AI

Epic Halts Product Development to Fix MyChart Bugs Found by Anthropic's Mythos

Epic has paused most product development for about six weeks to address security flaws in MyChart uncovered after a deployment of Anthropic's Mythos model.

Epic has paused most of its product development to address security vulnerabilities in its software and systems, CEO Judy Faulkner said, according to a report from techcrunch.com. Faulkner said the pause would likely last six weeks.

The flaws were found after a deployment of Anthropic's cybersecurity model Mythos. Epic's chief security officer, Stirling Martin, said some customer configurations of MyChart could let outsiders access patient records without logging an intrusion.

Martin said the AI model did not determine whether the bug could be exploited to alter patient records undetected.

MyChart maintains over 320 million patient records across U.S. hospitals and doctor's offices. The pause comes amid a run of major healthcare data breaches. In 2024, a ransomware attack on Change Healthcare allowed hackers to steal health data on more than 192 million people, and the company paid the hackers twice not to publish the data.

This year, breaches at CareCloud, McKesson and Craneware affected tens of millions of Americans. The Department of Health and Human Services lists a DentaQuest breach affecting 15 million people as the largest healthcare-related data breach of 2026 so far.

Quick answers

Why did Epic pause product development?

Epic paused most of its product development to address security vulnerabilities in its software and systems, including some customer configurations of MyChart.

How long will Epic's development pause last?

CEO Judy Faulkner said the pause would likely last six weeks.

What did Anthropic's Mythos model find?

The security flaws were found after a deployment of Anthropic's cybersecurity model Mythos. Epic CSO Stirling Martin said some MyChart configurations could let outsiders access patient records without logging an intrusion, though the model did not determine whether the bug could be exploited to alter records undetected.

Source