Epic Systems, the US medical-records giant whose MyChart software maintains more than 320 million patient records across hospitals and doctor's offices, has paused most of its product development for roughly six weeks while it works to fix security flaws that could allow access to patients' data. Founder and CEO Judy Faulkner told Modern Healthcare the pause is focused on "safeguarding" the company's products, after a deployment of Anthropic's frontier cybersecurity model Mythos unearthed the vulnerabilities. Epic has not disclosed the nature of the bugs, but chief security officer Stirling Martin told The New York Times that some customer configurations of MyChart could allow outsiders to access patient records without recording any intrusion in the software's logs — meaning a single unknown bug could let hackers compromise multiple MyChart deployments across the United States and raid the data within. Epic says it does not itself hold customers' medical data, placing remediation responsibility with providers. The story lands amid a brutal run for US healthcare: the 2024 Change Healthcare ransomware attack exposed data on more than 192 million people, and this year's breaches include CareCloud, McKesson and Craneware, with HHS listing a DentaQuest breach affecting 15 million people as 2026's largest so far. It is a rare public example of a vendor halting its roadmap for security, and a pointed signal of what AI-assisted vulnerability discovery — on both sides — is now doing to healthcare's attack surface.
| Attribute | Detail |
|---|---|
| Sector | Healthcare |
| Date | 2026-10-05 |
| Source | TechCrunch |
| Reliability | Tier 2 |