks of undetected access and potential alterations to health records.
- •Epic has paused product development to address these vulnerabilities and is facing ongoing phishing attacks.
Epic Systems, a leading medical records vendor, has revealed that it utilized Anthropic's Claude Mythos AI to identify and patch security vulnerabilities that could allow hackers undetected access to patient health data. CEO Judy Faulkner disclosed these vulnerabilities at a recent industry conference, emphasizing the urgency of the situation. The AI tool highlighted potential risks where hackers could alter health records without detection, posing significant threats to patient safety. Epic has paused certain product developments to implement necessary patches identified by the AI. The company is also dealing with ongoing phishing attacks targeting its MyChart portal. Epic Systems manages records for approximately 325 million patients, making the implications of these vulnerabilities particularly concerning. The healthcare sector has been a frequent target for cyberattacks, with FBI data indicating a rise in ransomware attacks and data breaches in 2025.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Change Healthcare in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What specific vulnerabilities were identified?
How is Epic addressing these vulnerabilities?
Are there any known exploits of these vulnerabilities?
Continue Reading
Critical Citrix NetScaler Vulnerabilities Actively Exploited in Finland The National Cyber Security Centre Finland (NCSC-FI) issued an alert regarding critical vulnerabilities in Citrix NetScaler ADC and Gateway products, specifically CVE-2026-88771 and CVE-2026-88772, which are being actively exploited in Finland. These vulnerabilities allow attackers to execute remote code without…
Critical Authentication Bypass in Rejetto HFS Exploited Within 24 Hours Anthropic's Mythos model identified a critical authentication bypass in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, allowing remote code execution. Discovered by Horizon3 researcher Zach Hanley, the flaw was revealed on September 27, 2026, and exploitation began within 24 hours, with attacks traced to…