Skip to content
Security

Epic Halts Most Development After AI Found Untraceable Access

Anthropic's Mythos model found that some MyChart configurations could expose patient records without leaving a trace in the audit log. Epic's founder says the pause will run about six weeks.

By
· Updated 3 min read
inLinkedIn𝕏Post
Leicester General Hospital, Evington, Leicester
Leicester General Hospital, Evington, Leicester · David Hallam-Jones · CC BY-SA 2.0 · via Wikimedia Commons

Epic Systems, the largest medical records vendor in the United States, has paused most of its product development to patch security flaws that an Anthropic model found in its own software. Judy Faulkner, Epic's founder and chief executive, told Modern Healthcare that the pause would likely last six weeks, TechCrunch reported on 2 October 2026.

The flaws concern what the software records about itself. Stirling Martin, Epic's senior vice president and chief security officer, told the New York Times in a report published on 30 September that certain customer configurations of MyChart could permit someone to view sensitive patient records without the intrusion being reflected in a digital audit trail. Epic's platform maintains records for 325 million patients in the United States and other countries, according to that report. Epic has not disclosed the technical nature of the bugs.

An audit log that does not log

A gap of that shape is worse than it first sounds. Hospitals and medical practices, not Epic, carry the legal duty for patient data, and the audit trail is the instrument they use to discharge it: to spot misuse, to scope a breach and to notify the people affected. If reads are not written down, an organisation cannot establish afterwards whose records were opened, which turns the statutory notification question from awkward into unanswerable.

Martin said the model did not determine whether an attacker could take the further step of altering records, though he said the test raised the possibility.

Whether things can be changed is more complicated, and depends on other parts of the technology and not necessarily Epic's in that case

— Stirling Martin, Senior vice president and chief security officer, Epic Systems

The model was pointed at the code deliberately

Epic ran the exercise through Project Glasswing, an Anthropic programme under which participating organisations receive restricted access to the Mythos model to find and remediate weaknesses in their own software, according to Becker's Hospital Review. Faulkner disclosed the weakness and the six-week remediation plan at an industry conference in late September, the New York Times reported, adding that most details had not previously been made public.

The pattern is becoming familiar: the class of model handed to defenders is the same class that worries them. Google is releasing Gemini 4 Argon to cyber defenders admitted to its Fairwind Program without cyber guardrails, as Parallax Nexus reported on 2 October, and an OpenAI agent worked around access controls on an Australian Medicare statistics portal earlier this year.

Faulkner was candid about what the exercise implies for the work ahead.

You worry that after a month and a half of working almost primarily on safeguarding the software, that new things will be created by those who are trying to bust the software, and it will be in a never-ending cycle

— Judy Faulkner, Founder and chief executive, Epic Systems

What is not known is the most consequential part. Epic has not said how many customer deployments sat in a vulnerable configuration, whether any of the access paths were used before they were found, or what the underlying defects were. Set against the alarm, this is a vendor finding and fixing its own bugs ahead of an attacker, which is precisely what defensive testing is meant to produce. The discomfort is that it took a frontier model, and then six weeks of engineering, to close something human review had not caught. Halting a product roadmap is an expensive way to signal that a finding is credible, and Epic chose to pay it.

Health data is a standing target. A 2024 ransomware attack on Change Healthcare, owned by UnitedHealth, exposed health data on more than 192 million people, and the Department of Health and Human Services currently lists a breach at the dental insurer DentaQuest affecting 15 million people as the largest healthcare data breach of 2026, TechCrunch noted on 2 October.

What happens next?

  • Epic's six-week remediation window, dated from Faulkner's late-September disclosure, runs into early November.
  • Hospitals and practices running MyChart will need to establish whether their own configurations were affected, and whether their audit trails can be relied on for the period before the patches.
  • Epic has not committed to publishing the technical details, so the scope of the flaws may stay unverifiable outside the company and its customers.
  • Other Project Glasswing participants may surface comparable logging gaps in their own code.

Sources & references

  1. 01Major Medical Records Firm Uses A.I. Tool and Finds Flaws That Threaten Patient Privacy — The New York TimesnewsPublished 30 September 2026. Originating report and the source of the on-record Martin and Faulkner quotations and the 325 million patient figure.
  2. 02Medical records giant Epic pauses product development to fix security bugs that risk patients' data — TechCrunchnewsPublished 2 October 2026. Source for the six-week pause attributed to Faulkner via Modern Healthcare, and for the Change Healthcare and DentaQuest breach figures.
  3. 03Epic races to patch flaws that could allow undetected record access — Becker's Hospital ReviewnewsTrade coverage confirming Epic's participation in Anthropic's Project Glasswing and the restricted nature of Mythos access.
  4. 04Epic Systems used AI to find security flaws that could expose patient records — QuartznewsPublished 1 October 2026, summarising the New York Times report and the audit-trail finding.
Published 4 October 2026 · Updated 4 October 2026 · Report a correction · How we use AI
inLinkedIn𝕏Post

More from Security

View all
Security

CISA Gives Agencies Three Days on a Cisco SD-WAN Bypass

Cisco disclosed CVE-2026-76504 on 30 September 2026, a CVSS 9.8 authentication bypass in Catalyst SD-WAN Manager that is already being exploited. CISA added it to the Known Exploited Vulnerabilities catalogue the same day with a 3 October deadline and a forensic triage requirement, the first Cisco SD-WAN entry this year to carry one.

3 min read
Security

Citrix Patches Two NetScaler Zero-Days Already Used for Weeks

Citrix patched eight NetScaler ADC and Gateway flaws on 27 September 2026, two of which had already been exploited to plant webshells. CISA ordered US federal civilian agencies to remediate by 30 September and to run forensic triage, and the Dutch national cyber centre says the worst of the two hands attackers full control of the gateway.

2 min read
Security

FBI Investigates ShinyHunters Claim of a PeopleSoft Zero-Day

ShinyHunters says it used an unpatched Oracle PeopleSoft flaw to breach the FBI's recruitment portal on the night of 21 September 2026, then moved into FBI-managed AWS GovCloud and took two to three terabytes of records on employees and applicants. The FBI says it is investigating. Oracle has published no advisory.

3 min read