Epic pauses new product development to fix MyChart security flaws
Epic, the company behind MyChart, suspended most of its product development after an Anthropic AI model found flaws that allowed access to patient records without leaving a trace in the logs.
Epic, the maker of the MyChart electronic health record software used by hospitals and clinics across the United States, paused most of its new product development to fix security flaws that put patient data at risk. The company's founder and CEO, Judy Faulkner, told Modern Healthcare last month that the pause should last about six weeks while the team works on what she called "hardening" the company's products.
The trigger was Mythos, a cybersecurity-focused AI model developed by Anthropic. When run against Epic's systems, Mythos found vulnerabilities that, in certain MyChart configurations used by customers, would let third parties access patient records without the intrusion being logged by the software. The information was given by Epic's chief security officer, Stirling Martin, to The New York Times.
A flaw that leaves no trace
The most serious part of the problem isn't just the unauthorized access: it's the lack of evidence. According to Martin, Mythos didn't confirm whether the flaw would also allow altering records without leaving a trace in the audit logs, but the possibility was already considered enough of a risk to justify the pause. Martin did not respond to TechCrunch's requests for comment.
For anyone building any system that handles sensitive data, this is the kind of flaw that is most expensive to fix after the fact: if the log didn't record the intrusion, there's no way to know for certain how many times it was exploited before being discovered. Auditing that fails silently is worse than no auditing at all, because it creates a false sense of security.
MyChart holds more than 320 million patient records across hospitals and clinics in the US. Epic says it doesn't have direct access to customers' medical data, a responsibility that falls to each hospital or clinic running its own instance of the system, but a flaw unknown to the vendor can compromise multiple MyChart instances at once, across different healthcare providers.
Why halting development is rare
Halting the release of new features to focus on security is an uncommon decision for a company the size of Epic, which dominates the US electronic health record market. TechCrunch ties this move to a broader concern: AI tools capable of finding and exploiting vulnerabilities quickly are giving attackers (and defenders too) a discovery speed that manual security reviews can't keep up with.
This flips a familiar logic for anyone working with fast release cycles. For years, the pressure in digital health products was to ship features quickly to gain ground in hospitals already using the system. Epic's case shows the other side of that bet: when the attack surface grows faster than the capacity to audit it, the fix comes as a full pause, not an isolated patch.
The pattern behind it: 2026 has already seen bigger leaks
Epic's episode joins a list of recent incidents in the US healthcare sector:
- Change Healthcare (2024): a ransomware attack exposed data from more than 192 million people, most of the US population; the company, owned by insurer UnitedHealth, paid the hackers twice to keep the data from being published.
- CareCloud: a breach exposed records stored by the electronic health data giant.
- McKesson: millions of lines of patient data stolen from the pharmaceutical distributor.
- Craneware: a British healthtech company whose software is used in North America, also suffered an unquantified data theft.
- DentaQuest: a dental insurer with a leak affecting 15 million people, listed by the U.S. Department of Health as the largest breach in the sector so far in 2026.
The pattern is clear: health data is a preferred target because hackers bet that hospitals and insurers will pay to avoid having the information published, as happened with Change Healthcare.
What changes for those integrating with Epic or building something similar
Epic hasn't publicly disclosed any customers in Brazil, and the case reported by TechCrunch is specific to the US market. But Brazilian healthtechs and hospital IT teams that do international integration (via standards like HL7 and FHIR, used by Epic's own API ecosystem) have direct lessons to take away:
- Auditing is part of the integration contract, not an extra. Before signing any partnership with a foreign electronic health record vendor, it's worth demanding evidence of how the access log is validated, not just that it exists.
- AI-driven pentesting is going from a differentiator to an expectation. If a vendor the size of Epic needed a model like Mythos to find its own blind spot, smaller teams can't assume manual security review is enough.
- LGPD, Brazil's data protection law, demands what Epic only discovered too late. It requires logging of processing operations involving sensitive data, including health data. A log that fails silently, like the one described in the MyChart case, would be a compliance failure here too, not just a security one.
Epic hasn't publicly detailed the technical nature of the flaws, nor confirmed when the six-week pause ends. It also isn't clear whether affected customers were notified individually or whether Mythos found anything beyond the access risk. Those details, when (and if) they come, will show whether the fix was a one-off configuration issue or an actual architecture problem.
Translated from the Brazilian Portuguese original · Read the original
Uber Eats rebuilds search pipeline and cuts latency by 50%
The company swapped the metric that measured speed, reduced retrieval and ranking work, and used agentic AI to find optimizations. The result: half the end-to-end time in Uber Eats search.