Static

Medical records giant Epic pauses product development to fix security bugs that risk patients’ data

First reported by TechCrunch ·

The signal ●○○○ Compiled by AI from TechCrunch, the single source so far
Why you might care

Your medical records are now potentially more secure against sophisticated cyberattacks without requiring any action from you.

What happened

Epic, a major provider of electronic health records software used by over 320 million patients in the U.S., has halted most product development for an estimated six weeks. This pause is to address critical security vulnerabilities discovered in its MyChart software. The flaws, identified by Anthropic's cybersecurity AI model Mythos, could allow unauthorized access to patient data without detection in system logs. While the exact nature of the bugs remains undisclosed, Epic's chief security officer confirmed that certain customer configurations could permit external parties to view patient records. This rare move by Epic comes amid increasing concerns about AI-powered cyberattacks and a rise in healthcare data breaches, such as the recent massive ransomware attack on Change Healthcare.

What it means

The decision by Epic to pause product development underscores the growing threat posed by AI-driven cybersecurity tools, which can rapidly uncover vulnerabilities that human attackers could then exploit. This incident highlights the race between AI for defense and AI for offense in the cybersecurity landscape, particularly in sensitive sectors like healthcare where data breaches have severe consequences. The reliance on AI to find these flaws also suggests a future where AI plays a more prominent role in both identifying and remediating security issues within software.

This event signals increased scrutiny on the security practices of major health tech companies and may lead to a broader industry re-evaluation of how AI is integrated into security auditing and software development lifecycles. Other healthcare providers and software vendors may face pressure to adopt similar proactive security measures, potentially impacting development timelines and budgets across the sector as they seek to protect highly sensitive patient data from evolving cyber threats.

AI-written summary. May contain errors.

Medical