Tech
Gist from Techcrunch

Epic Systems Halts Product Development to Patch Critical Security Vulnerabilities in MyChart

Summarized October 2, 2026
Jump to key takeaways

Major Security Pause at Healthcare Software Leader

Epic Systems, the dominant provider of medical records software serving over 320 million patient records across U.S. hospitals and doctor's offices, has suspended nearly all product development for approximately six weeks. Founder and CEO Judy Faulkner announced the halt to focus entirely on addressing security vulnerabilities discovered through deployment of an advanced AI cybersecurity tool. The company's MyChart software—widely used by patients to access their medical information—contains flaws that pose direct risks to patient data confidentiality.

The Nature of Discovered Vulnerabilities

Epic's chief security officer disclosed that certain customer configurations of MyChart could allow unauthorized external access to patient records without generating any audit trail or intrusion logs. This represents a particularly dangerous scenario because attackers could potentially breach systems and steal sensitive medical data while leaving no detectable evidence of the breach. The security officer noted that while the AI model did not definitively establish whether the vulnerabilities could be weaponized to alter patient records undetected, the risk level justified immediate remediation efforts.

The vulnerabilities were uncovered through Epic's deployment of Anthropic's Mythos frontier cybersecurity model, representing a shift toward using advanced artificial intelligence to proactively identify weaknesses before malicious actors do. The company has not disclosed specific technical details about the bugs or provided estimates of how many customer systems might be affected.

Broader Healthcare Security Crisis

Epic's action underscores an escalating crisis in healthcare data security. The healthcare sector has become increasingly attractive to cybercriminals seeking highly valuable personal health information, which commands premium prices on the black market and provides leverage for ransomware demands. A 2024 attack on Change Healthcare—a major health technology company owned by UnitedHealth that processes payments and billing for most Americans—resulted in the theft of health data affecting over 192 million people. The attackers demanded and received payment twice to prevent publication of the stolen information.

This year alone has witnessed multiple major healthcare data breaches. CareCloud, an electronic health records storage company, suffered a significant breach of patient records. McKesson, a major pharmaceutical distributor, lost millions of rows of patient data. The United Kingdom-based health tech company Craneware, whose software operates across North America, experienced a breach of unspecified proportions. The Department of Health and Human Services currently identifies a 2026 breach at dental insurance provider DentaQuest—affecting 15 million people—as the year's largest healthcare-related data breach so far.

AI's Double-Edged Sword in Cybersecurity

The decision by Epic to pause development reflects growing recognition that artificial intelligence tools capable of identifying vulnerabilities could equally enable attackers to exploit them more rapidly and at greater scale. Security researchers and industry observers have raised concerns that as AI becomes more sophisticated in finding security flaws, bad actors gain proportionally more capability to weaponize those discoveries before patches can be deployed. The fact that Epic chose to deploy such a powerful model internally—accepting the risk that vulnerabilities would be discovered—demonstrates how serious industry leaders now view the need for proactive defense.

This move to pause development remains uncommon across the software industry, making Epic's decision particularly notable. Most companies attempt to remediate security issues without suspending new features and improvements. Epic's commitment to a multi-week freeze signals the organization's assessment that the vulnerabilities pose sufficient risk to warrant pausing revenue-generating product enhancements.

Implications for Healthcare Infrastructure

MyChart's ubiquity across American healthcare infrastructure means that vulnerabilities in the platform have systemic implications far beyond any single organization. Hospitals and doctor's offices relying on the software cannot themselves patch the underlying flaws—they depend entirely on Epic to address the problems. This creates a vulnerability window during which patient data across hundreds of healthcare organizations remains at risk. The pause represents Epic's effort to compress that window as much as possible by dedicating all available engineering resources to security remediation.

Key Takeaways

  • Epic Systems pauses product development for six weeks to fix critical security flaws
  • MyChart vulnerabilities could allow unauthorized patient record access without detection
  • Platform secures over 320 million patient records across U.S. healthcare system
  • 2024 Change Healthcare breach exposed data on 192 million Americans
  • DentaQuest 2026 breach currently largest healthcare data breach at 15 million
  • AI cybersecurity tools finding vulnerabilities faster than traditional methods
  • Healthcare sector increasingly targeted for ransomware and data theft attacks
Read original article at Techcrunch

Summarize any article in seconds

Gist is a free AI reader for your browser, iPhone, and Android. Get concise summaries and key takeaways from any article or podcast.

Get Gist — Free
⚡ Instant summaries 💬 Chat with articles 🔒 Privacy-first