EPIC , the software giant behind the MyChart patient portal, has paused most of its product development to focus on addressing security flaws that could put patients’ data at risk. The move, described as likely to last about six weeks, follows findings from Anthropic’s frontier cybersecurity model Mythos that flagged vulnerabilities in the company’s software and configurations.
While Epic has not disclosed the exact nature of the bugs, its chief security officer, Stirling Martin, told The New York Times that certain customer configurations of MyChart could allow outsiders to access patient records without any intrusion being logged in the software’s logs.
The pause affects Epic’s ability to push new features while the company works to safeguard its products and systems. The disclosures have tied the issues to potential misconfigurations that could enable unauthorised access to records, raising concerns about how patient data is accessed and audited. Epic has not detailed any confirmed exploitation, and it remains to be seen how widely the configurations are adopted across client sites.
The company’s communications emphasise mitigating risk and protecting patient privacy, with public reporting from Modern Healthcare and The New York Times forming part of the evidentiary picture. Tech media coverage is referenced, but Epic has not released a technical advisory or CVE-style attribution in this briefing.