Epic Uses AI to Identify Security Flaws That Could Expose Patient Health Records
The electronic health record (EHR) vendor disclosed the findings last month and paused certain product development activities to implement patches addressing the identified risks.
Epic Systems has used Anthropic’s Claude Mythos artificial intelligence (AI) model to identify security vulnerabilities that could allow hackers to access patient health records without detection. The electronic health record (EHR) vendor disclosed the findings last month and paused certain product development activities to implement patches addressing the identified risks.
Epic CEO Judy Faulkner revealed the vulnerabilities and the use of the AI tool at a conference, according to a report by The New York Times. Claude Mythos is an AI model developed by Anthropic for advanced cybersecurity and biology research.
According to reporting by Wisconsin Public Radio (WPR), the vulnerabilities raised concerns about potential unauthorized access to sensitive health information. While the AI tool did not verify whether patient records could be altered, the possibility of undetected changes presents additional patient safety risks.
For example, unauthorized modifications to medical records could remove critical information, such as a patient's penicillin allergy, potentially affecting treatment decisions. The ability to access or manipulate records without leaving detectable traces could complicate investigations and increase the risk of clinical errors.
AI Accelerates Healthcare Cybersecurity Efforts
Rahul Gomes, department chair and associate professor of computer science at the University of Wisconsin-Eau Claire, said AI tools have accelerated the process of identifying and addressing software vulnerabilities.
Previously, cybersecurity researchers could spend days or weeks examining code and testing configurations to identify weaknesses in complex systems. AI can significantly shorten this process, allowing both security teams and malicious actors to identify vulnerabilities more quickly and with less specialized expertise.
However, healthcare organizations face additional challenges when deploying security updates. Unlike some financial services, hospitals cannot easily suspend critical systems for maintenance because clinicians need continuous access to patient information and clinical resources.
EHR Market Concentration Raises Security Concerns
Epic held nearly 44% of the US acute care EHR market in 2025, according to KLAS Research. Epic, Oracle Cerner and MEDITECH collectively account for nearly 75% of the country's electronic health record market, according to Definitive Healthcare.
This concentration creates both advantages and risks for healthcare cybersecurity. Large vendors can invest in advanced AI tools and standardize security processes across their platforms. However, a vulnerability affecting a widely used system could expose multiple healthcare organizations to similar threats.
Epic also uses AI for clinical applications, including Cosmos, a data aggregation platform designed to analyze medical records and support clinical decision-making.
The use of AI to detect software weaknesses highlights its growing role in healthcare security, even as the technology enables attackers to identify and exploit vulnerabilities more rapidly.
Add a stronger news leadClarify what Epic paused
Stay tuned for more such updates on Digital Health News