
Epic, the company behind the widely used MyChart patient portal, has paused most product development while it works to fix security flaws that could expose patients’ medical data. The move is unusual for a software company of Epic’s size, but it underscores how seriously the healthcare industry is taking a wave of cyber risks that are increasingly driven by AI-assisted vulnerability discovery.
Epic says the pause is about safeguarding MyChart and its systems
Epic founder and CEO Judy Faulkner told Modern Healthcare last month that the company expected the freeze on development to last about six weeks while it continued “safeguarding” its products. The work followed a deployment of Anthropic’s frontier cybersecurity model, Mythos, which reportedly surfaced security flaws that could put patient data at risk.
Epic has not publicly described the bugs in detail. But according to chief security officer Stirling Martin, some customer configurations of MyChart could allow outsiders to access patient records without leaving a trace in the software’s logs, according to The New York Times. Martin did not return TechCrunch’s request for comment.
What Epic says the bugs could do
The company has not said whether the issues affected every customer or only certain setups. It also has not disclosed whether the weaknesses could be used to change records, not just view them. Martin told the Times that the AI model did not indicate whether patient records could be altered without detection, but said the risk was serious enough to warrant remediation.
In a healthcare setting, even a read-only exposure can be damaging. Medical data can include diagnoses, prescriptions, insurance details, contact information and other personal information that can be valuable to criminals and deeply sensitive to patients.
Why MyChart matters so much
Epic’s MyChart software is used to manage more than 320 million patient records across hospitals and doctor’s offices in the United States. Epic says it does not hold customers’ medical data itself; instead, the responsibility for that data sits with healthcare providers such as hospitals and medical practices.
That structure does not reduce the impact of a software flaw. A bug that Epic did not know about could potentially affect multiple MyChart installations at once, creating a broad opening for attackers across the country.
The scale of Epic’s footprint helps explain why the company is treating the issue as a major operational priority. When a product used by hundreds of millions of patients shares a common vulnerability, the risk is not limited to one hospital or one city. It can spread wherever the affected configuration exists.
A rare pause, but one that reflects a changing threat landscape
It is uncommon for a large software vendor to slow product development to focus on security bugs. But the combination of high-value medical data and faster, AI-driven security research is changing how companies think about defense.
Tools that can rapidly identify weaknesses may help defenders patch products sooner. The same tools can also make it easier for attackers to find and exploit vulnerabilities before they are fixed. That has made security teams in healthcare, in particular, more wary of the pace at which breaches can unfold.
Epic’s decision suggests the company believes the safest path is to halt much of its product work until the exposure is addressed. For a platform as widely deployed as MyChart, that may be less disruptive than leaving a possible access flaw in place while new features continue to roll out.
Healthcare data remains a prime target
Healthcare breaches have become increasingly common because medical records are rich targets for extortion and identity theft. Attackers often assume providers may pay to avoid public leaks, especially when the stolen information is highly sensitive and tied to essential services.
The scale of recent incidents shows how costly those attacks can be. A 2024 ransomware attack on Change Healthcare, a health tech company owned by insurance giant UnitedHealth and responsible for payments and billing for most Americans, allowed hackers to steal health data on more than 192 million people. The company later paid the hackers twice not to publish the stolen data.
This year has also brought a series of other breaches affecting tens of millions of Americans. Those include medical records stolen in a breach at CareCloud, millions of rows of patient data taken from pharmaceutical distributor McKesson, and an unspecified amount of stolen data from U.K.-based health tech company Craneware, whose software is used across North America.
Largest healthcare breach so far in 2026
- The Department of Health and Human Services currently lists a breach at dental insurance company DentaQuest as affecting 15 million people.
- HHS says that is the largest healthcare-related data breach reported so far in 2026.
What Epic’s response signals for the industry
Epic’s move is a reminder that security maintenance can be as important as product innovation, especially in systems that handle medical information. For hospitals and doctors’ offices that rely on MyChart, the immediate concern is whether their configurations are among those affected and how quickly the vulnerabilities are being patched.
For the broader healthcare sector, the episode shows how AI tools are starting to alter the timing and scale of security response. If software can be probed faster, then patching and remediation have to move faster too.
That pressure may be uncomfortable for vendors, but in healthcare the stakes are unusually high. A flaw that reveals patient records is not just a technical issue; it can become a privacy, safety and trust crisis all at once.
Source: Original report
Was this helpful?
Explore more: Application Audit & Review More Cybersecurity Tech News
Last Modified: October 2, 2026 at 10:32 pm
5 views
