Application security

Epic pauses product development amid cybersecurity concerns

AI technologies in enhancing healthcare data security.

Epic, the company behind the widely used MyChart patient portal, has temporarily halted most of its product development to address significant cybersecurity vulnerabilities discovered in its systems. The pause, expected to last approximately six weeks, is a proactive measure to safeguard patient data following the identification of security flaws, based on information published by TechCrunch.

The vulnerabilities were uncovered by an AI cybersecurity model, which revealed potential weaknesses that could allow unauthorized access to sensitive patient records. While the exact nature of the bugs remains undisclosed, Epic's chief security officer, Stirling Martin, indicated that some configurations of MyChart could permit external parties to access patient data without detection in system logs. Although the AI model did not confirm if records could be altered undetected, Epic deemed the risk sufficient to warrant a development pause. This situation highlights growing concerns about AI's dual role in both identifying and potentially exploiting security flaws. The healthcare sector continues to be a prime target for cyberattacks, with numerous large-scale breaches impacting millions of individuals in recent years, including significant incidents at Change Healthcare, CareCloud, and McKesson, underscoring the critical need for robust data protection measures.

Source: TechCrunch

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds