Epic has paused most product development while it works to address security flaws that could put patients’ data at risk. The company makes MyChart, software used to access medical records.
Epic founder and chief executive Judy Faulkner told Modern Healthcare last month that the pause would likely last six weeks. The work follows a deployment of Anthropic’s Mythos cybersecurity model, which uncovered flaws that could allow access to patient data. Epic has not disclosed the bugs’ details.
Epic chief security officer Stirling Martin told The New York Times that some customer configurations of MyChart could let outsiders access patient records without the intrusion appearing in software logs. He said the model did not establish whether the flaw could be used to alter records undetected, but considered the risk sufficient to warrant fixes. Martin did not respond to TechCrunch’s request for comment.
Epic says it does not have access to customer medical data; healthcare providers are responsible for it. MyChart is used to maintain more than 320 million patient records across hospitals and doctors’ offices in the United States. The source report warns that an unknown flaw could expose data across multiple affected systems.
The pause comes amid growing concern that AI tools could help attackers find and exploit security vulnerabilities. A 2024 ransomware attack on Change Healthcare resulted in the theft of health data belonging to more than 192 million people. The U.S. Department of Health and Human Services lists a 2026 breach at DentaQuest affecting 15 million people as the largest healthcare-related breach of the year so far.
Comments
0No comments yet. Be the first to comment.