
Epic Used Claude Mythos to Find Patient-Data Security Risks
Published by AINave Editorial
Epic Systems used Anthropic’s Claude Mythos to stress-test its medical-records software, identifying security risks that company officials said could let hackers access patient health data without detection. Epic then slowed development on some product lines as engineers focused on patching the gaps, a trade-off that puts remediation ahead of planned product work.The New York Times reported
What Epic’s AI testing was meant to find
According to Epic representatives, the company deployed Mythos to probe its systems for ways attackers might use open-source AI agents to reach confidential records. That describes a security test aimed at possible attack paths, not evidence that attackers used one or that records were accessed.The report describes the testing goal
The distinction matters: the reported risk is serious, but the available account does not name the vulnerabilities or explain how they work. Without those details, readers cannot assess which systems or customers might be exposed, or how an attacker would exploit the weaknesses.
Epic maintains records for 325 million patients in the United States and other countries, according to the report. That figure indicates the potential scale of the systems at stake; it is not a count of people affected by a breach.
Remediation took priority over some product work
Epic chief executive Judy Faulkner announced a six-week plan to shore up the gaps at an industry conference. The company sent engineers into a patching sprint and slowed development on some product lines while they worked on security.The New York Times reported
This is a concrete operational consequence of finding a risk in widely used software: engineering time moved from some product development to remediation. Faulkner also raised the possibility that attackers could find new weaknesses after the intensive effort, but that was a concern about what might follow, not a reported outcome.Faulkner described that concern
The account offers a narrow but useful picture of AI-assisted security work. Mythos was used to stress-test software for routes toward confidential data, while the company’s response relied on engineers patching the identified gaps. The specific findings and testing process remain undisclosed, so the public record does not show how much the tool contributed or whether the fixes closed every risk.



















