
An AI Model Found Possible Patient-Data Risks in MyChart. Epic Paused Hundreds of Projects for Six Weeks.
Epic paused hundreds of projects for about six weeks after Anthropic’s Claude Mythos flagged potential MyChart patient-data risks. No breach is confirmed.
Epic paused hundreds of development projects for roughly six weeks after Anthropic’s Claude Mythos identified potential security flaws that could expose patient data in MyChart-related systems, according to TechCrunch, Wisconsin Public Radio, and Becker’s Hospital Review. Epic CEO Judy Faulkner said the company would stop most product development during the remediation period, TechCrunch reported. Epic maintains that its longer-term roadmap hasn’t changed.
The sources describe potential weaknesses and Epic’s response to them, not a confirmed breach. None of them establishes that an attacker accessed patient records, or that every MyChart deployment was affected.
One detail made the findings more serious. Wisconsin Public Radio reported that the AI-assisted review identified scenarios in which patient data could potentially be accessed without the activity being detectable in Epic’s logs. TechCrunch described similar configurations. The distinction matters because access restrictions and audit logs do different jobs. Restrictions try to stop unauthorized viewing, and logs let organizations investigate and disclose an incident if prevention fails. The reported risk is that certain setups could weaken both at once.
The public accounts leave most technical questions open. Neither outlet published enough detail to identify the vulnerability class. It isn’t clear which configurations were at risk, how many healthcare organizations used them, what Epic changed in code or configuration, or whether customers had to change their own deployments. From the public record you can’t tell whether this was a product defect affecting all customers, a weakness limited to particular implementations, or both.
The notable part is the decision, not just the discovery. Security reviews routinely turn up findings that have to be ranked against other engineering work. Epic’s reported choice to halt hundreds of projects suggests it treated these risks as urgent enough to override near-term delivery plans. The episode shows an AI finding going through a conventional security process: assessed, prioritized, and fixed, with product work deferred in the meantime.
It isn’t evidence that automated analysis can replace human security teams. The sources don’t compare Mythos’s performance with human reviewers, say how many findings it produced, or show that independent researchers validated each one. They also don’t establish that the review caught every relevant weakness.
Bottom line: An AI-assisted review surfaced risks serious enough for a major healthcare-software vendor to reorder its engineering priorities, which is a meaningful data point for how these tools get used in practice. What the public record doesn’t yet show is the scope of the affected deployments, whether any records were exposed, or how completely the fixes resolved the underlying risks.
- 1
Epic CEO Judy Faulkner said the company would stop most product development during the remediation period, TechCrunch reported.
- 2
The sources describe potential weaknesses and Epic’s response to them, not a confirmed breach.
- 3
None of them establishes that an attacker accessed patient records, or that every MyChart deployment was affected.
Continue reading