Epic Halts Most Product Development to Fix MyChart Security Gaps

Epic has paused most of its product development while it works to protect its software and systems from cyberattacks. TechCrunch
Founder and chief executive Judy Faulkner said the pause would likely last six weeks while the company focuses on safeguarding its products.
Deployment of Mythos, Anthropic's frontier model for finding cybersecurity flaws, unearthed security flaws in Epic systems that could allow access to patients' data. Epic makes MyChart, the software patients use to access their medical data.
Chief Security Officer Stirling Martin said some customer configurations of MyChart could allow outsiders to access patient records without recording any intrusion in the software's logs, the files that record who viewed what and when.
MyChart holds more than 320 million patient records across hospitals and doctor's offices in the United States. Epic says it does not have access to customers' medical data, with responsibility falling on healthcare providers such as hospitals and doctor's offices.
A 2024 ransomware attack on Change Healthcare allowed hackers to steal health data on more than 192 million people. The U.S. Department of Health and Human Services lists a breach at dental insurance company DentaQuest affecting 15 million people as the largest healthcare-related data breach of 2026 so far.
Separately, Epic faces regulatory pressure. Texas Attorney General Ken Paxton sued Epic in December, accusing the company of shutting out would-be rivals by holding data hostage. Reuters The U.S. Federal Trade Commission was probing health-records company Epic Systems as of August 2026.
The broader context here is the difference between a central code flaw and a deployment problem. Central code can be patched once and shipped to all customers. A risky customer configuration must be found and corrected site by site. Each hospital and clinic runs its own instance, access policies and integrations. That work is slower. It requires inventory, validation and coordination with local IT teams.
Looking at what this means for security operations, logging is central. When access does not create a log entry, detection fails. Scoping fails. Response becomes guesswork. Teams cannot answer the basic questions of what was accessed, when and by whom. They must assume broader exposure. For systems holding clinical histories, prescriptions, billing identifiers and contact details, that uncertainty carries operational and legal cost.
In my view, the pause itself is the signal to take seriously. Halting most product development concentrates review, testing and field remediation. It accepts delay elsewhere. Roadmaps slip. Integration work waits. For an electronic health record supplier at this scale, that is an expensive tradeoff. It is usually preferable to silent data access, particularly where audit trails are incomplete.
For the longer term, two shifts are worth watching. First, use of frontier models for proactive security review is becoming normal operational practice. Automated review finds classes of issues around authentication, confirming user identity, authorization, controlling what users can access, and logging that manual review misses under schedule pressure. Second, shared responsibility only works when defaults are safe and telemetry is complete. Worth flagging, vendors can document secure configuration, but providers operate under staffing and budget constraints. My children grew up assuming portals like these just worked. Behind that assumption sits a lot of unglamorous configuration work by hospital IT staff.
Looking ahead, if Epic returns to full development after six weeks with hardened code, corrected deployments and verifiable logging, customers gain more than fixes. They gain a clearer baseline for monitoring MyChart and for responding to the next incident. That baseline is what makes future automation, detection engineering and third-party review effective.


