· via TechCrunch
Epic halts most product development for six weeks to fix MyChart security flaws
Epic paused most product development after an Anthropic cybersecurity model uncovered MyChart flaws capable of exposing patient records without leaving traces in the software's logs.

Epic pauses development after AI security review
Epic, the company behind the MyChart patient records software used across US hospitals and clinics, has suspended most of its product development to concentrate on security fixes. According to TechCrunch, the move follows the discovery of vulnerabilities that could put patients' data at risk.
Epic founder and chief executive Judy Faulkner told Modern Healthcare that the freeze would likely run for about six weeks, with engineering effort redirected toward what she described as safeguarding the company's products. The bugs surfaced after Epic deployed Mythos, an Anthropic cybersecurity model that TechCrunch characterises as frontier-grade, which identified flaws capable of exposing patient data.
What the flaws could allow
Epic has not described the vulnerabilities in technical detail. However, its chief security officer Stirling Martin told The New York Times that particular customer configurations of MyChart could let outsiders reach patient records without any intrusion being written to the software's logs, meaning an attack could slip past the usual audit trail.
According to TechCrunch, Martin said the AI model had not determined whether the flaw could also be exploited to change patient records without detection, but he judged the risk serious enough to justify fixing the problems. TechCrunch reported that Martin did not respond to its request for comment.
The scale involved is considerable. TechCrunch reports that MyChart is used to maintain more than 320 million patient records across hospitals and doctors' offices in the United States. Epic maintains that it has no access to customers' medical data, since that responsibility rests with the healthcare providers running the software. But as TechCrunch notes, a flaw unknown to Epic could let attackers compromise multiple affected MyChart deployments across the country and extract the data stored within them.
Why a development freeze is unusual
Companies rarely stop shipping features to remediate security defects. TechCrunch frames Epic's decision against a broader shift in the threat landscape: AI tools can now locate and exploit vulnerabilities at machine speed, raising the odds that attackers find a given bug before defenders do. A previously unknown flaw in widely deployed software effectively becomes a race, and in healthcare the data at stake is among the most sensitive that exists.
Healthcare breaches keep compounding
The backdrop to Epic's caution is a sector under sustained attack. TechCrunch points to the 2024 ransomware attack on Change Healthcare, the UnitedHealth-owned company that handles payments and billing for most Americans, in which hackers stole health data on more than 192 million people — the majority of the US population. The company paid the attackers twice in an effort to keep the stolen data from being published.
Further incidents have followed this year, TechCrunch reports: stolen medical records from electronic health data storage provider CareCloud, millions of rows of patient data taken from pharmaceutical distributor McKesson, and an undisclosed volume of data from UK-based health tech firm Craneware, whose software is used across North America. The Department of Health and Human Services currently lists a breach at dental insurer DentaQuest, affecting 15 million people, as the largest healthcare-related breach of 2026 so far.
Why it matters
Epic's software sits at the centre of American healthcare, so a single class of configuration-dependent flaws has national reach. The specific behaviour reported — access that leaves no log entry — is especially troubling, because audit logs are how providers detect and investigate misuse. If an intruder leaves no trace, hospitals and patients may never learn that a record was viewed.
The episode also shows how AI is reshaping the economics of vulnerability discovery. A model found flaws that had apparently gone unnoticed, prompting one of healthcare software's largest vendors to halt its roadmap for six weeks. The same capability is available to attackers, which pressures every vendor of widely deployed software to find and fix problems faster than the other side. Given healthcare's demonstrated willingness to pay ransoms, as Change Healthcare's double payment showed, the sector will remain a prime target. For hospitals and patients, Epic's pause trades short-term disruption for closing holes before someone else finds them.
- #cybersecurity
- #healthcare
- #epic-mychart
- #electronic-health-records
- #ai-security