Epic halts product development to patch MyChart security flaws found by AI model
Epic, maker of the widely used MyChart patient records software, has paused most new product development for about six weeks to fix security vulnerabilities discovered during testing with Anthropic's Mythos cybersecurity model. CEO Judy Faulkner confirmed the pause to Modern Healthcare, and chief security officer Stirling Martin told the New York Times that some customer configurations could let outsiders access patient records without leaving any trace in system logs.
GoKawiil's interpretation of the reporting above, not reported fact.
MyChart holds over 320 million patient records across US hospitals and clinics, so an undetectable access flaw could expose vast amounts of sensitive health data before anyone noticed. The episode suggests AI tools are becoming powerful enough to surface serious vulnerabilities that human testing missed, which could push other major software vendors toward similar pauses or AI-assisted audits. It also underscores growing concern that the same AI capabilities could be turned by attackers to find and exploit such flaws faster than defenders can patch them.
- Epic paused most product development for roughly six weeks to fix flaws found via Anthropic's Mythos AI model.
- Some MyChart configurations reportedly allowed patient record access without logging the intrusion, per CSO Stirling Martin.
- MyChart manages over 320 million patient records, making undetected breaches potentially widespread.
Source: techcrunch.com — Zack Whittaker, 2026-10-02
Published there as: “Medical records giant Epic pauses product development to fix security bugs that risk patients’ data”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.