Technology·News & analysis
Epic pauses most product work after AI finds MyChart security flaws
The medical records giant behind MyChart says it is spending about six weeks hardening its software after Anthropic's Mythos model found flaws that could expose patient records.

Tide
Wave
Sci-fi
4/10
Reality
Shipping
An AI goes bug hunting and a hospital software giant hits pause.How we rate
Epic, maker of the MyChart patient portal, has paused most product development for about six weeks to fix security flaws, TechCrunch reports.
Anthropic's Mythos AI model found the bugs, which in some setups could let outsiders read patient records without leaving a trace in the logs. MyChart holds over 320 million records. Epic hasn't detailed the flaws, and says its roadmap is unchanged.
What to know
- Epic, maker of the MyChart patient portal, has paused most of its product development to work on security, TechCrunch reports.
- CEO Judy Faulkner told Modern Healthcare the pause would likely last about six weeks, after Anthropic's Mythos model found flaws that could expose patient data.
- Epic's security chief told The New York Times that some MyChart configurations could let outsiders access records without leaving a trace in the logs.
- Epic hasn't disclosed the bugs, and a spokesperson says its development roadmap hasn't changed.
Epic, the company behind the MyChart patient portal, has paused most of its product development to shore up the security of its software, TechCrunch reports. The move follows a scan by Anthropic's Mythos AI model that turned up flaws which could expose patients' medical records.
What did Epic do?
Epic founder and CEO Judy Faulkner told Modern Healthcare that the pause would likely last about six weeks while the company works on "safeguarding" its products, according to TechCrunch.
She spoke about it on a panel about how CEOs are leading their teams through AI, according to health tech writer Brendan Keeler, citing Modern Healthcare. Keeler says she described the pause as covering hundreds of projects, and called the decision a "shame."
It's rare for a company to pause development to fix security bugs, TechCrunch notes. But the rise of AI tools that can quickly find and exploit vulnerabilities has raised concerns that attackers could have an easier time stealing data.
What did the AI find?
Epic hasn't disclosed the nature of the bugs. But its chief security officer, Stirling Martin, gave The New York Times an outline, according to TechCrunch:
- The risk: some customer configurations of MyChart could let outsiders access patient records.
- No trace: that access might not show up in the software's logs.
- What's unknown: the AI model didn't say whether the bug could be used to alter patient records without detection.
Martin told the Times the risk was enough to fix the issues, even without knowing whether records could be altered. He did not respond to TechCrunch's request for comment.
The flaws were found when Epic deployed Mythos, Anthropic's frontier cybersecurity model, on its software, TechCrunch reports.
The New York Times, which first reported the details, said Epic is using Mythos to stress-test its software and to probe how attackers might use open-source AI agents to unlock confidential records. The Times described Epic as the largest US medical records vendor, serving thousands of hospitals and doctor's offices, with records for 325 million patients worldwide.
How big is MyChart?
MyChart is the software millions of Americans use to view lab results, message their doctors and manage prescriptions, as Cryptonomist describes it.
By the numbers: MyChart is used to maintain more than 320 million patient records across hospitals and doctor's offices in the US, according to TechCrunch.
Epic says it doesn't have access to customers' medical data. That responsibility belongs to the healthcare providers, like hospitals and clinics, that run its software.
The catch: a single bug in Epic's software could still matter across many providers at once. TechCrunch notes that a flaw unknown to Epic could let hackers compromise multiple affected MyChart systems across the US and take the data stored in them.
In real life If you log in to see test results or message your doctor, there's a good chance you use MyChart. The flaws are in the software your hospital runs, which is why Epic, not patients, is the one fixing them.
What is Epic saying now?
There are two messages coming out of Epic, as Keeler points out.
Keeler, who writes the Health API Guy newsletter, notes that Epic has long been a famously private company. It has invested more in lobbying and marketing in recent years and has even opened its Users Group Meeting to the press, he writes, which is part of why Faulkner's candid comments drew so much attention.
Faulkner sounded cautious about what comes after the pause. "You worry that after a month and a half of working almost primarily on safeguarding the software, that new things will be created by those who are trying to bust the software, and it will be in a never-ending cycle," she said, according to Modern Healthcare as quoted by Keeler.
She added that she expects "a different pace" going forward, with a constant need "to look at the next attack and figure out what to do to prevent anything from being hurt."
Epic's spokesperson struck a calmer note. "Our development roadmap hasn't changed since we presented it at our August 2026 Users Group Meeting," the spokesperson told Becker's Hospital Review, as quoted by Keeler.
Why are hospitals worried about hacks?
The big picture: healthcare has become one of the most targeted industries for hackers, who bet that providers will pay to keep stolen medical data from being published, TechCrunch reports.
- Change Healthcare: a 2024 ransomware attack on the UnitedHealth-owned company, which handles payments and billing for most Americans, exposed health data on more than 192 million people. The company paid the hackers twice not to publish the data.
- 2026 breaches: this year has seen breaches at electronic health records firm CareCloud, pharmaceutical distributor McKesson and UK health tech company Craneware, whose software is used across North America.
