News with an accent.

Large red Epic Systems letters on a grassy lawn, with company buildings in the background.
Privacy

Epic halts most development to fix MyChart flaws

An Anthropic AI model found portal settings that could let someone read patient records without a trace. Epic reports no attacks and has not published a CVE.

Share

Epic Systems, which sells electronic health record software to hospitals across the United States, has stopped almost all of its product development to focus on security. Founder and CEO Judy Faulkner said the pause will last about six weeks, according to Modern Healthcare, which picked up her remarks at a summit it hosted.

The reason is a set of flaws Epic found with Mythos, Anthropic's cybersecurity model. Stirling Martin, Epic's chief security officer, told The New York Times that some MyChart configurations, the portal patients use to view their records, could let a third party read records without the access showing up in the logs. The statement reaches us through TechCrunch, which cites the Times; the original text is paywalled and could not be read, and Epic has not issued a statement of its own.

What is known and what is not

No attacks have been confirmed. Martin said the model could not establish whether someone could alter records without being detected, and that the risk was enough to justify a fix. No CVE identifier, affected version or numbered patch has been published, so it is not known how many hospitals have the risky configuration.

Medical Daily adds that hundreds of projects are under heightened review and that the pause would end around early November, a calculation by the outlet itself. An Epic spokesperson said its roadmap has not changed since August, and the company says it will keep working on its AI features.

The patient counts do not match: TechCrunch cites more than 320 million records in MyChart, and Quartz says 325 million.

How Mythos reached Epic

Anthropic launched Project Glasswing in April, a program in which companies run Mythos against their own code to find and repair weaknesses. On June 2, Anthropic expanded it to sectors such as health care, energy, water and communications.

No action has been announced for patients, and Epic says part of the fixes depends on each hospital's configuration. No effects in Mexico are known. Still pending is a customer notice or a CVE saying which configurations need fixing and by when.

Share

Keep reading

El Mediático uses cookies to measure its audience and, where advertising is active, to show ads. You can accept all, reject all, or choose what to allow. The cookie policy is available in Spanish only. More about cookies (Spanish)