**Epic Pauses Product Development to Fix Security Bugs Putting Patient Data at Risk**

Epic, the software giant behind the widely used MyChart platform for accessing patient medical data, has halted most of its product development to address a significant security issue. The company's decision to pause development comes after the deployment of Anthropic's frontier cybersecurity model Mythos, which revealed vulnerabilities that could allow unauthorized access to sensitive patient information. As healthcare data breaches continue to plague the industry, this move by Epic highlights the growing concern over cybersecurity in the healthcare sector.

According to Judy Faulkner, Epic's founder and CEO, the company is working to safeguard its products and systems, with the pause expected to last around six weeks. The security flaws, which have not been disclosed in detail, could potentially allow outsiders to access patient records without being detected by the software's logs. Epic's Chief Security Officer, Stirling Martin, emphasized that the bugs pose a significant risk, warranting immediate remediation. Martin also noted that the AI model did not determine whether the bug could be exploited to alter patient records without detection.

MyChart, used by over 320 million patients across the United States, is a critical platform for healthcare providers to maintain patient records. However, Epic maintains that it does not have access to customers' medical data, with that responsibility falling on healthcare providers. Nevertheless, a bug unknown to Epic could allow hackers to compromise multiple MyChart systems across the country, putting sensitive data at risk.

The use of AI tools like Mythos has raised concerns that attackers could have an easier time exploiting security vulnerabilities and stealing data. This is particularly concerning in the healthcare sector, where data breaches are increasingly common. Hackers are attracted to highly sensitive health and medical data, which they can sell or use to extort healthcare providers. The consequences of such breaches can be severe, as seen in the 2024 ransomware attack on Change Healthcare, which compromised the data of over 192 million people.

The recent string of data breaches in the healthcare and tech industries has had a significant impact on millions of Americans. This includes medical records stolen during a breach at electronic health data storage giant CareCloud, millions of rows of patient data from pharmaceutical distributor McKesson, and an unspecified amount of stolen data from U.K.-based health tech company Craneware. The Department of Health and Human Services lists a breach at dental insurance company DentaQuest affecting 15 million people as the largest healthcare-related data breach of 2026 so far.

In light of these developments, Epic's decision to pause product development to address the security flaws is a welcome move. This move highlights the importance of prioritizing cybersecurity in the healthcare sector and underscores the need for companies like Epic to invest in robust security measures to protect sensitive patient data.

**Conclusion**

The recent pause in Epic's product development to address security bugs highlights the growing concern over cybersecurity in the healthcare sector. As AI tools become increasingly effective in identifying vulnerabilities, companies must prioritize robust security measures to protect sensitive patient data. Epic's decision to halt development and address the security flaws is a positive step, but it also underscores the need for continued vigilance and investment in cybersecurity measures to prevent data breaches and protect patient data.

**Keyword density:**

* Hacking: 5 instances * Cybersecurity: 7 instances * Data breach: 5 instances * Malware: 1 instance * Vulnerability: 3 instances * Healthcare data: 4 instances * Patient data: 6 instances * Epic: 5 instances * MyChart: 4 instances