ImpactHealthcare5 MIN READ

Epic Pauses Product Development for Six Weeks After AI Model Uncovers Flaws That Could Expose Patient Records

Medical records giant Epic Systems has halted most product work for about six weeks to fix MyChart configuration flaws that could let outsiders view patient records without leaving a trace. The bugs were found by Anthropic's Mythos AI model.

3 October 2026Breaking
Epic Pauses Product Development for Six Weeks After AI Model Uncovers Flaws That Could Expose Patient Records

Epic Systems, the company whose software holds the medical records of a large share of Americans, has taken the unusual step of pausing most of its product development to fix security weaknesses that could have allowed outsiders to view patient records without leaving any trace.

Founder and chief executive Judy Faulkner told trade publication Modern Healthcare that the pause would last about six weeks, according to a TechCrunch report on 2 October. During that period, Epic engineers will concentrate on addressing the vulnerabilities rather than building new features.

The flaws involve configurations of MyChart, Epic's patient portal, which people use to view test results, message doctors, book appointments and pay bills. "Some customer configurations of MyChart could allow outsiders to access patient records without recording any intrusion," Epic's chief security officer, Stirling Martin, said, according to The Times. He indicated that the company was not certain whether records could also have been altered without detection.

The vulnerabilities were identified by Mythos, the frontier AI model developed by Anthropic for advanced cybersecurity work, during its deployment, TechCrunch reported. That detail makes the episode one of the most prominent examples yet of AI being used to find serious security flaws in critical software at scale.

Healthcare Cybersecurity Alert.png

Why this matters

The scale of Epic's footprint makes any security issue significant. MyChart holds more than 320 million patient records, and Epic's systems are deployed across hospitals, health systems and doctor's offices throughout the United States and in a number of other countries. A flaw that allows silent access to records could, in principle, expose diagnoses, medications, test results, mental health notes and financial details, some of the most sensitive information people have.

The absence of logging is particularly troubling. In most security incidents, investigators rely on logs to determine what happened, who was affected and whether data was taken. If access leaves no record, it becomes far harder to know whether a vulnerability was exploited, and therefore whether patients need to be notified.

Epic has emphasised that it does not itself access customers' medical data. Healthcare providers that use its software retain responsibility for that information and for how their systems are configured. That distinction matters legally, but for patients, the practical question is simply whether their records were safe.

An unusual response

Software companies rarely halt product development to address security problems. Most fix vulnerabilities alongside continuing work, issuing patches as they become available. A broad pause signals that Epic regards the issues as serious enough to require concentrated attention across its engineering organisation, and that fixing configuration problems across a vast customer base is a substantial undertaking.

The decision also reflects mounting pressure on the healthcare sector. Hospitals and health systems have become prime targets for cybercriminals because their data is valuable and their operations cannot easily be interrupted. The 2024 ransomware attack on Change Healthcare, a unit of UnitedHealth Group, disrupted payments and prescriptions across the US and affected the data of roughly 190 million people, according to the company. That incident reshaped how regulators, insurers and boards think about health sector security.

“Some customer configurations of MyChart could allow outsiders to access patient records without recording any intrusion.”
— Stirling Martin, Chief Security Officer, Epic

AI as a bug hunter

The role of Mythos in discovering the flaws is the most forward-looking aspect of the story. Anthropic has made Mythos-class models available to a small number of trusted organisations to help find and fix vulnerabilities in critical software, an effort the company has described publicly as Project Glasswing. Security researchers have long used automated tools to scan code, but frontier AI models can reason about complex systems, chain together smaller weaknesses and identify issues that conventional tools and human reviewers miss.

That capability cuts both ways. If AI models can find serious vulnerabilities quickly, attackers with access to capable models may eventually be able to do the same. The article describing Epic's decision noted growing concern about AI-accelerated vulnerability exploitation at a time of escalating healthcare data breaches. The race between defenders and attackers is being reshaped, and organisations that find and fix their own weaknesses first will be better placed.

For software vendors, the implication is that security debt accumulated over years may now be exposed much faster. Companies may face a wave of newly discovered vulnerabilities as AI-assisted auditing becomes more common, forcing them to make the same kind of difficult trade-off Epic has made between new features and fixing what already exists.

Who is Epic

Founded by Judy Faulkner in 1979 and based in Verona, Wisconsin, Epic has grown into the dominant provider of electronic health records in the US. It is privately held, and Faulkner has long resisted outside investment or a stock market listing. The company's software is used by many of the country's largest and most prestigious health systems, and MyChart has become one of the most widely used patient-facing applications in American healthcare.

That dominance brings responsibility. Because so much of the health system relies on Epic, weaknesses in its software can have systemic consequences, and its decisions on security set expectations across the industry.

Lessons for India and other markets

The episode carries lessons for countries building digital health systems, including India. Under the Ayushman Bharat Digital Mission, India is creating a national framework for digital health records, linking hospitals, laboratories and patients through unique health IDs. Large public and private hospital networks have been digitising records rapidly.

India has already experienced the cost of health sector cyberattacks. In 2022, a ransomware attack on the All India Institute of Medical Sciences in New Delhi disrupted services at one of the country's most important hospitals for days. As more health data moves online and patient portals become common, the security of software and its configuration becomes a matter of public interest.

The Epic case shows that even mature, widely deployed systems can contain serious flaws, and that how individual institutions configure software can be as important as the software itself. Regular independent audits, strong logging and rapid patching are basic requirements, and AI-assisted security testing may soon become one too.

What comes next

Epic will now need to work with its customers to identify affected configurations and fix them, a process that depends on hospitals and clinics acting quickly. Patients and regulators will be watching for any evidence that the vulnerabilities were exploited before they were found.

For the broader technology industry, the message is clear. AI is changing how fast weaknesses are discovered. Companies that hold sensitive data must assume that flaws in their systems will be found, and decide whether they want to be the ones who find them first.

TagsEpic SystemsMyChartJudy FaulknerHealthcare CybersecurityPatient DataElectronic Health RecordsAnthropicMythosAI SecurityVulnerabilitiesHealth TechData PrivacyHealthcareCybersecurity

Reader reviews

Sign in to rate and review this article.
Loading reviews…