
TL;DR: Key Takeaways

- Development Halted: Epic Systems has paused most product development for an estimated six weeks while it works to protect its software and systems from cyberattacks.
- AI Discovery: The vulnerabilities were uncovered after deploying Anthropic's frontier cybersecurity AI model, Mythos.
- Logging Blindspot: Epic Chief Security Officer Stirling Martin told The New York Times that certain customer configurations of MyChart could allow outsiders to access patient records without recording any intrusion in software logs.
- Massive National Footprint: Epic's MyChart software is used to maintain more than 320 million patient records across hospitals and clinics throughout the United States.
- No Known Exploits Disclosed: Epic has not disclosed technical details of the bugs, and the AI model did not determine whether records could be altered without detection, but leadership prioritized remediation due to the potential data risk.
Healthcare software technology leader Epic Systems has halted most of its product development as the company moves to safeguard its core platforms against cyber threats. The pause follows an evaluation involving advanced artificial intelligence tools that revealed vulnerabilities capable of exposing sensitive patient information within the company's widely adopted health software.
Epic's flagship MyChart platform serves as a critical digital conduit for patient health data across the United States healthcare infrastructure. The decision to halt ongoing product feature work highlights the heightened sensitivity surrounding electronic medical records and the proactive measures healthcare software vendors are taking as automated vulnerability discovery tools reshape the cybersecurity landscape.
AI-Driven Testing Unearths Configuration Vulnerabilities

According to statements made by Epic founder and Chief Executive Officer Judy Faulkner to Modern Healthcare, the product development pause is expected to last approximately six weeks. The dedicated period will focus on "safeguarding" the company's portfolio of healthcare software solutions.
The security flaws were identified following the deployment of Anthropic's frontier cybersecurity model, known as Mythos. As frontier AI models demonstrate increasing proficiency in evaluating source code and identifying architectural weaknesses, organizations are deploying them internally to locate software defects before malicious actors can discover and leverage them.
Nature of the Flaws and Unlogged Access Risks
While Epic has not publicly disclosed technical specifics regarding the vulnerabilities, company leadership has shared high-level context concerning the nature of the issue. Epic Chief Security Officer Stirling Martin told The New York Times that specific customer configurations of MyChart could potentially enable unauthorized external parties to access patient records without generating an entry in the software's intrusion logs.
The absence of access logging presents a serious security consideration for network administrators, as detection mechanisms often rely on audit logs to identify anomalous activity and initiate incident response protocols. Martin indicated that the AI model did not confirm whether the flaw could be exploited to alter patient records without detection. However, Martin maintained that the potential for unlogged unauthorized access presented sufficient risk to justify halting routine development work to implement immediate fixes. Martin did not return a request for comment from TechCrunch.
The Scope of MyChart and Patient Data Custody
Epic occupies a central position within the United States medical system. Its MyChart software is deployed across hospitals, clinics, and medical practices nationwide to manage over 320 million patient records. The platform allows individuals to review test results, communicate with medical professionals, and manage appointment scheduling.
Epic has emphasized that it does not possess direct access to customer medical data. Under the prevailing operational framework, data custody and security administration reside with individual healthcare providers, including hospitals and medical offices. Nonetheless, industry analysts recognize that vendor-level software vulnerabilities present systemic supply chain risks: an unaddressed flaw in the underlying codebase could potentially expose multiple independent healthcare networks running vulnerable MyChart configurations across the country.
Escalating Cyber Risks Across the Healthcare Sector
A corporate decision to suspend standard feature development to remediate security issues remains rare within the enterprise software industry. However, the rapid emergence of advanced AI utilities capable of identifying security flaws has raised concern that attackers could rapidly discover and exploit systemic vulnerabilities at unprecedented speeds.
Healthcare networks remain frequent targets for extortion and ransomware operations. Threat actors frequently focus on healthcare organizations under the premise that medical facilities face operational pressure to prevent the public dissemination of sensitive health records. In 2024, a major ransomware attack struck Change Healthcare, a health technology entity owned by UnitedHealth responsible for processing national billing and payments. That incident resulted in the theft of health records belonging to more than 192 million individuals—representing a majority of the United States population—with the company paying ransoms twice in an effort to prevent publication of the stolen data.
The healthcare technology industry has experienced repeated data security incidents throughout 2026, impacting tens of millions of Americans. Documented incidents include the theft of medical records from electronic health data storage provider CareCloud, millions of rows of patient data accessed from pharmaceutical distributor McKesson, and an unspecified volume of data compromised from United Kingdom-based health tech provider Craneware, whose software is utilized across North America. Currently, the United States Department of Health and Human Services lists a breach at dental insurance provider DentaQuest affecting 15 million individuals as the largest healthcare-related data breach recorded in 2026 so far.
Balancing Feature Delivery and Structural Security
Epic's intervention illustrates the delicate balance health technology developers must maintain between introducing new clinical capabilities and hardening baseline software infrastructure. With patient portals serving as primary gateways to electronic medical records, addressing configuration vulnerabilities that evade standard logging tools represents a critical defensive priority.
As the six-week remediation window proceeds, healthcare providers and technology partners will monitor Epic's updates to ensure their specific MyChart deployments receive necessary configuration adjustments and security patches.
Frequently Asked Questions
Why did Epic pause its product development?
Epic paused most product development for an anticipated six weeks to focus engineering resources on fixing security vulnerabilities and safeguarding its software systems from potential cyberattacks.
How were the MyChart security vulnerabilities discovered?
The security flaws were identified during testing with Anthropic's frontier cybersecurity AI model, Mythos, which was deployed to analyze the software for potential security weaknesses.
What security risk do the identified bugs present?
According to Epic Chief Security Officer Stirling Martin, certain customer configurations of MyChart could allow unauthorized outsiders to access patient records without recording any intrusion event in the software's audit logs.
Could patient records be altered because of these bugs?
Epic Chief Security Officer Stirling Martin stated that the AI model did not indicate whether the vulnerabilities could be exploited to modify or alter patient records undetected, but leadership determined the data access risk was serious enough to require immediate remediation.
Does Epic Systems store and manage patient medical records directly?
Epic states that it does not have direct access to customers' medical data. The responsibility for holding and securing patient records rests with individual healthcare providers, such as hospitals and medical practices that utilize Epic's software.
What was the largest healthcare data breach of 2026 so far?
According to records from the Department of Health and Human Services, a breach at dental insurance provider DentaQuest impacting 15 million individuals currently ranks as the largest healthcare-related data breach of 2026 so far.
0 Comments