Epic Halts Product Dev to Fix Security Bugs Risking Patient Data

▼ Summary
– Epic has paused most product development for six weeks to secure its MyChart software after AI tool Mythos identified critical security flaws.
– Chief Security Officer Stirling Martin warned that some configurations could allow unauthorized access to patient records without triggering intrusion logs.
– The vulnerabilities affect over 320 million patient records managed by hospitals and doctors across the United States.
– This incident highlights rising concerns about AI-powered cyberattacks targeting healthcare data amid a surge in recent major breaches.
– Recent significant breaches include those at Change Healthcare, CareCloud, McKesson, and DentaQuest, affecting millions of Americans.
Strategic Halt to Development
Epic, the dominant provider of healthcare software including the widely utilized MyChart platform, has temporarily suspended most product development initiatives. This strategic pause is designed to allow the company to focus intensely on securing its systems against potential cyber threats. The decision follows an internal audit triggered by the deployment of Anthropic’s advanced cybersecurity model, Mythos. This AI tool identified significant security vulnerabilities that could potentially expose sensitive patient information.
Judy Faulkner, Epic’s founder and CEO, confirmed to Modern Healthcare that the development halt is expected to last approximately six weeks. During this period, engineering teams will prioritize “safeguarding” the company’s products to ensure robust protection for user data. While the specific technical details of the flaws remain undisclosed, the move underscores a proactive approach to managing risk in an increasingly hostile digital environment.
Unlogged Access Vulnerabilities
The severity of the discovered bugs lies in their stealth capabilities. Stirling Martin, Epic’s chief security officer, explained to The New York Times that certain configurations of MyChart allowed external actors to view patient records without generating any entry in the software’s intrusion logs. This lack of detection makes identifying and responding to breaches significantly more difficult for administrators.
Martin clarified the scope of the risk during his interview with the Times. He stated:
> “The AI model did not say if the bug could be exploited to alter patient records without detection, but argued it was enough of a risk to remediate the issues.”
Although Martin declined to comment further with TechCrunch, his statements highlight the critical nature of the flaw. Even if the vulnerability primarily allowed for unauthorized viewing rather than alteration, the ability to access data silently poses a substantial threat to patient privacy and regulatory compliance.
Scale of Exposure and Industry Context
MyChart serves as a central hub for over 320 million patient records across hospitals and medical practices nationwide. While Epic maintains that it does not directly access customer medical data,placing that responsibility on healthcare providers,the existence of such a massive attack surface creates significant concern. A single undetected breach could compromise millions of records simultaneously, affecting systems across multiple states.
This incident reflects a broader trend in the technology sector where AI-driven security tools are becoming double-edged swords. While these models help companies identify weaknesses before malicious actors do, they also demonstrate how easily sophisticated attackers might exploit similar methods to find and leverage vulnerabilities. The rapid pace at which AI can uncover flaws has heightened anxiety among tech leaders about the potential for widespread data theft.
Rising Threats in Healthcare
The healthcare industry remains a prime target for cybercriminals due to the high value of medical data on the black market. Hackers often assume that providers will pay ransoms to prevent the public release of sensitive health information. Recent history illustrates the devastating impact of such attacks. In 2024, a ransomware assault on Change Healthcare, owned by UnitedHealth, compromised the health data of more than 192 million people. The company ultimately paid the attackers twice to keep the stolen information private.
Earlier this year, a series of consecutive breaches affected tens of millions of Americans. Notable incidents included the theft of medical records from CareCloud, the exposure of patient data from pharmaceutical distributor McKesson, and the compromise of data from Craneware, a U. K.-based firm whose software operates throughout North America.
As of October 2026, the largest recorded healthcare-related data breach of the year involves DentaQuest, a dental insurance company. The Department of Health and Human Services lists this incident as affecting 15 million people, marking it as the most significant breach of 2026 so far. These cumulative events highlight the urgent need for enhanced security measures within the healthcare technology ecosystem.
(Source: TechCrunch)