Epic Pauses Development After AI Finds MyChart Security Flaws
Epic pauses most product development for six weeks after Anthropic's Mythos uncovers MyChart flaws that could expose over 320 million patient records.
Summary
As of October 2, 2026, Epic has paused most product development for a likely six weeks while securing MyChart after Anthropic’s frontier cybersecurity model Mythos uncovered undisclosed flaws. Founder and CEO Judy Faulkner described the effort as safeguarding. Chief security officer Stirling Martin said some customer configurations could let outsiders access records without generating intrusion logs. Mythos did not determine whether attackers could alter records undetected, but Martin said the risk warranted remediation.
MyChart supports over 320 million patient records at U.S. hospitals and doctors’ offices. Epic says providers, not Epic, control customer medical data, but an unknown flaw could compromise multiple affected systems nationwide. The rare development pause reflects concern that AI can accelerate vulnerability discovery and exploitation amid escalating healthcare extortion. A 2024 ransomware attack on Change Healthcare, UnitedHealth’s payments and billing business serving most Americans, exposed data on more than 192 million people and led to two payments to hackers. In 2026, thieves stole CareCloud medical records, millions of patient-data rows from pharmaceutical distributor McKesson, and an unspecified amount from U.K.-based Craneware, whose software operates across North America. The Department of Health and Human Services lists DentaQuest’s 15 million-person breach as 2026’s largest healthcare incident so far.
Positives
- Epic paused most product development for a likely six weeks to prioritize security remediation across its products and systems.
- Anthropic’s Mythos uncovered previously unknown MyChart flaws that Epic is now working to fix.
- Stirling Martin supported remediation despite uncertainty over whether attackers could secretly alter patient records.
Risks & concerns
- Some MyChart customer configurations could allow outsiders to access patient records without leaving evidence in intrusion logs.
- MyChart supports over 320 million records, creating broad potential exposure across affected U.S. healthcare systems.
- Epic has not disclosed the bugs’ nature or whether any attackers have already exploited them.
- AI tools could help attackers discover and exploit vulnerabilities faster, increasing pressure on healthcare providers.
- DentaQuest’s 15 million-person breach is already the largest healthcare incident listed by federal officials for 2026.