Эрүүл мэндийн мэдээллийн Epic систем кибер аюулгүй байдлын эрсдэлээс үүдэн бүтээгдэхүүн хөгжүүлэлтээ түр зогсоолоо

Published:

Энэхүү мэдээ, нийтлэлийг хиймэл оюун боловсруулав.

Тус компани өвчтөний мэдээлэл алдагдаж болзошгүй цоорхойг засахаар зургаан долоо хоногийн хугацаатай хөгжүүлэлтийн ажлаа зогсоосон байна

Эрүүл мэндийн мэдээллийн технологийн салбарын тэргүүлэгч Epic компани өөрийн MyChart программ хангамжийн аюулгүй байдлыг хангах зорилгоор бүтээгдэхүүн хөгжүүлэлтийн ихэнх ажлаа түр зогсоолоо. Тус компанийн гүйцэтгэх захирал Жүди Фолкнер уг засварын ажил ойролцоогоор зургаан долоо хоног үргэлжлэх төлөвтэй байгааг мэдэгдэв. Энэхүү шийдвэр нь Anthropic компанийн Mythos нэртэй кибер аюулгүй байдлын загварыг ашиглан хийсэн шалгалтын явцад өвчтөний мэдээлэлд нэвтрэх боломжтой ноцтой сул талууд илэрсэнтэй холбоотой юм.

Epic компанийн аюулгүй байдал хариуцсан захирал Стирлинг Мартины мэдээлснээр, MyChart-ын зарим тохиргоо нь гадны этгээдүүдэд системийн бүртгэлд ул мөр үлдээлгүйгээр өвчтөний мэдээлэлд нэвтрэх боломжийг олгож болзошгүй байна. Хэдийгээр тус компани илэрсэн цоорхойнуудын талаар дэлгэрэнгүй мэдээлэл өгөөгүй ч, хиймэл оюун ухааны тусламжтайгаар эдгээр сул талыг ашиглан мэдээлэлд нэвтрэх эрсдэл өндөр байгааг онцолжээ.

АНУ-ын эмнэлэг, эмнэлгийн байгууллагуудад 320 сая гаруй өвчтөний бүртгэлийг хадгалдаг MyChart систем нь өгөгдлийн аюулгүй байдлын хувьд чухал ач холбогдолтой юм. Epic өөрөө өвчтөний мэдээлэлд шууд хандах эрхгүй боловч, системийн сул тал нь хакеруудад олон тооны эмнэлгийн байгууллагын мэдээллийн санг эрсдэлд оруулах боломж олгож болзошгүй.

Сүүлийн үед эрүүл мэндийн салбарын компаниуд кибер халдлагад өртөх нь эрс нэмэгдээд байна. Тухайлбал, 2024 онд Change Healthcare компанид гарсан халдлагын улмаас 192 сая хүний эрүүл мэндийн мэдээлэл алдагдсан бол энэ онд CareCloud, McKesson, Craneware зэрэг компаниудад ижил төстэй өгөгдөл алдагдлын тохиолдлууд бүртгэгдээд байгаа юм.

Дэлгэрэнгүйг эх сурвалжаас харах

↓Эх сурвалжийг нээх ↓

Epic, the software technology giant that makes the widely used MyChart software for accessing patients’ medical data, has paused most of its product development as the company works to protect its software and systems from cyberattacks.

Judy Faulkner, the founder and chief executive of Epic, told Modern Healthcare last month that the pause would likely last six weeks while work continues on “safeguarding” the company’s products, after a deployment of Anthropic’s frontier cybersecurity model Mythos unearthed security flaws that could allow access to patients’ data.

The company has not disclosed the nature of the bugs, but its chief security officer Stirling Martin told the Times that some customer configurations of MyChart could allow outsiders to access patient records without recording any intrusion in the software’s logs.

Martin, who did not return TechCrunch’s request for comment, told The Times that the AI model did not say if the bug could be exploited to alter patient records without detection, but argued it was enough of a risk to remediate the issues.

Epic’s widely used MyChart software is used to maintain over 320 million patient records across hospitals and doctor’s offices across the United States. Epic says it does not have access to customers’ medical data: that responsibility falls on healthcare providers like hospitals and doctor’s offices. But a bug unknown to Epic could allow hackers to compromise multiple MyChart affected systems located across the United States and raid the data stored within.

It’s rare for a company to pause development to fix security bugs, but the advent of AI tools capable of rapidly finding and exploiting security vulnerabilities has led to concerns that attackers could have an easier time at stealing data.

Healthcare breaches are increasingly common as hackers seek access to highly sensitive health and medical data, under the assumption that providers would pay to prevent hackers from publishing the information online. A 2024 ransomware attack on Change Healthcare, a health-tech company owned by insurance giant UnitedHealth tasked with handling payments and billing for most Americans, allowed hackers to steal health data on more than 192 million people, the majority of people in the United States. The company paid the hackers twice not to publish the stolen data.

This year, a string of back-to-back data breaches at healthcare and tech companies have affected tens of millions of Americans. This includes medical records stolen during a breach at electronic health data storage giant CareCloud, millions of rows of patient data from pharmaceutical distributor McKesson, and an unspecified amount of stolen data from U.K.-based health tech company Craneware, whose software is used across North America.

The Department of Health and Human Services currently lists a breach at dental insurance company DentaQuest affecting 15 million people as the largest healthcare-related data breach of 2026 so far.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

Та юу гэж бодож байна?

Сэтгэгдлээ оруулна уу!
Please enter your name here

MFC.mn сайтад сэтгэгдэл оруулахад анхаарах зүйлс

Холбоотой

spot_img

Шинэ

spot_img