Epic Pauses Product Development to Fix Patient-Data Flaws Found by AI
Some MyChart configurations could allow access without an intrusion log, Epic’s security chief said. Whether the flaws could enable undetected record changes remains unverified.
Loading page…
Some MyChart configurations could allow access without an intrusion log, Epic’s security chief said. Whether the flaws could enable undetected record changes remains unverified.
Listen to this story
Epic is using Anthropic’s Claude Mythos to address security flaws in some MyChart customer configurations, and the company halted most product development while implementing fixes. The disclosed concern is that outsiders could reach records without an intrusion being logged; Epic’s security chief said the model had not established whether records could also be changed undetected, and Epic has not revealed the bugs’ technical details. The response has no confirmed end date, while healthcare providers still need access to systems used in patient care.
CEO Judy Faulkner said in September that the pause would likely last six weeks, but no completion date has been confirmed.
The concern involves some MyChart customer configurations; Epic has not disclosed the flaws or the affected technical details.
MyChart is used for more than 320 million patient records; KLAS put Epic’s 2025 acute-care EHR market share at nearly 44%.
An AI security check gave Epic a reason to stop building some new features and fix potential routes into patient records. Anthropic’s Claude Mythos surfaced flaws that could allow access without detection, according to Epic’s security chief. But the model did not determine whether someone could also change those records without leaving a trace.
CEO Judy Faulkner disclosed the vulnerabilities and Epic’s use of the tool at a September conference, according to The New York Times, as cited by Wisconsin Public Radio. WPR’s October 7 coverage also examined the difficulty of repairing health software that doctors must keep using, adding a practical constraint to the company’s security response.
The specific concern involves some customer configurations of MyChart, Epic’s software for accessing patient medical data. Chief security officer Stirling Martin told the Times that outsiders could potentially reach records without the software logging an intrusion, according to TechCrunch’s October 2 account. That makes the logging gap part of the risk: the software would not record the intrusion.
Martin said Mythos had not determined whether the bug could enable undetected changes to patient records. He nevertheless considered the risk sufficient to warrant remediation. Epic has not disclosed the nature of the bugs, leaving the technical details of the affected configurations and the flaws themselves undisclosed.
The response reached beyond a routine patching assignment. TechCrunch reported that Epic paused most product development to safeguard its software and systems. Faulkner told Modern Healthcare in September that the pause would likely last six weeks. WPR described the company as pausing certain new product elements to implement patches identified through the AI work; neither description supplies a confirmed completion date.
The problems are: how do we keep it updated, and at the same time allow doctors to access these resources?
Rahul Gomes, UW-Eau Claire computer science department chair, speaking to WPR
Gomes told WPR that AI accelerates vulnerability research for both companies and attackers. Work that once required experienced researchers to spend days or weeks reading code and testing configurations can move faster. Healthcare adds an operational constraint, he said: shutting down systems for an update can interrupt doctors’ access to resources needed for patient care.
Epic’s reach makes that challenge consequential. MyChart is used to maintain more than 320 million patient records across U.S. hospitals and doctors’ offices, TechCrunch reported. Epic says it does not have access to customers’ medical data; responsibility for that data rests with healthcare providers. Separately, KLAS Research put Epic’s share of the acute-care electronic health record market at nearly 44 percent in 2025, WPR reported.
Gomes sees advantages and risks in that concentration. A large vendor has resources to use advanced models and standardize security work. But a common platform also creates a shared weakness if an attacker gains access. In his assessment, access to current models improves defenders’ exposure to possible attacks, increasing their chances of protecting patient data.
Loading discussion...
Join the conversation
Explain whether stronger shared defenses outweigh the risk of a shared weakness.
Be the first to share a perspective or an experience.
Reader comments
Newest comments first. Replies stay oldest first.