the weekly eHealth brief
eHealth Cyber Brief — 5 Oct 2026
The vendor that holds 325 million patient records has stopped building features for six weeks: Epic paused most product development after Anthropic's Mythos model found that some MyChart configurations let outsiders read patient records without leaving a trace in the logs, a weakness its…
The vendor that holds 325 million patient records has stopped building features for six weeks: Epic paused most product development after Anthropic's Mythos model found that some MyChart configurations let outsiders read patient records without leaving a trace in the logs, a weakness its chief executive disclosed on stage and that affects hospitals from the Netherlands to the UK as much as the US. In the same fortnight Denmark's central population register was breached, exposing the CPR numbers that index every Danish health record for about 8.8 million people, Italy's Garante fined IQVIA 7 million euros after ruling that a research database of one million patients from 800 family doctors was not anonymous, Interlock claimed a hospice manager's 710 gigabytes and a dialysis provider in quick succession, and the US Senate passed its first dedicated hospital cybersecurity statute by unanimous consent as NHS England's board rated cyber its top risk at the maximum score and admitted it has no single vision for AI. On the clinical-AI lane, the US health secretary told patients an AI second opinion beats any doctor while 89% of patients say they want a human checking the answer, the FDA put generative mental-health chatbots on its 2027 guidance list, a Stanford genomics leader showed a consumer model analysing his genome in 30 minutes and asked who sets the standards, and Barts Health put 2,000 clinicians on an ambient-voice agent with little published on consent or error handling. European hospital incidents were quiet in this window and the ingest was degraded by four blocked trade feeds, so the breach count here leans American; the structural stories, in Copenhagen, Rome and Verona, are European.
Top Stories
- Medical records giant Epic pauses product development to fix security bugs that risk patients’ data — DataBreaches.Net · Health Data & Breaches
- Denmark's central population register breached: CPR numbers, names and addresses of 8.8 million people exposed — web_search (Bloomberg) · Health Data & Breaches
- RFK Jr.'s AI claims spark physician backlash as debate over medical AI intensifies — Fierce Healthcare · Clinical AI & Safety
- Italy’s Data Protection Authority fines IQVIA €7 million over data protection breach — DataBreaches.Net · Health Data & Breaches
- FDA to prioritize guidance on AI, surgical robots next year — MedTech Dive - Latest News · Clinical AI & Safety
Clinical AI & Safety
RFK Jr.'s AI claims spark physician backlash as debate over medical AI intensifies — Fierce Healthcare
Why it matters: The US health secretary telling patients an AI second opinion beats any doctor; the clearest statement yet of a government pushing clinical AI ahead of its validation.
Robert F. Kennedy Jr. said artificial intelligence can give patients a second opinion that is much better informed than any doctor in the country, prompting pushback from physician groups who point to hallucination rates, missing context and the absence of accountability when advice goes wrong. The remarks sit alongside HHS's new AI clinical-trial programme and the MAHA movement's push to open up health data, and against survey evidence that 89% of patients want human oversight of AI answers. For Europe, where the AI Act treats clinical decision support as high-risk, it is the counter-model.
FDA to prioritize guidance on AI, surgical robots next year — MedTech Dive - Latest News
Why it matters: The FDA's 2027 guidance list puts AI lifecycle management and generative mental-health chatbots on the A-list; the US regulatory map for the year.
The FDA's fiscal 2027 priorities put finalising the January 2025 draft on lifecycle management and marketing submissions for AI-enabled devices on the A-list, alongside new draft guidance on generative-AI conversational devices for mental-health disorders and final guidance on robotically assisted surgical devices. Comments are open until 30 November. Mental-health chatbots are the first generative-AI device class to get dedicated guidance anywhere, a reference point for EU notified bodies applying MDCG 2025-6 on the AI Act and MDR interplay.
Opinion: Claude analyzed my genome in 30 minutes. Now we need standards for the results — STAT health tech: Stories on AI, new medical devices and more
Why it matters: A Stanford genomics leader showing a consumer LLM doing a year's expert work on his genome for five dollars, and listing what could go wrong without standards.
Euan Ashley uploaded his full genome to Claude and had rare variants, drug responses and disease risks analysed in 30 minutes for about $5, work that took 30 experts a year in 2009; it found his APOE e4 variant. He warns of false reassurance when genes are not fully examined, of people receiving life-changing findings at home without counselling, of sequencing gaps in repetitive regions and of unrepresentative reference genomes, and proposes minimum detection thresholds, a catalogue of hard-to-sequence medical genes, disclosure duties for labs and AI developers, and clinical support for AI-generated results. Under the AI Act and IVDR such use by a provider would be high-risk; as consumer use it is unregulated.
