Medical Records Giant Epic Pauses Product Development Following AI Security Audit

By The Indus Pulse Editorial Team3 min read
AI-generated editorial illustration
AI Illustration

Medical software titan Epic has enacted an unprecedented halt on most product development to address critical security vulnerabilities discovered in its widely deployed MyChart patient portal. Chief Executive Judy Faulkner disclosed that the protective pause is slated to last approximately six weeks as engineering teams race to safeguard infrastructure following an internal security audit.

According to Quartz, for EHR Vendor AI Auditing Adoption, Epic's engagement with Anthropic under Project Glasswing positions it among the first medical software vendors deploying frontier AI models to discover structural vulnerabilities in proprietary code. According to Quartz, epic identified the software vulnerabilities by participating in Anthropic's Project Glasswing, a cybersecurity program expanded in June 2026 to evaluate critical infrastructure codebases.

The underlying flaws were unmasked during a deployment of Mythos, a frontier cybersecurity model developed by Anthropic. While company leadership emphasized that the exact nature of the bugs remains confidential, Chief Security Officer Stirling Martin revealed to media outlets that specific customer configurations of MyChart could permit external parties to access sensitive patient records without generating audit logs of the intrusion.

According to Quartz, epic Chief Security Officer Stirling Martin warned hospital customers that they must immediately accelerate software patching cadences to ingest incoming security remediations. According to Quartz, for Provider Remediation Protocols, Healthcare systems are required to rapidly deploy incoming security updates and direct patients to access health records strictly through the MyChart mobile app.

Vulnerability Scope and AI Audit Discovery

Epic's MyChart software underpins digital health infrastructure across the United States, managing more than 320 million patient records stored by hospitals and physician practices. Although Epic maintains that it does not directly store or access patient medical data, leaving that responsibility to individual healthcare providers, an undetected software vulnerability exposes connected institutional systems to systemic data compromise.

According to Quartz, epic and hospital partners faced phishing campaigns utilizing AI-generated emails targeting MyChart users to compromise financial details and medical credentials.

According to statements provided to industry publications, Anthropic's Mythos model did not ascertain whether the discovered flaws could be leveraged to covertly alter medical records. Nevertheless, executive leadership deemed the exposure severe enough to warrant halting regular feature development to prioritize remediation.

Broad Healthcare Sector Vulnerability

The decision to suspend normal operations highlights mounting security pressures across the health technology sector as automated AI tools accelerate vulnerability discovery. Security researchers warn that advanced models provide malicious actors with enhanced capabilities to locate and exploit system weaknesses.

The healthcare industry has faced a relentless series of high-profile cyber incidents, most notably the 2024 ransomware attack on UnitedHealth-owned Change Healthcare, which compromised records for over 192 million individuals. Additional major breaches throughout the year have affected organizations such as CareCloud, pharmaceutical distributor McKesson, U.K.-based Craneware, and dental insurance provider DentaQuest, which reported an incident impacting 15 million patients.

The Indus Pulse is committed to accuracy and transparency.