Epic pauses product development to fix security flaws found by AI model

The electronic health records giant halts work for six weeks after Anthropic's Mythos tool uncovers vulnerabilities in MyChart software.

By LineZotpaper
Published
Read Time2 min
Epic, the software company behind the widely used MyChart patient portal, has paused most product development for an estimated six weeks to address security flaws that could allow outsiders to access patient data without detection. The bugs were discovered by Anthropic's frontier cybersecurity model Mythos.

Epic founder and CEO Judy Faulkner told Modern Healthcare that the pause would last about six weeks while work continues on safeguarding the company's products. The decision follows a deployment of Anthropic's Mythos, a frontier AI cybersecurity model, which unearthed security flaws that could allow unauthorized access to patients' data.

Epic's chief security officer Stirling Martin told The New York Times that some customer configurations of MyChart could allow outsiders to access patient records without recording any intrusion in the software's logs. Martin noted that the AI model did not say whether the bug could be exploited to alter patient records without detection, but argued it was enough of a risk to remediate the issues.

Epic has not disclosed the specific nature of the bugs. MyChart maintains over 320 million patient records across hospitals and doctors' offices in the United States. Epic says it does not have access to customers' medical data; that responsibility falls on healthcare providers like hospitals and doctor's offices. But a bug unknown to Epic could allow hackers to compromise multiple affected systems and raid the stored data.

It is rare for a company to pause development to fix security bugs, but the advent of AI tools capable of rapidly finding and exploiting security vulnerabilities has raised concerns. Healthcare breaches are increasingly common, with hackers targeting highly sensitive health data. A ransomware attack on Change Healthcare in 2024 affected more than 192 million people, and this year breaches at CareCloud and McKesson have affected tens of millions of Americans.

§

Analysis

Why This Matters

  • The pause highlights how AI-driven security tools are forcing major software vendors to prioritize vulnerability remediation over new features.
  • With over 320 million patient records at risk, a flaw in MyChart could expose the health data of a large portion of the US population.
  • The incident may set a precedent for other healthcare IT companies to halt development to perform AI-assisted security audits.

Background

Epic Systems is one of the largest providers of electronic health record software in the United States, with its MyChart portal serving as the primary patient access tool for many hospitals. The company has historically focused on product innovation, but the discovery of vulnerabilities by Anthropic's Mythos model has prompted an unusual halt. The healthcare sector has been a frequent target of ransomware attacks, as stolen medical data is highly valuable and providers often pay ransoms to prevent data leaks.

Key Perspectives

Epic Systems: The company prioritizes patient data security and decided to pause development to address the urgent risks identified by the AI audit, even at the cost of delaying new features. Healthcare Providers: Hospitals and doctor's offices that rely on MyChart are concerned about potential data breaches and may need to reassess their configurations and security practices. Critics and Security Experts: Some may question whether the pause is sufficient and whether Epic should have proactively scanned for such bugs earlier, especially given the rise in healthcare data breaches.

What to Watch

  • Whether Epic can complete the remediation within the six-week timeline and disclose the specific vulnerabilities.
  • How Anthropic's Mythos model and similar AI tools are adopted by other companies for security auditing.
  • Any subsequent reports of data breaches exploiting the MyChart vulnerabilities before the fix is deployed.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.