Epic’s AI Security Test Exposes Untraceable Patient Data Access

Epic logo data breaches

Highlights

Epic’s AI test turned up a hidden risk. Anthropic’s Claude Mythos found MyChart setups that could let outsiders read patient records without showing up in audit logs.

Security work moved ahead of new features. Epic shifted engineers off product development for about six weeks to close the gaps.

Patching is now the hard part. Anthropic’s Glasswing partners found more than 10,000 serious flaws in one month, but fixes take about two weeks each.

Epic Systems found flaws in certain MyChart configurations that could let someone view patient records without the access appearing in an audit trail. The company found them by testing its software with Anthropic’s Claude Mythos, Stirling Martin, Epic’s chief security officer, told The New York Times. Epic used Mythos to test how attackers might use open-source artificial intelligence agents to reach confidential records, the Times reported.

    Get the Full Story

    Complete the form to unlock this article and enjoy unlimited free access to all PYMNTS content — no additional logins required.

    Subscribe to our daily newsletter, PYMNTS Today.

    By completing this form, you agree to receive marketing communications from PYMNTS and to the sharing of your information with our sponsor, if applicable, in accordance with our Privacy Policy and Terms and Conditions.

    Epic moved engineers off new product work to fix the flaws. Judy Faulkner, Epic’s founder and CEO, told Modern Healthcare the work would likely take about six weeks. Epic later said its AI and interoperability plans remained on track, Fierce Healthcare reported.

    Mythos did not determine whether the flaws could be used to alter records without detection, TechCrunch reported. Martin said the risk was high enough to fix. MyChart supports more than 320 million patient records across U.S. hospitals and doctors’ offices. Epic says providers, not Epic, control that data.

    AI Finds Flaws That Years of Review Missed

    Epic is part of Project Glasswing, Anthropic’s program that gives selected organizations access to the unreleased Mythos model for defensive security work. Martin confirmed Epic’s participation at the company’s August user group meeting, Fierce Healthcare reported. He told health system IT teams to expect a “higher-than-usual number of urgent security fixes.”

    We’d love to be your preferred source for news.

    Please add us to your preferred sources list so our news, data and interviews show up in your feed. Thanks!

    Anthropic launched Glasswing on April 7 with partners including Amazon Web Services, Apple, Cisco, CrowdStrike, Google, JPMorgan Chase and Microsoft, the company said. Mythos found a 27-year-old flaw in the OpenBSD operating system, according to Anthropic. It also found a 16-year-old flaw in FFmpeg video software that automated testing had hit 5 million times without catching.

    Healthcare breaches cost an average of $6.64 million, the highest of any industry for the 13th straight year, IBM found in its 2026 Cost of a Data Breach Report. The 2024 ransomware attack on Change Healthcare, a UnitedHealth unit, exposed health data on more than 192 million people, TechCrunch reported.

    Patching Becomes the Bottleneck

    About 50 Glasswing partners found more than 10,000 high- or critical-severity vulnerabilities in the program’s first month, Anthropic reported in a May update. Cloudflare alone found 2,000 bugs, 400 of them high or critical. Of 530 high- or critical-severity bugs Anthropic disclosed to open-source maintainers, 75 had been patched at the time. A fix took about two weeks on average. Anthropic said security progress is now limited by how fast defenders can verify, disclose and patch flaws, not how fast they find them.

    Banks are adjusting to the same volume. Mythos has found several hundred to thousands of low- to moderate-ranked vulnerabilities in banks’ technology, and banks now patch flaws in days instead of weeks, PYMNTS reported. Anthropic CEO Dario Amodei said in May that organizations have six to 12 months to fix vulnerabilities before other AI models match Mythos, PYMNTS reported.

    Few companies pause development to fix security bugs. Epic’s choice put a security finding ahead of new features for about six weeks. Each Epic fix also lands on the hospital IT teams that run MyChart, the same teams Martin told to expect more urgent updates.

    For all PYMNTS AI coverage, subscribe to the daily AI Newsletter.