Epic is the software technology giant behind the widely used MyChart software, which is used to access patients' medical data. As the company is making efforts to protect its software and systems from cyberattacks, Epic has suspended most of its product development.
Epic founder and CEO Judy Faulkner stated last month to Modern Healthcare that security vulnerabilities were discovered after the deployment of Mythos, a cutting-edge network security model from Anthropic, which may put patient data at risk. Therefore, this suspension is expected to last for about six weeks, during which time the company will continue to carry out "strengthening" efforts.
The company has not yet disclosed the specific nature of these vulnerabilities, but the Chief Security Officer Stirling Martin told The Times that some configurations of MyChart may allow external personnel to access patient records without any intrusion being recorded in the software logs.
Martin did not respond to TechCrunch's request for a comment. He told The Times that the AI model does not indicate whether this vulnerability can be exploited to tamper with patient records without being detected, but he believes that this risk is sufficient to prompt the company to fix these issues.
The widely used MyChart software is used to maintain over 320 million patient records in hospitals and doctors' offices across the United States. Epic indicates that the company cannot access patients' medical data; this responsibility lies with healthcare providers such as hospitals and doctors' offices. However, an unknown vulnerability Epic may allow hackers to breach multiple affected MyChart systems across the U.S. and steal the data stored within them.
It is not common for companies to pause development in order to fix security vulnerabilities, but with the emergence of AI tools that can quickly identify and exploit such vulnerabilities, people have begun to worry that attackers will find it easier to steal data.
Data breaches in the healthcare industry are becoming increasingly common as hackers attempt to obtain highly sensitive health and medical information, assuming that medical institutions will pay to prevent them from releasing this information online. In 2024, Change Healthcare, a medical technology company under the insurance giant UnitedHealth that handles payments and billing for most Americans, was attacked by ransomware. Hackers stole the health data of over 192 million people, covering the majority of the U.S. population. The company paid the hackers twice, requesting that they not disclose the stolen data.
This year, a series of data breaches involving medical and technology companies have affected tens of millions of Americans. These include the theft of medical records from the electronic health data storage giant CareCloud after an intrusion, the leakage of millions of patient records by the pharmaceutical distributor McKesson, and an unspecified amount of data stolen from the UK-based medical technology company Craneware. The software from Craneware is used in various regions across North America.
The largest healthcare-related data breach incident in 2026 currently listed by the U.S. Department of Health and Human Services is one involving the dental insurance company DentaQuest, which affected 15 million people.












