Medical records giant Epic pauses product development to fix security bugs that risk patients’ data
Epic Systems has paused most product development for several weeks to remediate security vulnerabilities discovered after deploying Anthropic’s cybersecurity model Mythos. Company founder Judy Faulkner said the pause will likely last six weeks while Epic focuses on safeguarding its products, including the widely used MyChart patient portal.

Why It Matters
The pause affects software that supports access to more than 320 million patient records across the U.S., and Epic's move underscores rising concerns that AI tools can rapidly surface vulnerabilities which, if exploited, could expose large volumes of sensitive health data.
Key Facts
- Company: Epic Systems
- Product affected: MyChart patient portal
- Scope of records: Over 320 million patient records
- Planned pause duration: Likely six weeks (as stated by Judy Faulkner)
- Discovery method: Deployment of Anthropic's Mythos cybersecurity model
Epic Systems has temporarily halted most product development to address security issues identified after the company deployed Anthropic’s Mythos cybersecurity model. Founder and CEO Judy Faulkner told Modern Healthcare the pause would likely last about six weeks while Epic works to "safeguard" its products, a move aimed at preventing potential cyberattacks.
Epic has not publicly detailed the technical nature of the vulnerabilities. Stirling Martin, Epic’s chief security officer, told The New York Times that certain customer configurations of MyChart could permit outsiders to access patient records without generating logs that would record the intrusion. Martin also said the AI model did not indicate whether an exploit could alter patient records without detection, but characterized the risk as sufficient to warrant remediation.
MyChart is used to manage medical records for more than 320 million patients across U.S. hospitals and physician offices. Epic says it does not possess customer medical data directly; responsibility for the data rests with healthcare providers. However, Epic acknowledged that an undisclosed bug could enable attackers to compromise multiple MyChart installations and access the information they store.
The decision to pause development is unusual but comes amid broader concern about AI tools accelerating the discovery and potential exploitation of software vulnerabilities. The healthcare sector has faced a string of major breaches in recent years, including a 2024 ransomware attack on Change Healthcare that exposed data on about 192 million people, and several 2026 incidents affecting firms such as CareCloud, McKesson, and Craneware. The Department of Health and Human Services currently lists a DentaQuest breach affecting 15 million people as the largest healthcare-related breach of 2026 so far.
Keep Reading

Apple will limit Mac disk access as AI agents ‘substantially’ increase risk

Netflix is pivoting away from prestige

Call it AI, call it Super Intelligence, only 2% of consumers are buying it
