Epic, the software technology leader responsible for the popular MyChart platform, has decided to halt most of its product development efforts. This action is intended to enhance the security of its software and systems against potential cyber threats. The pause is anticipated to last approximately six weeks as Epic works to resolve recently discovered security issues.
Last month, Judy Faulkner, the founder and CEO of Epic, revealed that the company is taking measures to “safeguard” its products. This initiative comes after the implementation of Anthropic’s frontier cybersecurity model, Mythos, which uncovered security flaws that could permit unauthorized access to patient data. Stirling Martin, the chief security officer at Epic, mentioned in a recent interview that certain configurations of MyChart could allow external parties to access patient records without leaving any trace of intrusion in the software’s logs.
While Epic has not provided details about the specific vulnerabilities, Martin indicated that the AI model did not clarify whether these bugs could be exploited to modify patient records undetected. Nevertheless, he emphasized the urgency of addressing these concerns, labeling them as a considerable risk.
MyChart serves a crucial function in the healthcare sector, managing over 320 million patient records across hospitals and medical offices throughout the United States. Although Epic asserts it does not have access to its customers’ medical data–stating that healthcare providers are responsible for safeguarding this information–a bug unknown to Epic could potentially compromise numerous MyChart systems nationwide, putting sensitive patient data in jeopardy.
Halting product development is an uncommon move for a company like Epic. Generally, organizations prioritize launching new features over tackling security issues. However, the emergence of AI tools that can swiftly pinpoint and exploit vulnerabilities has raised concerns about how easily attackers might gain access to sensitive information.
This year has witnessed a concerning increase in healthcare breaches, with hackers increasingly targeting organizations to acquire sensitive health and medical data. The prevailing assumption is that healthcare providers would be willing to pay to prevent the consequences of having their data released online. For example, a ransomware attack in 2024 on Change Healthcare resulted in hackers stealing data impacting over 192 million individuals–most of whom are in the United States. This incident compelled the company to pay the hackers twice to avert the publication of the stolen data.
Moreover, a series of data breaches in 2026 has affected tens of millions of Americans. Significant breaches have occurred at major healthcare and tech companies, including CareCloud, which confirmed that 3.7 million patients had their medical records compromised, and McKesson, which faced a breach impacting millions of patient records. Even Craneware, a health tech company based in the U.K., experienced a breach that resulted in an unspecified amount of stolen data from its software utilized across North America.
At present, the Department of Health and Human Services identifies a breach at DentaQuest, which affects 15 million people, as the largest healthcare-related data breach of 2026. This event underscores the increasing risks encountered by healthcare organizations and the urgent need to address security vulnerabilities as they emerge.



