344
Productivity & Workflow355
Automation & Workflow225
Software Development251
Marketing & Growth193
AI Infrastructure & MLOps175
Writing & Content Creation204
Data & Analytics142
Photography & Imaging156
Design & Creative170
Customer Support133
Sales & Outreach125
Voice & Speech135
Education & Learning131
Operations & Admin87
A report links Epic and Anthropic tools to finding security flaws. Available details do not show that patient records were accessed or exposed.
In short: A report raised concerns about Epic using an Anthropic tool, but the available details point to security testing and coding help, not confirmed patient data exposure.
Some coverage has circulated the idea that Epic engineers deployed an Anthropic tool that exposed risks which could allow undetected access to millions of patient records.
Based on the reporting available here, that specific claim cannot be confirmed as stated. What appears supported is that Epic has used Anthropic tools in two different ways.
First, Epic engineers reportedly used Anthropic’s Claude Code as a software development helper, meaning a tool that helps write and review code (like a spellchecker, but for software). That does not, by itself, show the tool was connected to live patient records.
Second, Epic’s chief security officer reportedly said Epic used an Anthropic model called Mythos to scan Epic’s codebase and find possible security weaknesses. This is closer to a safety inspection than a break-in, since it looks for problems before someone else can exploit them.
Importantly, the available information does not establish that patient records were accessed, that access went unnoticed, or that a patient data incident occurred. Claims like “millions of records” require very specific proof, such as what system was reached, how it happened, and confirmation from the company or regulators.
Epic software helps store and manage medical records, so even unproven claims about patient data can spread quickly and cause alarm. At the same time, it is normal for large companies to use tools that help developers write code and tools that help security teams find weak spots. The key difference is whether a tool actually touched real patient data, which is not shown in the details available here.
Source: NYTimes