Urgent.News

What's breaking now, across thousands of outlets.

Tech

Medical records giant Epic pauses product development to fix security bugs that risk patients’ data

The health tech software giant, which makes the widely used MyChart system for accessing medical data, will focus on fixing security bugs for the next few weeks.

Epic, the software company behind the popular MyChart patient portal, has temporarily halted product development to address security vulnerabilities that could potentially expose patients' medical records. The company's founder and CEO, Judy Faulkner, announced the six-week pause after security researchers identified flaws in their systems using Anthropic's AI-powered security model, Mythos.

While the specific details of the bugs remain undisclosed, Epic's chief security officer, Stirling Martin, revealed that certain configurations of MyChart might allow unauthorized access to patient data without triggering any alerts. This AI-assisted discovery of security flaws, coupled with the increasing prevalence of cyberattacks targeting healthcare data, has prompted Epic to prioritize safeguarding its products.

MyChart, used by over 320 million patients across the United States, stores sensitive health information in hospitals and clinics' databases. While Epic does not directly handle patients' medical data, a security lapse could potentially compromise multiple systems, putting countless patients' records at risk. The frequency of healthcare data breaches is on the rise, with recent incidents involving major players like Change Healthcare and CareCloud highlighting the urgent need for robust cybersecurity measures in the healthcare industry.

Written by urgent.news from TechCrunch's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at techcrunch.com →

More in Tech

Security updates for Friday

Security updates have been issued by AlmaLinux (dogtag-pki, expat, freerdp, gawk, gdb, ghostscript, gvfs, kernel, kernel-rt, libpcap, openssh, pki-core, rsync, thunderbird, and webkit2gtk3), Debian…

Why a VEX document should be diffed claim by claim

Nobody reads your VEX document twice. A customer reads the first one you publish, and after that they read the difference between the new one and the copy they already hold: which advisories you have…

  • Diff VEX documents claim by claim for customer readability
  • VEX document is JSON, straightforward diff reports byte-level changes
  • Keyed comparison promotes unmatched items to top of report

Ceremony proportional to irreversibility: Type 1 vs Type 2 engineering decisions

By Decision Desk Every engineering team eventually has the same argument. One group says "we need more design review, we keep shipping things we regret." Another says "we need less process, it takes…

  • Type 1 decisions are irreversible and require careful deliberation
  • Type 2 decisions are reversible and can be undone if needed
  • Appropriate ceremony depends on the irreversibility of each decision

More from Friday 2 October →