JUDGMENT OF RECORD ·
Record security now sets the pace for hospital software. AI found Epic flaws allowing untracked chart access, and customers must patch on Epic's six week clock.
Epic is racing to patch flaws that could let someone view patient records without leaving an audit trail, per reports on Sept 30 and Oct 1. Epic found them by testing its own code with Anthropic's Claude Mythos model. Epic holds records for about 325 million patients. It paused most new product work and set a six week timeline to close the gaps. Its security chief said whether records could be changed is more complicated.
Audit logs underpin HIPAA compliance and breach forensics, so the fix lands on every hospital running Epic. Separately on Oct 1, Payerset launched an assistant that serves payer rate data through an MCP server inside general AI tools, built on 20 trillion retained rate records. Health data is entering general assistants as defenders race to find flaws first.
The layer moving is infrastructure: AI testing now finds flaws faster than release cycles fix them. Distribution Capture governs, since Epic's reach makes its patch schedule the sector's. Confidence is Low: the access detail traces to one outlet, Epic says its roadmap is unchanged, and no breach is reported.
- CONFIDENCE
- Low
- HORIZON
- Through mid November 2026
- VS. PRIOR CALL
- New call
WHAT WOULD PROVE THIS WRONG
Epic restores full product development by Nov 15, 2026 with patches shipped, and no large health system reports a patching backlog or delayed upgrades.