Epic founder and CEO Judy Faulkner told Modern Healthcare that the pause would last about six weeks while work continues on safeguarding the company's products. The decision follows a deployment of Anthropic's Mythos, a frontier AI cybersecurity model, which unearthed security flaws that could allow unauthorized access to patients' data.
Epic's chief security officer Stirling Martin told The New York Times that some customer configurations of MyChart could allow outsiders to access patient records without recording any intrusion in the software's logs. Martin noted that the AI model did not say whether the bug could be exploited to alter patient records without detection, but argued it was enough of a risk to remediate the issues.
Epic has not disclosed the specific nature of the bugs. MyChart maintains over 320 million patient records across hospitals and doctors' offices in the United States. Epic says it does not have access to customers' medical data; that responsibility falls on healthcare providers like hospitals and doctor's offices. But a bug unknown to Epic could allow hackers to compromise multiple affected systems and raid the stored data.
It is rare for a company to pause development to fix security bugs, but the advent of AI tools capable of rapidly finding and exploiting security vulnerabilities has raised concerns. Healthcare breaches are increasingly common, with hackers targeting highly sensitive health data. A ransomware attack on Change Healthcare in 2024 affected more than 192 million people, and this year breaches at CareCloud and McKesson have affected tens of millions of Americans.