Innovation & Tech

Epic Halts Product Development to Fix MyChart Security Flaws

Epic paused most product development for six weeks after Anthropic's Mythos AI found MyChart flaws that could expose over 320 million U.S. patient records undetected.

By Amara Osei

3 min read

Updated

Medical records giant Epic pauses product development to fix security bugs that risk patients’ data
Medical records giant Epic pauses product development to fix security bugs that risk patients’ dataAI-generated

What's News

  • Epic paused most product development for roughly six weeks to fix security flaws found by Anthropic's Mythos cybersecurity model.
  • MyChart maintains over 320 million patient records across U.S. hospitals and doctor's offices.
  • CSO Stirling Martin said some MyChart configurations could allow outsiders to access patient records without any trace in the software's logs.
  • The 2024 Change Healthcare ransomware attack exposed health data on more than 192 million people; UnitedHealth paid the hackers twice.
  • HHS lists a DentaQuest breach affecting 15 million people as the largest healthcare data breach of 2026 so far.

Epic has paused most of its product development for roughly six weeks to fix security flaws that could expose the medical records of more than 320 million patients.

The Wisconsin-based software giant, whose MyChart platform dominates patient record access across U.S. hospitals and doctor's offices, took the unusual step after a deployment of Anthropic's frontier cybersecurity model, Mythos, uncovered bugs in its systems, according to founder and chief executive Judy Faulkner. She told Modern Healthcare last month that the pause would likely last six weeks while the company works on "safeguarding" its products.

Epic has not disclosed the nature of the bugs. But chief security officer Stirling Martin told the Times that some customer configurations of MyChart could allow outsiders to access patient records without any intrusion appearing in the software's logs. Martin, who did not return TechCrunch's request for comment, said the AI model did not indicate whether the bug could be exploited to alter patient records without detection. He argued the risk alone justified remediating the issues.

The stakes are considerable. MyChart maintains over 320 million patient records across the United States. Epic says it does not have access to customers' medical data — that responsibility falls on healthcare providers such as hospitals and doctor's offices. But a bug unknown to Epic could allow hackers to compromise multiple affected MyChart systems across the country and raid the data stored within.

Pausing development to fix security bugs is rare for a software company of Epic's scale. The decision reflects a broader shift in the industry: AI tools capable of rapidly finding and exploiting security vulnerabilities have raised concerns that attackers now have an easier path to stealing data. Epic's move suggests defenders can use the same technology to find flaws before criminals do — but it also shows how much damage those tools can surface.

Healthcare breaches are compounding

The healthcare sector has become a prime target for hackers seeking highly sensitive medical data, operating on the assumption that providers will pay to keep stolen information from being published online.

The most damaging incident to date remains the 2024 ransomware attack on Change Healthcare, the UnitedHealth-owned health-tech company that handles payments and billing for most Americans. Hackers stole health data on more than 192 million people — the majority of the U.S. population. The company paid the hackers twice in an effort to prevent publication of the stolen data.

This year has brought a string of back-to-back breaches at healthcare and technology companies affecting tens of millions of Americans. The incidents include medical records stolen in a breach at electronic health data storage giant CareCloud, millions of rows of patient data taken from pharmaceutical distributor McKesson, and an unspecified amount of data stolen from U.K.-based health tech company Craneware, whose software is used across North America.

The Department of Health and Human Services currently lists a breach at dental insurance company DentaQuest affecting 15 million people as the largest healthcare-related data breach of 2026 so far.

What comes next

Epic has set no firm public deadline beyond the approximate six-week timeframe, and it has not said whether any patient data was actually accessed through the flaws Mythos identified. The company's decision to halt development rather than patch quietly signals how seriously it rates the risk to systems holding records for most Americans' medical histories. If AI-driven security audits become standard practice, Epic's six-week freeze may become a template — or a warning — for other software vendors sitting on similarly sensitive data.

Original: modernhealthcare.com

Share this article:

More from Amara Osei

Amara Osei

Show full bio

Senior reporter covering consumer brands and retail at Business Bearings.

414 articles

Related articles

« Previous articleNext article »