Data privacy concerns could hold patients back from using AI — MedTech Dive - Latest News
Why it matters: Patient trust numbers that should frame every clinical-AI deployment: 70% worry about privacy, 89% want human oversight.
An Ipsos survey of 254 US patients for Wolters Kluwer found more than 70% worried about the privacy of their health information in AI, 89% saying AI responses need human oversight, 72% worried about bias and 69% about hallucinations, with fewer than a third willing to use AI for common health tasks involving personal data. The trust gap argues for the AI Act's transparency and human-oversight duties as adoption enablers rather than obstacles.
STAT+: HHS announces new efforts to speed up, expand clinical trials with AI — STAT health tech: Stories on AI, new medical devices and more
Why it matters: ARPA-H's SURPASS programme: AI and simulation to replace rigid trial phases, with no published validation framework yet.
HHS announced initiatives through ARPA-H to speed clinical trials by incorporating AI and computational models and moving away from sharply delineated phases, centred on SURPASS, Simulation-augmented Real-time Platform Adaptive Seamless Trials, which launches this autumn and will fund cross-disciplinary teams over five years; funding levels and validation safeguards were not detailed. EMA's own reflection paper on AI in the medicinal-product lifecycle sets a more cautious bar, and divergence on simulated evidence would complicate transatlantic trial acceptance.
STAT+: Anthropic joins ARPA-H clinical AI moonshot, will hold closed-door health care event — STAT health tech: Stories on AI, new medical devices and more
Why it matters: A frontier lab embedded in the US government's patient-facing clinical-agent programme, days after its model found flaws in the dominant EHR.
STAT reports Anthropic has joined ARPA-H's clinical AI moonshot, which includes the ADVOCATE programme to build the first FDA-authorised patient-facing agentic AI for heart-failure care, and will hold a closed-door health-care event; the company already supports ARPA-H's pediatric data network. The same fortnight its Mythos model found unlogged access paths to patient records in Epic's software. The lab is simultaneously the discoverer of clinical-system flaws and a builder of clinical agents.
Barts Health continues to roll out ambient voice technology — HTN Health Tech News
Why it matters: The largest NHS ambient-voice deployment: 2,000 clinicians on Oracle's agent under a national trial, with governance detail still thin.
Barts Health NHS Trust has given more than 2,000 clinicians access to Oracle's Clinical AI Agent to transcribe consultations and generate notes and letters, with 1,350 having used it and 700 active in September, as part of a national trial; an earlier 250-user pilot reported better consultation quality for two-thirds and five minutes saved per appointment. Published material says little about consent, retention or error handling, the points the NHS England board flagged when it said the service lacks a single AI vision.
STAT+: In radiology, AI is blurring the line between technology development and clinical practice — STAT health tech: Stories on AI, new medical devices and more
Why it matters: Radiology groups building and deploying their own AI; who regulates a practice that is also a device maker?
STAT describes outpatient and teleradiology practices acquiring and developing AI in-house to become AI-native, deploying tools on their own patients to perfect them. The arrangement collapses the distinction between manufacturer and user that MDR and the AI Act rely on; an EU practice doing the same would face in-house device rules and high-risk AI obligations at once.
Clinician-centered evaluation of large language model-generated discharge summaries for longer hospitalizations — npj Digital Medicine
Why it matters: Peer-reviewed evidence on LLM discharge summaries for long admissions, the use case most NHS and EU trusts are piloting.
An npj Digital Medicine study published 2 October evaluates large-language-model-generated discharge summaries for longer hospitalisations against clinician judgement, the setting where omissions matter most because of medication changes and multiple specialties. Full results are behind the journal's access wall; the study joins a growing evidence base that trusts deploying ambient and summarisation tools should cite in their clinical-safety cases.
Health Data & Breaches
[P1] Medical records giant Epic pauses product development to fix security bugs that risk patients’ data — DataBreaches.Net
Why it matters: The vendor holding 325 million patient records stops feature work for six weeks after an AI model found paths to read records without leaving a log; the biggest health-data security event of the fortnight.
Epic Systems paused most product development for about six weeks after deploying Anthropic's Mythos model against its software and finding that some customer configurations of MyChart could let outsiders access patient records without any trace in the logs; CEO Judy Faulkner disclosed the weakness and the remediation plan at the company's conference and warned that new flaws will be found as fast as old ones are fixed. The number of affected customers is undisclosed; no exploitation is reported.
severity high · EU: GDPR Art.9, NIS2, EHDS, MDR
[P1] Denmark's central population register breached: CPR numbers, names and addresses of 8.8 million people exposed — web_search (Bloomberg)
Why it matters: The CPR number is the key to every Danish patient record, prescription and health portal login; mass exposure of the register is a health-data event even though the register itself is civil.
