Medical Records Firm Uses AI Tool to Expose Flaws that Threaten Patient Privacy

Epic Systems, the nation’s largest medical records vendor that is relied on by thousands of hospitals and doctors’ offices, is using artificial intelligence tools to patch security risks that could give hackers undetectable access to patient health data, company officials said.The unusual nature of the vulnerability and the urgency to fix it prompted Epic to slow down development of some product lines while it sent engineers into a sprint to patch security holes.Judy Faulkner, Epic’s chief executive, revealed the security weakness and a six-week plan to shore up the gaps at an industry conference last week, but most details about the danger have not previously been reported.“You worry that after a month and a half of working almost primarily on safeguarding the software, that new things will be created by those who are trying to bust the software, and it will be in a never-ending cycle,” Ms.Faulkner said.According to company representatives, Epic deployed Anthropic’s Claude Mythos artificial intelligence agent to stress-test its systems, to hunt for ways that hackers could unleash open-source A.I.
agents and unlock confidential patient records.The security weaknesses pose a particularly acute threat for Epic, which maintains records of 325 million patients in the United States and other countries.We are having trouble retrieving the article content.Please enable JavaScript in your browser settings.Thank you for your patience while we verify access.If you are in Reader mode please exit and log into your Times account, or subscribe for all of The Times.Thank you for your patience while we verify access.Already a subscriber? Log in.Want all of The Times? Subscribe....