Epic, the software giant behind the widely used MyChart platform for patient medical records, has suspended nearly all product development for roughly six weeks to address security vulnerabilities that could expose patient data to outsiders, according to a report by TechCrunch published this week. Founder and CEO Judy Faulkner revealed last month that the company discovered the flaws after deploying Anthropic's advanced cybersecurity AI model, Mythos, which identified weaknesses that hackers could potentially exploit to access sensitive health information. The pause represents a rare move in the software industry, where development typically continues even as security teams work on fixes.
The security issues center on MyChart, a system that maintains records for more than 320 million patients across hospitals and medical offices throughout the United States. Chief security officer Stirling Martin explained that certain customer setups of MyChart might permit unauthorized individuals to view patient records without leaving any trace of the breach in the software's activity logs. While the AI model didn't determine whether attackers could modify patient records undetected, Martin said the potential risk was serious enough to warrant immediate action. Epic doesn't directly handle customers' medical information—that responsibility rests with healthcare providers like hospitals and clinics—but a vulnerability unknown to the company could allow hackers to break into multiple MyChart systems nationwide and steal the data they contain.
The report notes that pausing development to repair security bugs is uncommon, but the emergence of AI tools capable of quickly identifying and taking advantage of software weaknesses has raised concerns that attackers may find it easier to steal information. Healthcare breaches have become increasingly frequent as hackers target highly sensitive medical data, betting that providers will pay to keep stolen information from being posted online. A 2024 ransomware attack on Change Healthcare, owned by insurance giant UnitedHealth, compromised health data belonging to more than 192 million Americans—the majority of the U.S. population—and the company paid the hackers twice to prevent publication of the stolen records. This year alone, consecutive data breaches at healthcare and technology companies have impacted tens of millions of people, including stolen medical records from electronic health storage company CareCloud, millions of rows of patient information from pharmaceutical distributor McKesson, and an unspecified volume of data from U.K.-based health tech firm Craneware, whose software is deployed across North America.
The timing reflects broader anxiety in the healthcare technology sector about AI-powered attacks outpacing traditional security measures. While Epic's decision to halt development demonstrates a commitment to protecting patient information, it also signals that even the largest medical software providers are vulnerable to flaws they didn't know existed until advanced AI systems uncovered them. The Department of Health and Human Services currently lists a breach at dental insurance company DentaQuest affecting 15 million people as the largest healthcare-related data incident of 2026 so far. Epic's six-week pause aims to "safeguard" its products before they return to normal development, though the company hasn't disclosed technical details about the vulnerabilities or whether any patient data was actually accessed before the issues were discovered. The episode may force healthcare organizations to reconsider how they balance the speed of software innovation against the imperative of airtight security, particularly when a single overlooked flaw can expose hundreds of millions of records simultaneously.