National population register exposure covering the identifiers that index Danish health records, sundhed.dk and MitID-protected patient services; details of the intrusion are not yet public.
severity critical · exploited in the wild · EU: GDPR Art.9, NIS2, EHDS, eIDAS 2.0
[P2] Italy’s Data Protection Authority fines IQVIA €7 million over data protection breach — DataBreaches.Net
Why it matters: A one-million-patient research database from 800 GPs ruled not anonymous; the Garante setting the bar that EHDS secondary use will be judged against.
Italy's Garante fined IQVIA Solutions Italy 7 million euros over a database of about one million patients from 800 general practitioners used for pharmaceutical-company studies: patients carried a persistent code enabling tracking over time, and with year of birth, sex, diagnoses, symptoms, prescriptions, tests, vaccinations and location data they could be singled out and reasonably re-identified; more than 3,300 records carried names, tax codes and addresses. Violations included no legal basis, inadequate information, no retention period for data back to 2001, no impact assessment and inadequate security; IQVIA, deemed controller from collection, has 120 days to comply or have doctors anonymise the data independently.
severity high · EU: GDPR Art.9, EHDS, NIS2
DC Medicaid Agency Notifies 400,000 Beneficiaries About Data Exposure — The HIPAA Journal
Why it matters: A public agency publishing reports with hidden personal data on its own website; the non-malicious breach class that EHDS secondary-use rules must prevent.
The District of Columbia Department of Health Care Finance disclosed that two website reports meant to show summary statistics contained hidden personal information, exposing Medicaid IDs, provider names, dates of birth, race, gender, ethnicity and ward for 399,086 Medicaid and DC Healthcare Alliance beneficiaries enrolled between 2023 and 2026, discovered in July. No names or Social Security numbers were included. The same failure mode, residual identifiers in published aggregates, is what EHDS anonymisation and the IQVIA decision in Italy are about.
[P2] Texas Hospice Management Company Data Breach Affects 35,000 Texas Residents — The HIPAA Journal
Why it matters: Interlock stealing 710 gigabytes from a hospice and home-health manager, plus a phishing breach exposing substance-use treatment records.
AngMar Management Services, a Texas home-health and hospice manager, identified unauthorised access on 20 July after an intrusion around 18 July; Interlock claimed responsibility and 710 GB of data, and 35,916 Texans' names, Social Security numbers, patient and record numbers, insurance, diagnoses, prescriptions and medical histories were exposed. The same report covers Eskenazi Health in Indianapolis, where a phished employee mailbox exposed demographics, insurance and substance-use disorder treatment details, and an EHR-vendor incident affecting two Massachusetts jails' medical records.
severity high · exploited in the wild · EU: GDPR Art.9, NIS2 · actor Interlock (self-claimed; data posted) (70%)
[P3] Data Breaches Announced by Saber Healthcare & Buchalter — The HIPAA Journal
Why it matters: Three smaller US breaches, including a law firm serving a public hospital and a ransomware-encrypted dental practice.
Saber Healthcare in Ohio found unauthorised server access on 27 July affecting more than 3,000 people with identity, insurance, medical and financial data; law firm Buchalter confirmed on 4 September that third-party access exposed limited data on Arrowhead Regional Medical Center patients; Bright Smile Dental Care in Indiana suffered a ransomware attack on 3 August encrypting patient data, with keys believed not obtained by attackers.
severity medium · exploited in the wild · EU: GDPR Art.9, NIS2
[P3] Fairchild Medical Center & Boone Health Settle Pixel Lawsuits — The HIPAA Journal
Why it matters: Website tracking pixels on patient portals keep producing settlements; the same tooling is live on European hospital sites.
Fairchild Medical Center and Boone Health agreed to settle class actions alleging they disclosed patient data to third parties through pixels and website tracking tools on their sites and portals, joining a long run of US pixel settlements.
severity low · EU: GDPR Art.9, ePrivacy, DSA
Health Policy & Regulation
Senate passes bipartisan bill to bolster hospital cybersecurity — DataBreaches.Net
Why it matters: The first dedicated health-cyber statute to pass a US chamber, by unanimous consent, as hospital attacks mount.
The Senate passed the Health Care Cybersecurity and Resilience Act by unanimous consent on 1 October, sponsored by Senators Cassidy, Hassan, Cornyn and Warner, to help providers strengthen defences and protect patient data, with companion rural-hospital measures advanced by the HELP committee; House action is pending. It is the US counterpart to the EU's hospital cybersecurity action plan and ENISA's support centre, and arrives the same week Epic froze development to fix flaws.
