Frontier AI models turn up critical flaws in hospital software

Anthropic's Mythos exposed a MyChart flaw that could hide record access, and Google says its Gemini 4 Argon found a separate critical bug in hospital software.

MedRisk Staff
By
2 Min Read

Two frontier AI models have now turned up critical flaws in the clinical software hospitals depend on, a sign that vendor code is facing a new kind of scrutiny.

The first involves Epic, whose MyChart portal holds more than 320 million patient records. Epic has paused most product development for roughly six weeks while it fixes flaws surfaced by Mythos, the cybersecurity model built by Anthropic. Chief security officer Stirling Martin told The New York Times that some customer configurations of MyChart could let an outsider reach patient records without recording the access in the software’s logs. He did not say whether records could be altered undetected.

The second comes from Google. The company says its new frontier model, Gemini 4 Argon, found a critical vulnerability in healthcare software used by hospitals worldwide. Google-owned Wiz surfaced the issue through its Scan for Good program, which offers free scanning to critical infrastructure operators. Google did not name the software or its maker, and did not say whether the flaw was patched. Wiz separately said Sept. 24 that Scan for Good, running an earlier Gemini model, found exposures at two unnamed hospitals.

The pattern matters to hospital IT teams. Record platforms and clinical tools sit at the center of healthcare’s blast radius, and AI-driven code review is surfacing bugs that human testers and earlier models missed. The same guardrail-free models that help defenders can help attackers.

For security leaders, the practical step is to press vendors on how they handle AI-discovered flaws, and to treat a six-week development freeze at a major vendor as a cue to re-check configurations.

Share This Article