Why Epic Systems Paused Development to Address MyChart Security Vulnerabilities

Epic Systems, the electronic health records giant managing data for more than 320 million patients, has initiated a rare six-week “security sprint,” pausing most new product development to address vulnerabilities that could allow intruders to access patient records without leaving a trace.

The security flaws were identified through “Project Glasswing,” a restricted initiative involving Anthropic’s “Mythos” AI model. This AI-driven stress test of Epic’s 100-million-line codebase uncovered a specific type of vulnerability known as “silent access.” Under certain configurations of the MyChart patient portal, an unauthorized user could potentially view sensitive medical data while bypassing the system’s internal audit logs—the very logs healthcare providers rely on to detect and report data breaches.

A conceptual image of AI scanning software code for vulnerabilities.
’s 'Mythos' model was used to identify 'silent access' vulnerabilities within Epic's codebase.

Epic CEO Judy Faulkner disclosed the development halt during the Modern Healthcare Leadership Summit in late September 2026. While the company characterizes the move as a proactive measure to harden its infrastructure against AI-equipped hackers, the decision to freeze features highlights the critical nature of the vulnerabilities discovered.

The Threat of Undetected Intrusion

The primary concern cited by security leadership is the inability of current monitoring tools to register these specific access points. Epic Chief Security Officer Stirling Martin clarified that while the Mythos model did not definitively confirm that records could be altered or deleted, the risk of undetected viewing was significant enough to warrant an immediate shift in resources.

In the healthcare sector, audit logs are the backbone of HIPAA compliance and forensic investigations. If an intruder can access a patient’s history, medications, or lab results without triggering a log entry, a provider may never know a breach occurred, preventing them from notifying affected individuals as required by law.

The vulnerabilities are particularly concerning given the 2026 cybersecurity landscape, which has already seen massive data compromises, including the 15-million-record breach at DentaQuest. By identifying these flaws via Project Glasswing before they were exploited in the wild, Epic is attempting to close a window of opportunity that could have led to one of the largest healthcare data exposures in history.

The ‘Pause’ vs. The Roadmap

Despite the shift in focus, there appears to be internal tension regarding how the security sprint affects Epic’s long-term goals. While Faulkner stated that the company has “paused most technology development” to prioritize these fixes, a spokesperson for the company later suggested that the development roadmap remains on track and has not changed since its August 2026 projections.

This distinction is critical for hospital systems that are currently waiting for promised clinical AI tools and workflow updates. The six-week pause likely defers the rollout of non-security-related features while engineers work on “hardening” the codebase.

The “Mythos” model used in the discovery represents a new frontier in defensive cybersecurity. Unlike traditional static analysis tools that often produce high volumes of false positives, the Anthropic AI was able to identify complex logic flaws that could lead to authorization bypasses. This proactive “red-teaming” reflects a growing industry trend where software vendors use generative AI to hunt for bugs before malicious actors can develop their own AI-driven exploits.

For healthcare IT administrators, the immediate impact is a focus on system configurations. While Epic remediates the core software bugs, hospital systems are encouraged to verify their specific MyChart settings and monitor for unusual traffic patterns that might fall outside standard audit parameters. The security sprint is expected to conclude in mid-November, at which point Epic is expected to resume its standard development cycle.

More From Category

More Stories Today