NHS England on increased digital risk, pace of delivery for key digital programmes, vision for AI — HTN Health Tech News
Why it matters: NHS England's board rating cyber its top risk at the maximum score, with many providers failing the security toolkit and no single AI vision.
The NHS England board kept cyber as its highest-rated risk at a score of 25, noting a high number of organisations receiving standards-not-met results on the Data Security and Protection Toolkit and continuing alerts; it raised its technology and innovation risk from 8 to 12, citing slow delivery of the Federated Data Platform, NHS App, single patient record and ambient voice programmes due to provider capacity and internal approval processes, and said the NHS lacks a single clear vision for AI, risking delay and duplication.
OpenAI pledges $1B to provide resources, training for frontline cyber defenders — Health-ISAC – Health Information Sharing and Analysis Center
Why it matters: A frontier lab under investigation offering subsidised AI defence to hospitals; useful capacity, with a dependency question attached.
OpenAI announced Daybreak for Frontline Defenders, a $1 billion commitment of subsidised access and training for small security teams in electricity, water, local government and healthcare, to find vulnerabilities, detect intrusions and respond; Health-ISAC's chief security officer welcomed delivery to the last mile. The pledge comes as OpenAI faces FTC and state investigations over its own agents' intrusions, and it would tie hospital defence to a single US provider, the concentration risk the ECB flagged this week.
National Data Guardian seeks views on single patient record — HTN Health Tech News
Why it matters: The NDG consulting professionals on trust in the single patient record before design is fixed; the English analogue to EHDS primary-use rules.
National Data Guardian Nicola Byrne is surveying health and care professionals, until 9 October, on what the single patient record needs to earn their trust from day one, including accountability for entered data, handling of conflicting information, transition burden and the erosion of trust if information is used beyond direct care, with a report due in autumn. The questions map onto EHDS Article 3 patient rights and the access-logging duties that Epic's flaws show are not yet guaranteed in practice.
Health-ISAC® Director of European Operations Elected European Council of ISACs Chair — Health-ISAC – Health Information Sharing and Analysis Center
Why it matters: Health-sector leadership of Europe's cross-sector ISAC council as NIS2 and the hospital action plan mature.
Health-ISAC's director of European operations, Vasileios Mingos, was elected chair of the European Council of ISACs, leading cross-sector cyber and physical resilience initiatives across European critical infrastructure, and published a companion piece arguing healthcare cybersecurity is entering an era of collective defence. It gives the health sector a seat at the table where ENISA's support centre and NIS2 information-sharing arrangements are shaped.
Why MAHA wants to make health data much more accessible — STAT health tech: Stories on AI, new medical devices and more
Why it matters: The MAHA movement's push to open health data, in the same week its secretary promoted AI second opinions.
The MAHA Institute, a think tank of RFK Jr. allies, held an event emphasising broad patient and researcher access to health data, STAT reports, aligning with HHS AI initiatives. The EU route to the same goal is the EHDS, with opt-outs, anonymisation duties and health-data access bodies; the US approach relies on market access and consumer apps.
Telehealth & Digital Health
Oracle launches Oracle Health Oncology EHR with AI assistant — HTN Health Tech News
Why it matters: An oncology EHR shipping with embedded AI agents and automated chemotherapy regimen planning; the AI Act's high-risk clinical decision support, productised.
Oracle introduced an oncology-specific EHR with built-in AI agents providing pre-visit summaries, tumour-board preparation, guideline-grounded treatment planning, precision-oncology insights from genomic and pathology data and automated chemotherapy regimen planning with dose calculations. The announcement gives no regulatory status; in the EU, dose calculation and treatment recommendation functions are medical-device software under MDR and high-risk AI under the Act.
Is AI jacking up healthcare costs? — Endpoints News
Why it matters: Insurer analysis finding AI is raising costs through billing and utilisation rather than cutting them.
A Blue Cross Blue Shield Association analysis blames AI-enabled coding and billing tools for rising claims costs, Endpoints reports, as Cigna announces a $3 billion productivity programme built on AI and AKASA launches autonomous inpatient coding. The arms race between provider-side and payer-side AI is a US dynamic that European statutory systems will meet through DRG coding tools.
STAT+: UnitedHealth, CVS push back on Medicare plan to curb remote patient monitoring — STAT health tech: Stories on AI, new medical devices and more
Why it matters: Insurers defending remote-monitoring billing against Medicare's abuse concerns; the economics of connected devices.
