Epic, the software company behind MyChart, has halted most product development for approximately six weeks. This pause is dedicated to safeguarding its software and systems against cyberattacks, following the discovery of significant security vulnerabilities.
The security flaws were identified by Anthropic's frontier cybersecurity model, Mythos. Epic's chief security officer, Stirling Martin, stated that some configurations of MyChart could permit external access to patient records without logging any intrusion, posing a risk to patient data integrity.
MyChart software is used to manage over 320 million patient records across healthcare providers in the United States. While Epic does not directly access patient data, a vulnerability in its software could allow attackers to compromise multiple systems and steal sensitive information. The company has not disclosed the specific nature of the bugs.
Pausing development for security fixes is uncommon, but the increasing capability of AI tools to find vulnerabilities raises concerns about easier data theft. Healthcare breaches are frequent, with recent incidents like the Change Healthcare ransomware attack affecting over 192 million people, highlighting the high value of medical data to attackers.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Epic, developer of the MyChart software, has paused most product development for six weeks to fix security vulnerabilities. These flaws, discovered by Anthropic's Mythos AI, could allow unauthorized access to patient data without detection, impacting over 320 million patient records.