Epic used AI to find security flaws in patient health records
- Doom: AI testing revealed patient data could be accessed without leaving an audit trail
- Boom: Epic deployed AI to identify security vulnerabilities in its health records platform
- Boom: Epic is developing patches to close the security flaws the AI identified
- Neutral: Reporting on the incident appeared across multiple outlets between October 7 and 9, 2026
The story in full
Epic, the health records software company, used artificial intelligence to identify potential security vulnerabilities in its system that could expose patient health data, according to reporting from October 2026. The AI testing surfaced cases where patient data could be accessed without leaving a traceable audit trail.
Epic's system holds medical records for a large share of US patients, making security gaps in its platform a significant concern for healthcare providers and regulators. The company appears to have used AI both to detect the flaws and to develop patches addressing them.
Analysis
360 wordsEpic, the Wisconsin-based electronic health records company whose platform holds medical records for a substantial portion of US patients, used artificial intelligence tools to probe its own system for security vulnerabilities, with reporting on the incident emerging between October 7 and 9, 2026. The AI testing uncovered cases where patient data could be accessed without generating an audit trail, meaning such access would leave no traceable record for compliance officers or investigators to review. Epic is reported to be developing patches to close the identified gaps.
The story carries particular weight because of Epic's scale. A company that handles records for a large share of the US patient population presents a concentrated target, and any flaw that allows untraced data access touches on core requirements under federal health privacy law. The genuinely contested question here is not whether the vulnerabilities existed but what their discovery reveals about the state of health IT security more broadly, and whether AI-assisted auditing of this kind should become a standard or even mandatory practice across the industry.
None of the three camps had published reactions at the time of writing, so what follows reflects the positions each would typically take on a story of this kind. The Pro-AI camp would likely read this as a clear demonstration of AI's practical value, arguing that automated testing can surface risks that human auditors would miss and that Epic's approach should be a model for the sector. The Anti-AI camp would probably focus on the vulnerability itself, questioning whether AI-dependent systems introduce new attack surfaces and pointing out that the flaw allowing untraceable access is itself a serious lapse, whatever tool found it. The Middle Ground camp would tend to argue that AI security auditing is a reasonable tool but that its output requires rigorous human oversight and transparent disclosure to regulators and affected patients before patches are complete.
The details worth watching include whether Epic discloses the scope of potential exposure to regulators or the public, what timeline the company sets for deploying the patches, and whether federal health authorities treat this incident as a trigger for broader guidance on AI-assisted security auditing in healthcare settings.
Where do you stand?
Add your take
0 reader votesSign in with Google to pick a side and post. Your vote moves the story's Doom / Boom score.