Major insurers are opposing a Medicare proposal to rein in spending on remote patient monitoring with connected cuffs, scales and glucose meters, STAT reports, arguing it would disrupt chronic-care models. The dispute frames how IoMT data flows get paid for, and therefore how widely the devices are deployed.
Government of Guernsey updates on progress and closure of EPR programme — HTN Health Tech News
Why it matters: A small jurisdiction winding down its EPR programme in favour of incremental improvement; a cautionary case for big-bang record projects.
Guernsey's health committee reported on phase one of its electronic patient record programme and a decision to transition towards closure in favour of a rolling programme of improvement, citing resourcing constraints. It is a small-scale version of the delivery problems NHS England's board flagged for its own flagship programmes.
Interweave partners with the Dorset Care Record and expands Yorkshire and Humber Care Record — HTN Health Tech News
Why it matters: Shared care records continuing to expand across English regions ahead of the single patient record.
Interweave announced a partnership with the Dorset Care Record and continued expansion of the Yorkshire and Humber Care Record, extending regional shared-record coverage as the National Data Guardian consults on the national single patient record.
Medical Devices & IoMT
Health-ISAC Hacking Healthcare 9-29-2026 — Health-ISAC – Health Information Sharing and Analysis Center
Why it matters: CRA vulnerability reporting is now live for device makers: 24-hour early warnings through ENISA's single portal, alongside MDR vigilance.
Health-ISAC's EU update notes that since 11 September manufacturers of products with digital elements, including connected medical devices, must report actively exploited vulnerabilities and severe incidents under the Cyber Resilience Act: early warning within 24 hours, notification within 72 hours and a final report within 14 days or one month, through ENISA's new single reporting platform. A delegated act on certification-based presumption of conformity is expected in the fourth quarter. For medtech this runs in parallel with MDR vigilance and NIS2 duties on their hospital customers.
GE HealthCare hires new global chief AI officer — MedTech Dive - Latest News
Why it matters: A device major putting AI leadership at group level to connect devices, software and data.
GE HealthCare appointed Rodolphe Katra, from Medtronic, as global chief AI officer to lead efforts to connect devices, software and data, a sign that AI governance is moving into the core of imaging and monitoring product lines that the AI Act and CRA will regulate together.
Pharma & Biotech
Q&A: Anthropic's life sciences team talks Claude's first scientific discovery — Endpoints News
Why it matters: A lab claiming an AI-discovered enzyme system; provenance and verification of AI-generated science is a regulatory question in waiting.
Endpoints interviews Anthropic's life-sciences team about the claim that Claude agents discovered a new enzyme system, publicised in a blog post, with outside experts noting the experiments were still queued when the announcement went out. As AI-generated findings enter drug discovery pipelines, EMA and FDA will need provenance standards for machine-originated evidence.
[P3] Patient death raises liver questions ahead of Bristol Myers readout — Endpoints News
Why it matters: A fatal liver injury disclosed quietly in a trial amendment ahead of a major readout; pharmacovigilance transparency as a safety signal.
Bristol Myers Squibb disclosed one case of fatal liver injury in a May amendment to a trial of its lung-disease candidate, raising safety questions ahead of an upcoming readout, Endpoints reports; the disclosure route, a protocol amendment rather than a public safety notice, is the issue.
severity medium · EU: EMA pharmacovigilance, Clinical Trials Regulation
Threat Intelligence (Health)
[P3] H1 2026 Healthcare Data Breach Report — The HIPAA Journal
Why it matters: The half-year baseline: fewer US breaches, far fewer people affected, hacking still 86% of incidents and business associates as damaging per incident as providers.
HIPAA Journal counts 397 large US healthcare breaches in the first half of 2026, down 5.9% on H1 2025, affecting about 33.8 million people, down 22.6%; hacking and IT incidents accounted for 343, up 2.1%, with ransomware and extortion growing; nine breaches exceeded a million records, led by TriZetto Provider Solutions at 3.4 million and QualDerm at 2.95 million; providers reported 290, business associates 59 and plans 48, with similar average impact per incident.
severity medium · exploited in the wild · EU: NIS2, GDPR Art.9
Hospitals & Care Disruption
[P2] Interlock claims ransomware attack on The Center for Kidney Care (New Jersey), exposing nephrology patient data — web_search (DeXpose / ransomware.live)
Why it matters: Interlock, the group behind the Kettering Health shutdown, returning to dialysis and nephrology providers, where downtime has direct patient-safety consequences.
Leak-site claim against a nephrology provider; no confirmed care disruption, extent of data theft unverified.
severity high · exploited in the wild · EU: NIS2, GDPR Art.9 · actor Interlock (self-claimed; unverified) (50%)