Epic Used Claude Mythos to Find Patient-Data Security Risks
nytimes.com

Epic Used Claude Mythos to Find Patient-Data Security Risks

Tech News
3 min read

Published by AINave Editorial

TL;DREpic says it used Anthropic’s Claude Mythos to stress-test its medical-records systems and uncover risks to patient privacy. The company announced a six-week effort to patch them, slowing development on some product lines.

Epic Systems used Anthropic’s Claude Mythos to stress-test its medical-records software, identifying security risks that company officials said could let hackers access patient health data without detection. Epic then slowed development on some product lines as engineers focused on patching the gaps, a trade-off that puts remediation ahead of planned product work.The New York Times reported

What Epic’s AI testing was meant to find

According to Epic representatives, the company deployed Mythos to probe its systems for ways attackers might use open-source AI agents to reach confidential records. That describes a security test aimed at possible attack paths, not evidence that attackers used one or that records were accessed.The report describes the testing goal

The distinction matters: the reported risk is serious, but the available account does not name the vulnerabilities or explain how they work. Without those details, readers cannot assess which systems or customers might be exposed, or how an attacker would exploit the weaknesses.

Epic maintains records for 325 million patients in the United States and other countries, according to the report. That figure indicates the potential scale of the systems at stake; it is not a count of people affected by a breach.

Remediation took priority over some product work

Epic chief executive Judy Faulkner announced a six-week plan to shore up the gaps at an industry conference. The company sent engineers into a patching sprint and slowed development on some product lines while they worked on security.The New York Times reported

This is a concrete operational consequence of finding a risk in widely used software: engineering time moved from some product development to remediation. Faulkner also raised the possibility that attackers could find new weaknesses after the intensive effort, but that was a concern about what might follow, not a reported outcome.Faulkner described that concern

The account offers a narrow but useful picture of AI-assisted security work. Mythos was used to stress-test software for routes toward confidential data, while the company’s response relied on engineers patching the identified gaps. The specific findings and testing process remain undisclosed, so the public record does not show how much the tool contributed or whether the fixes closed every risk.

FAQs

Company officials said the weaknesses could allow hackers to access patient health data undetected, but the reporting does not specify the flaws’ technical nature.The reported risk

Sources

Latest Tech News