Contacts
Follow us:
Contact us
Close

CONTACTS

Krikis, MB, Company code: 305601196, Klaipėda, Lithuania

info@krikis.lt

Epic pauses product development to fix security flaws that put patient data at risk

Epic pauses product development to fix security flaws that put patient data at risk

Epic pauses product development to fix security flaws that put patient data at risk

„Epic, a widely used health information systems company, has announced that it is suspending most of its product development. The decision comes after the company’s CEO, Judy Faulkner, who is also its founder and CEO, said that the company will spend the next six weeks “defining„ its software against cyber threats. The hiatus comes after Anthropic’s artificial intelligence security model, Mythos, revealed several security vulnerabilities that could have allowed unauthorized access to patient data.

While Epic did not disclose the specific nature of the flaws, the company’s chief security officer, Stirling Martin, said that some MyChart configurations could allow outsiders to access patient records without logging into the app’s logs. Martin, speaking to The New York Times, emphasized that while it’s unclear whether the flaw would allow records to be altered without detection, the risk is high enough that it’s urgent to address the vulnerabilities.

MyChart is Epic’s core platform, which allows patients to view and manage their medical records online. The system currently manages more than 320 million patient records in hospitals and doctor’s offices across the United States. Epic says it does not have direct access to customers’ medical data — that’s the responsibility of healthcare providers. However, according to the source, an unknown flaw could allow cybercriminals to hack into many of MyChart’s systems and access stored data.

Artificial Intelligence Data Center

A breach of this magnitude is rare in the health technology sector, but AI tools that can quickly detect and exploit security vulnerabilities pose new threats. The frequency of today’s cyberattacks suggests that hackers are increasingly targeting health data—valued for its potential for ransom and the ability to exploit personal information. For example, in 2024, Change Healthcare suffered a major ransomware attack that stole the health information of 192 million people, and the company paid twice to stop the data from being made public.

Several major data breaches in the healthcare sector have already occurred in 2026: CareCloud, McKesson, Craneware, and the largest to date, the dental insurance company DentaQuest data breach, which affected 15 million people. These events show that health data security is becoming an increasingly important issue for both companies and regulators.

Business Technology Office

Epic’s move to temporarily suspend product development reflects the industry’s broader focus on prevention, rather than just response, after an incident. The company expects to have the vulnerabilities fixed within six weeks, making the MyChart platform safe for both healthcare providers and patients. The pause also gives other health technology companies an opportunity to review their security protocols and assess whether similar AI tools like Mythos can uncover security weaknesses in their systems.

While Epic did not disclose whether the bugs could allow for the modification of patient records, the fact that some configurations could allow for undocumented access to logs is already a cause for concern. This information highlights that even well-known and widely used health IT platforms can have unintended vulnerabilities that only become visible with the use of advanced AI security tools.

In the future, the healthcare sector is likely to invest even more in AI-based security solutions to detect potential threats early. The Epic example shows that even the largest companies are willing to temporarily suspend innovation to ensure the security of patient data. This may become the new norm - prioritizing security over rapid functionality development.

However, while this temporary suspension lasts, healthcare organizations should be vigilant and review their MyChart configurations to prevent potential unauthorized access. This is an important step to maintain trust in digital health services and prevent potential data breaches in the future.

Sources

IT SERVICES

Let's transform technology real results for your business.

We help companies apply artificial intelligence, automation, internet systems, and other digital solutions to real business processes.

Contact us Initial consultation is free of charge.