Medical records giant Epic pauses product development to fix security bugs that risk patients’ data

Epic, the developer of the widely used MyChart medical software, has paused product development for six weeks to address critical security vulnerabilities. The flaws were identified by an AI cybersecurity model and could potentially allow unauthorized access to millions of patient records.
Why it matters
This highlights the growing intersection of AI-driven security testing and the protection of massive, sensitive healthcare databases against potential cyberattacks.
Epic, the software technology giant that makes the widely used MyChart software for accessing patients’ medical data, has paused most of its product development as the company works to protect its software and systems from cyberattacks.
Judy Faulkner, the founder and chief executive of Epic, told Modern Healthcare last month that the pause would likely last six weeks while work continues on “safeguarding” the company’s products, after a deployment of Anthropic’s frontier cybersecurity model Mythos unearthed security flaws that could allow access to patients’ data.
The company has not disclosed the nature of the bugs, but its chief security officer Stirling Martin told the Times that some customer configurations of MyChart could allow outsiders to access patient records without recording any intrusion in the software’s logs.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in