
Epic halts most development to fix MyChart flaws
An Anthropic AI model found portal settings that could let someone read patient records without a trace. Epic reports no attacks and has not published a CVE.
Epic Systems, which sells electronic health record software to hospitals across the United States, has stopped almost all of its product development to focus on security. Founder and CEO Judy Faulkner said the pause will last about six weeks, according to Modern Healthcare, which picked up her remarks at a summit it hosted.
The reason is a set of flaws Epic found with Mythos, Anthropic's cybersecurity model. Stirling Martin, Epic's chief security officer, told The New York Times that some MyChart configurations, the portal patients use to view their records, could let a third party read records without the access showing up in the logs. The statement reaches us through TechCrunch, which cites the Times; the original text is paywalled and could not be read, and Epic has not issued a statement of its own.
What is known and what is not
No attacks have been confirmed. Martin said the model could not establish whether someone could alter records without being detected, and that the risk was enough to justify a fix. No CVE identifier, affected version or numbered patch has been published, so it is not known how many hospitals have the risky configuration.
Medical Daily adds that hundreds of projects are under heightened review and that the pause would end around early November, a calculation by the outlet itself. An Epic spokesperson said its roadmap has not changed since August, and the company says it will keep working on its AI features.
The patient counts do not match: TechCrunch cites more than 320 million records in MyChart, and Quartz says 325 million.
How Mythos reached Epic
Anthropic launched Project Glasswing in April, a program in which companies run Mythos against their own code to find and repair weaknesses. On June 2, Anthropic expanded it to sectors such as health care, energy, water and communications.
No action has been announced for patients, and Epic says part of the fixes depends on each hospital's configuration. No effects in Mexico are known. Still pending is a customer notice or a CVE saying which configurations need fixing and by when.



