Skip to content
TECH CEO Daily

Epic pauses most product development to fix MyChart security flaws found with Mythos

CEO Judy Faulkner said the pause would likely last six weeks; Epic's security chief said some MyChart setups could allow access without a log entry.

By · Editor

· 3 min read · Fact-checked

The 60-second brief

  • 1Epic paused most product development to fix security flaws; CEO Judy Faulkner said the pause would likely last six weeks.
  • 2Epic's security chief said some MyChart configurations could let outsiders access patient records without the intrusion being logged.
  • 3The flaws surfaced after Epic deployed Anthropic's Mythos model; no report cited says attackers exploited them.

Video summary · 0:45

Watch: Epic pauses most product development to fix MyChart security flaws found with Mythos

The story in under a minute, with captions. Tap to play with sound.

Video summary · Voiced with a synthetic voice.

The news

Epic Systems, the company behind the MyChart patient portal, has paused most product development to fix MyChart security flaws that could put patient data at risk, TechCrunch reported on October 2. CEO Judy Faulkner said the pause would likely last six weeks.

Faulkner disclosed the pause in September in an interview with Modern Healthcare, saying work would continue on safeguarding the company's products, according to TechCrunch. The flaws surfaced after Epic deployed Mythos, the frontier cybersecurity model built by Anthropic, which identified weaknesses in the software.

Epic's chief security officer, Stirling Martin, told The New York Times that some customer configurations of MyChart could allow outsiders to access patient records without the intrusion being recorded in the software's logs, as reported by TechCrunch. Martin said the model had not confirmed whether the flaw could be used to alter records undetected, but argued it posed enough risk to fix.

The scale is large. MyChart is used to maintain more than 320 million patient records across hospitals and doctor's offices in the United States, according to TechCrunch. Epic says it does not have access to customers' medical data; that responsibility sits with the hospitals and practices that run the software.

That split is part of the risk. TechCrunch noted that a single flaw unknown to Epic could let hackers compromise many separately run MyChart systems across the country and take the data stored in them.

The reports cited by TechCrunch did not say attackers had exploited the flaws. They also did not identify which MyChart configurations are affected or say exactly when the pause began.

The numbers

Expected length of Epic's pause, per CEO Judy Faulkner
Likely six weeks
Patient records maintained in MyChart (TechCrunch)
More than 320 million
People whose data was stolen in the 2024 Change Healthcare attack
More than 192 million
Largest healthcare breach of 2026 on HHS list (DentaQuest)
15 million people
High- or critical-severity flaws found via Anthropic's Project Glasswing (May 2026)
More than 10,000

Why CEOs should care

For health systems that run Epic, the first step is a direct conversation with the vendor. Chief information security officers (CISOs) should ask Epic whether their MyChart setup matches the configurations Martin described, what changes the customer must make, and when fixes will ship. Because the reported risk involves access that may not appear in MyChart's own logs, security teams should also ask which other records, such as network, identity-provider or web application firewall logs, could reveal past misuse.

Chief information officers and CFOs should plan for roadmap slippage. A pause of most product development at a medical records giant means features customers expected in late 2026 may arrive later, which can ripple into project budgets, go-live dates and staffing plans. Vendor-risk teams can use the moment to update reviews of every critical software supplier: ask whether it runs AI-assisted code audits, how it will tell customers what it finds, and how quickly it can ship fixes.

Boards and general counsel should weigh the compliance angle. Epic says providers, not Epic, are responsible for the patient data in their systems. If a flaw could allow access without a log entry, a provider may find it harder to show that no breach occurred, a question to settle with counsel before any notification decision is needed.

The bigger picture

Epic's move is an early test of what happens when AI finds flaws faster than vendors can fix them. Anthropic said in May that its Project Glasswing program, which gives vetted partners access to Mythos, had uncovered more than 10,000 high- or critical-severity vulnerabilities, and that the limit on fixing them was human capacity to triage and patch, CyberScoop reported. TechCrunch noted that it is rare for a company to pause development to fix security bugs.

Healthcare remains a prime target. The 2024 ransomware attack on Change Healthcare, owned by UnitedHealth Group (UNH), let hackers steal health data on more than 192 million people, TechCrunch noted. The Department of Health and Human Services lists a breach at DentaQuest affecting 15 million people as the largest healthcare-related breach of 2026 so far. TechCrunch also noted that 2026 has brought breaches at electronic health data company CareCloud, pharmaceutical distributor McKesson (MCK) and U.K.-based health tech firm Craneware.

What’s next

Watch for Epic to tell customers which MyChart configurations need changes and when fixes will arrive, and for any sign that the six-week estimate stretches. Health systems should also expect other software suppliers that use AI models to audit their code to report similar findings, and should ask them now how they plan to handle the fixes.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

Companies in this story

Epic SystemsMyChartAnthropicHealthcare cybersecurity

Earlier coverage of Anthropic

All Anthropic coverage →

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.