Epic Pauses to Patch Mythos-Detected MyChart Security Bugs — SkimNews

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Epic paused most product development for an expected six weeks, per CEO Judy Faulkner, to remediate security vulnerabilities in its MyChart software.
- Anthropic's frontier cybersecurity model Mythos uncovered the bugs during a deployment at Epic, identifying flaws that could let outsiders access patient records without leaving traces in system logs.
- Stirling Martin, Epic's CSO, told the Times the AI did not confirm whether the bugs could alter patient records, but the access risk alone justified the remediation push.
- MyChart holds over 320 million patient records across U.S. hospitals and physician offices, with Epic noting healthcare providers—not the company itself—control the underlying data.
- The pause is unusual for a company of Epic's scale, reflecting concerns the source attributes to AI tools that can rapidly find and exploit software vulnerabilities before defenders catch up.
Why it matters: An AI-driven audit of software managing 320 million patient records surfaced access vulnerabilities before attackers could weaponize them—yet the 2024 Change Healthcare breach, which compromised data on 192 million people, demonstrates how catastrophic a successful hit on healthcare data infrastructure can be.
Ask SkimNews


