Epic pauses most development over MyChart vulnerabilities — TechCrunch
In the United States, Epic has paused most product development work to address vulnerabilities in its software and systems and strengthen protection against cyberattacks. The pause could last about six weeks, TechCrunch reports.
Anthropic model identified the vulnerabilities
Epic founder and CEO Judy Faulkner told Modern Healthcare that the company will focus on protecting its products. The issues were identified after using Anthropic's cybersecurity model Mythos.
Epic did not disclose the nature of the identified bugs. At the same time, the company's security director, Stirling Martin, told The Times that some MyChart configurations at customers could have allowed third parties to access medical records without such interference being recorded in system logs.
According to Martin, the model did not determine whether this vulnerability could have been used to alter medical records without detection. However, the company decided to fix the issues because of the potential risk.
More current news is available on the UA.News Telegram channel Telegram.
MyChart covers more than 320 million records
MyChart software is used by hospitals and medical offices in the United States to manage more than 320 million patient records. Epic says it does not have access to customers' medical data, as healthcare institutions themselves are responsible for it.
At the same time, a bug unknown to Epic could have allowed hackers to compromise several MyChart systems affected by the vulnerability and steal the data stored in them. TechCrunch notes that pausing product development to fix security bugs is an unusual decision.
The publication links such risks to the spread of artificial intelligence tools capable of quickly finding and exploiting cyber vulnerabilities. A ransomware attack on Change Healthcare in 2024 allowed attackers to steal the medical data of more than 192 million people. The U.S. Department of Health and Human Services currently lists an incident at insurance company DentaQuest, which affected 15 million people, as the largest healthcare-related data breach in 2026.