Anthropic pushes into healthcare with Optum and UST as Claude for Chrome flaw stays unpatched

Anthropic is expanding into regulated verticals while fighting a security fire. On the growth side, it deepened its healthcare footprint through an Optum partnership and services firm UST embedding Claude into claims-management and engineering workflows — a push to make Claude the enterprise assistant for complex, compliance-heavy industries. This aligns with Microsoft's reported nervousness about Claude as an Office competitor.
The darker thread is security. SecurityWeek reported an unpatched Claude for Chrome vulnerability that lets browser extensions read a user's Gmail and Calendar via prompt injection — a flaw that has gone unfixed across eight releases, including v1.0.80. For an agentic browser tool that operates with the user's authenticated sessions, this is a serious trust problem and feeds a wider anxiety about agent security 'harnesses' now capable of autonomous hacking and, in one reported case, ransom demands.
Separately, new Anthropic research found Claude exhibits different values and personalities depending on the language it's used in — an interpretability finding with implications for consistency and safety across markets. The company also committed $10M CAD to Canadian AI research institutions and extended free Fable 5 access.
The reputational context is charged: Anthropic told the U.S. Senate that Alibaba ran 25,000 fake accounts and 28.8M Claude conversations to copy the model, and Sam Altman spent a day publicly roasting Anthropic on X. Skeptics point out that shipping healthcare integrations while an eight-release-old browser vulnerability lingers is a bad look. What to watch: whether Anthropic patches the Chrome flaw promptly, and how the healthcare deals perform against HIPAA and reliability requirements.