- Largest this year: the Department of Health and Human Services lists a breach at dental insurer DentaQuest, affecting 15 million people, as the largest healthcare data breach of 2026 so far.
Is AI changing cybersecurity?
Why it matters: this is one of the clearest examples yet of AI changing the security calendar for a major software company.
The same kind of AI that can help defenders find flaws faster can, in principle, help attackers find them too. That's the worry TechCrunch describes, and the "never-ending cycle" Faulkner says she fears.
Keeler frames the reaction to Epic's pause in three ways. Startups question how slow a company has to be to freeze development for six weeks. Customers ask what it means for the roadmap they were promised. And security chiefs see a vendor putting security first, which deserves some credit.
For more on Anthropic and its models, see our Anthropic topic page.
What happens next?
What's next: Faulkner's estimate is about six weeks of security-focused work. Epic hasn't published a more detailed public timeline, and it hasn't said when or whether it will describe the specific bugs, Cryptonomist notes.
A few things to watch:
- The end of the pause: whether Epic returns to its normal release schedule after six weeks, or, as Faulkner suggested, settles into a slower pace with more time spent on security.
- The roadmap: Epic's spokesperson says the plan shown at its August Users Group Meeting still stands, so customers will be watching whether promised features arrive on time.
- Disclosure: Epic hasn't described the bugs publicly, and the risk Martin described depends on how each customer has configured MyChart.
What it means for you
- No sign of a breach: the reports describe flaws found by AI and being fixed, not data that was stolen.
- Your provider holds your data: Epic says hospitals and clinics, not Epic, are responsible for patient records, so any notices would come from them.
- Stay alert: be careful with unexpected emails or texts about your MyChart account, and log in through your provider's usual app or website.
- Expect more of this: as AI makes finding bugs faster, more companies may pause to fix them.
The bottom line
Epic is taking about six weeks to fix MyChart security flaws that Anthropic's Mythos model uncovered, including one that could let outsiders view records without leaving a trace in some setups. Nothing suggests the flaws were exploited. It's a sign of how AI is speeding up the race between finding bugs and fixing them.
Key facts
- Company
- Epic, maker of MyChart
- Pause
- Most product development, for about six weeks
- Found by
- Anthropic's Mythos cybersecurity model
- Risk
- Some setups could allow record access without appearing in logs
- Scale
- Over 320 million patient records in the US
Got questions?
Quick answers, plain wordsWhy did Epic pause product development?
To focus on security. CEO Judy Faulkner told Modern Healthcare the pause would last about six weeks while Epic works on safeguarding its products, after Anthropic's Mythos model found flaws that could allow access to patient data.
What is MyChart?
MyChart is Epic's widely used software for accessing medical records. TechCrunch says it's used to maintain over 320 million patient records across US hospitals and doctor's offices.
What did the AI find?
Epic hasn't disclosed details. Its chief security officer, Stirling Martin, told The New York Times that some customer configurations of MyChart could let outsiders access patient records without the intrusion showing up in the software's logs.
Was my medical data stolen?
Nothing in the reports says the flaws were exploited. Epic is fixing them now. Epic also says it doesn't have access to patients' data, which is held by hospitals and doctor's offices.
Could the bugs be used to change records?
Unclear. Martin told the Times the AI model didn't say whether the bug could be used to alter records without detection, but that the risk was enough to fix the issues.
What is Anthropic's Mythos?
It's Anthropic's frontier cybersecurity AI model, which TechCrunch says Epic deployed on its software and which uncovered the flaws.
Is Epic's roadmap delayed?
An Epic spokesperson told Becker's Hospital Review that its development roadmap hasn't changed since it was presented at the August 2026 Users Group Meeting.
Do I need to do anything?
There's no specific action for patients in the reports. As always, watch for notices from your healthcare provider about your account, and be careful with unexpected messages asking for login details.
Why does this matter for healthcare?
Health data is a big target. TechCrunch notes the 2024 Change Healthcare ransomware attack exposed data on more than 192 million people.
SourcesTechCrunch
Topics and tagsAnthropic, security, healthcare, anthropic
Related stories

Met Police pauses Oxygen Forensics phone tool after US Russia charges
Scotland Yard has stopped using a phone data extraction tool while it reviews US charges that the company behind it hid Russian owners and Russian-built software.

GrayKey maker reportedly found a way around the iPhone's Inactivity Reboot
A leaked training video seen by 404 Media says Magnet Forensics' new tools keep a seized iPhone in an easier-to-search state, even after the reboot Apple added in iOS 18.1.

WhatsApp will now tell parents when their teen joins a group, but not what's said in it
WhatsApp launched optional parental controls for teen accounts, alerting parents when their teen joins or leaves groups while keeping actual messages end-to-end encrypted.
More in brief
- Slovenia's .si domain booms after the US starts calling AI 'super intelligence'Oct 2
- Tesla delivered 486,532 cars in Q3, beating every Wall Street estimateOct 2
- OpenAI fires three safety researchers over alleged sharing of sensitive infoOct 2
- AT&T, T-Mobile and Verizon make their dead zone satellite venture officialOct 2
- Amazon pledges $1B+ to the towns that host its data centersOct 2
- California man charged with smuggling $300M in Nvidia AI servers to ChinaOct 2