Skip to content
Rush Commerce
Software & Dev2 min read

Epic pauses development after AI finds MyChart flaw: plan a security sprint

Epic paused most product work for about six weeks after an AI model found a MyChart flaw that left no audit trail. Budget your own security sprint now.

The biggest electronic health records vendor in the US stopped building features to fix security. Epic Systems paused most product development for about six weeks after an AI model found a MyChart flaw: in some customer configurations, an outsider could read patient records and the access did not show in the logs. When AI finds bugs faster than your team can ship features, the roadmap waits. That is the new math, and it applies to your codebase too.

What actually happened

CEO Judy Faulkner disclosed the pause at Modern Healthcare's Leadership Summit in September. She said the security work would take about six more weeks, with product development continuing at a slower pace.

On October 2, TechCrunch reported new detail from Epic's chief security officer, Stirling Martin, who told The New York Times that some MyChart configurations could let outsiders access patient records without the intrusion being recorded. The bugs were found by Anthropic's Mythos model. Epic takes part in Project Glasswing, Anthropic's program that gives defenders early access to vulnerability-hunting AI. Per TechCrunch, it is not yet known whether the flaws could also let someone change records without detection.

Epic told Becker's that its roadmap is unchanged.

Why it matters for your business

Two lessons here, and neither is about healthcare.

AI vulnerability discovery creates a backlog. Point a strong model at a large codebase and it returns a list. Somebody has to triage and fix that list, and that somebody was going to build features this quarter. Per Fierce Healthcare, Epic's codebase runs to several hundred million lines, and it still had to stop. Plan the sprint before the scan, not after.

Logs that miss an access are worse than no logs. The worst part of the MyChart flaw is the silence. If your customer portal, admin panel or API can serve data without a log entry, you cannot answer "who saw what" after an incident. Test it: make an access through every path, then check that each one appears in the audit trail.

Configuration is code. The flaw lived in customer configurations, not only in Epic's core. If you ship a product your clients configure, your security review must cover the settings they can turn on.

Key takeaways

  • Epic paused most product development for about six weeks to fix security issues
  • Anthropic's Mythos found that some MyChart configurations allowed record access with no audit trail
  • AI bug hunting produces a fix backlog: budget engineering time before you run the scan
  • Test that every data access path writes an audit log entry
  • Review the configurations your customers can set, not only your core code

Want to know what an AI scan would find in your code? We run AI-assisted security reviews on small-business apps, then fix what we find and verify your audit logs actually log. See what we build, or book a review.

Sources: TechCrunch, Modern Healthcare, Becker's Hospital Review.

  • #epic-systems
  • #ai-vulnerability-discovery
  • #security-sprint
  • #audit-logs
  • #mythos
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.