VMTech
Discuss a project →

Epic pauses most development to remediate MyChart security flaws

Epic pauses most development to remediate MyChart security flaws

Epic has paused most product development for an expected six weeks while it addresses security flaws identified in its products and systems. Founder and chief executive Judy Faulkner told Modern Healthcare that the work began after Anthropic deployed its frontier cybersecurity model, Mythos, to examine Epic’s software.

The issue affects the widely used MyChart platform, which is used to maintain more than 320 million patient records across hospitals and doctors’ offices in the United States. Epic has not disclosed the technical nature of the bugs or identified the customer environments affected.

Undetected access risk prompts remediation

Epic chief security officer Stirling Martin told The Times that some customer configurations of MyChart could permit outsiders to access patient records without the activity being recorded in the software’s logs. He said Mythos did not determine whether the weakness could also enable undetected changes to patient records, but Epic considered the exposure sufficient to require remediation.

Epic says it does not have access to customers’ medical data, because healthcare providers such as hospitals and doctors’ offices are responsible for that information. Even so, an unknown flaw could create a path for attackers to compromise multiple affected MyChart systems and obtain the data held by those providers.

AI-assisted testing changes the security calculus

The decision to halt most development is unusual, but it reflects concerns that AI tools can accelerate the discovery and potential exploitation of vulnerabilities. The use of Mythos in this case put attention on configuration-dependent weaknesses that may not be visible through normal application logging.

The exposure is especially significant in healthcare, where attackers target sensitive medical information and may seek payment to avoid publishing stolen data. In 2024, a ransomware attack on UnitedHealth-owned Change Healthcare exposed health data on more than 192 million people. The company paid the attackers twice in an effort to prevent publication of the stolen information.

Healthcare and technology organisations have also reported back-to-back breaches this year. They include records taken from CareCloud, millions of rows of patient data from pharmaceutical distributor McKesson, and an unspecified quantity of data from U.K.-based health technology company Craneware. The Department of Health and Human Services lists a DentaQuest breach affecting 15 million people as the largest healthcare-related breach of 2026 so far.

What healthcare organisations should examine

For healthcare providers using Epic software, the episode puts renewed emphasis on system configuration, access controls and the reliability of security logs. The relationship between clinical platforms and AI is also evolving, as Epic systems connect with ChatGPT connects Epic systems with ChatGPT and official medical databases, while security testing is revealing risks that can emerge around the same healthcare technology stack.

The practical implication is that organisations should treat remediation guidance, configuration reviews and independent access monitoring as operational priorities, particularly where an application’s own logs may not capture every suspected intrusion.

#cybersecurity#healthcare#patientdata#mychart
Open analytics
On the site 0 views
min read 4 02.10.2026
Instagram

Epic pauses most development to remediate MyChart security flaws

Open the post on Instagram ↗