Epic Systems, the healthcare software behemoth behind MyChart, has temporarily suspended the majority of its product development efforts. The pause—expected to last around six weeks—is aimed at addressing serious security vulnerabilities uncovered across systems handling sensitive patient medical data. These flaws were identified using Mythos, a cutting-edge cybersecurity model developed by Anthropic. Epic’s leadership declared that securing its software stack is now its highest priority.
Chief among the concerns is a particular issue where certain customer configurations of MyChart may allow unauthorized third parties to access patient health records. Alarmingly, these breaches would leave no trace in the system’s logging mechanisms. While Epic hasn’t confirmed whether the bugs enable attackers to modify data without detection, it has flagged the risk as severe enough to warrant immediate corrective action.
MyChart is a key player in U.S. healthcare: its portal is used to manage over 320 million patient records maintained by hospitals and clinics nationwide. Although Epic maintains that it does not directly store or control these medical records—responsibility rests with the healthcare providers—experts warn that vulnerabilities unknown to Epic could still expose data across multiple installations.
Why This Move Is Unusual
It’s rare for any tech company to suspend product development purely to overhaul security, especially in the healthcare sector where software release cycles are often tightly managed for regulatory and logistical reasons. The decision reflects growing concern about the rising threat posed by AI-powered tools that can detect and exploit flaws faster than traditional security practices can address.
Healthcare has become a primary target for cybercriminals seeking high-value personal information. For instance, a 2024 ransomware incident involving a major billing and clinical data processor impacted nearly 200 million U.S. citizens. More recently, data breaches at companies such as CareCloud and pharmaceutical distributor McKesson have exposed millions of medical records, while a breach at dental insurer DentaQuest affecting 15 million enrollees is currently the largest healthcare incident of 2026.
Epic has not revealed the technical specifics of the bugs or the configurations in question. The company’s Chief Security Officer, Stirling Martin, has asserted that while Mythos did not confirm every possible exploit (such as undetected modifications of records), the risk profile warranted a full security review. Epic is doubling down on its defensive posture with this development freeze.
What to Watch
- How Epic communicates timelines for remediating these vulnerabilities and what safeguards it puts in place.
- Whether Epic releases a post-mortem explaining how such bugs slipped past existing security controls.
- Potential regulatory fallout—healthcare regulators may demand more disclosure and prompt patching of vulnerabilities.
- The broader impact on industry standards, especially how other EHR (electronic health record) providers respond to similar AI-identified security risks.
This unprecedented halt in product development underscores the growing firepower of AI tools like Mythos in unearthing security flaws that traditional audits have missed. For healthcare providers still using vulnerable setups, the risk isn’t just theoretical—it’s immediate. For Epic, the real test lies in restoring trust while modernizing defenses. Industries beyond healthcare will be watching closely: when AI reveals unseen holes in systems, ignoring them isn’t an option anymore.