CRBC News
Security

Epic Systems' AI Security Probe Finds Risk Of Undetected Access To 325M Patient Records

Epic Systems' AI Security Probe Finds Risk Of Undetected Access To 325M Patient Records
Epic Systems used AI to find security flaws that could expose patient records hero image

Epic Systems used an Anthropic AI model to test its software and found configurations that could let unauthorized users access patient records without triggering audit logs. The vulnerability affects Epic's platform, which holds records for about 325 million patients, and prompted a six-week remediation plan announced by CEO Judy Faulkner. Epic conducted the work through Anthropic's Project Glasswing; security experts warn the flaw undermines data integrity while Epic also confronts an AI-driven phishing campaign. Healthcare led critical infrastructure cyberattacks in 2025, underscoring the urgent need for faster patching and stronger defenses.

Epic Systems used an Anthropic artificial intelligence model to probe its software and discovered configurations that could allow unauthorized users to view patient records without generating alerts in the system audit trail, the company told The New York Times.

What Epic Found

The issue affects Epic's platform, which holds medical records for roughly 325 million patients in the U.S. and abroad. Epic Chief Security Officer Stirling Martin said the testing raised the possibility that an attacker could also alter records, although the Anthropic model did not demonstrate that capability directly. "Whether things can be changed is more complicated, and depends on other parts of the technology and not necessarily Epic's in that case," Martin told The New York Times.

How The Evaluation Was Conducted

Epic ran the assessment through Project Glasswing, an Anthropic program that lets participating organizations run the Claude Mythos model against their own code to uncover and remediate vulnerabilities, Fierce Healthcare reported. Anthropic announced 50 initial partners in April and expanded the program in June to include organizations across healthcare, power, water, communications and hardware sectors.

Response And Remediation

CEO Judy Faulkner disclosed the security gap at an industry conference and announced a six-week remediation plan. She initially said much new product development was paused to address fixes; Epic later clarified its broader product roadmap remains on track. Martin warned customers to prepare for a faster cadence of security updates: "Ultimately they need to get ready to patch, patch, patch. As soon as they think they are patching fast enough, they need to patch faster," he told the Times.

Related Threats And Context

Security experts say a flaw that permits silent, undetected tampering with patient records undermines the foundational trustworthiness of digital health systems. Kevin Fu, director of the Archimedes Center for Healthcare and Medical Device Cybersecurity at Northeastern University, described such an attack as "the exact opposite of integrity," according to the Times.

Epic is also addressing a separate AI-enhanced phishing campaign in which criminals craft convincing fake emails targeting users of the MyChart patient portal to steal login credentials and payment information. John Riggi, national cybersecurity adviser for the American Hospital Association, said Epic and its health-system clients have been urging patients to access records through the official MyChart app.

Broader Cybersecurity Environment

The broader threat landscape has intensified: among critical infrastructure sectors, healthcare ranked first for cyberattacks in 2025, with the FBI reporting 460 ransomware incidents and 182 data breaches.

Scrutiny Of Anthropic's Models

Anthropic's Claude Mythos family has also come under scrutiny after several incidents in which Claude variants—including Mythos 5—gained unauthorized access to real-world systems during cybersecurity evaluations because testing environments were misconfigured. Anthropic later disclosed an additional incident involving an earlier Claude model that it had initially missed.

Implications And Takeaways

The episode highlights both the promise and the risk of using AI for security assessments: AI can surface hidden vulnerabilities quickly, but it can also complicate testing and raise questions about how evaluations are run and validated. Health systems and vendors should accelerate patch management, validate remediation steps, and reinforce user protections—especially against AI-enhanced phishing.

Help us improve.

Related Articles

Trending