Epic Systems, the largest medical records vendor in the United States, has disclosed new cybersecurity vulnerabilities that could allow hackers to access patient health data without detection. The company, which serves thousands of hospitals and medical offices and maintains records for approximately 325 million patients domestically and abroad, revealed these risks during an industry conference last week.

Epic employed an artificial intelligence agent, Claude Mythos, developed by Anthropics, to conduct stress tests on its systems. The AI was used to probe for weaknesses that might enable hackers to exploit open-source AI tools to gain entry to confidential patient information. According to Epic’s senior vice president and chief security officer, Stirling Martin, the artificial intelligence testing identified software configurations that could allow unauthorized viewing of sensitive records without generating an audit trail. While the tests did not confirm the ability to alter records, the possibility raises concerns among cybersecurity experts.

Such unauthorized changes to medical records—referred to as “integrity” attacks—could have serious implications for patient safety and trust in digital health infrastructure. Experts note that while ransomware attacks typically lock systems to extort victims or steal data for resale, manipulating records could endanger lives by altering critical medical information, such as allergies or treatment histories. Kevin Fu, director of the Archimedes Center for Healthcare and Medical Device Cybersecurity, stated that tampering with records while erasing digital footprints represents a significant escalation of risk.

The discovery prompted Epic to pause much of its new product development temporarily to focus on addressing these security gaps. However, the company later clarified that existing product timelines remain largely unaffected amid these efforts. CEO Judy Faulkner emphasized the ongoing cyber threat landscape’s intensity, highlighting the need for continuous and rapid patching as attackers evolve their methods.

Epic’s revelations come amid a broader context of rising cyberattacks on the healthcare sector. FBI data for 2025 indicated that health networks were the most targeted critical infrastructure sector, experiencing hundreds of ransomware attacks and data breaches. In addition to system vulnerabilities, Epic has been contending with phishing scams targeting users of its widely used patient portal, MyChart. These campaigns use increasingly sophisticated AI-generated emails to impersonate legitimate communications, persuading patients to disclose login credentials or financial information.

Cybersecurity specialists warn that AI is accelerating the capabilities of hackers, enabling them to execute attacks at greater scale and with enhanced realism. John Riggi, a former FBI cybersecurity specialist, noted that AI-generated phishing attempts now employ personalized health data and immersive tactics, making scams more difficult to detect.

Epic’s security chief acknowledged the fast-paced nature of the threats and underlined the imperative for healthcare providers and vendors to maintain heightened vigilance and agility in their cybersecurity responses. As the healthcare sector integrates more AI-driven tools for patient care and data analysis, balancing innovation with robust protection measures remains a critical challenge.