Medical records giant Epic pauses product development to fix security bugs that risk patients’ data
- ID
- 31101
- Status
- summarized
- Published
- 02 Oct 2026, 9:23 PM
- Fetched
- 02 Oct 2026, 10:45 PM
- Provider
- TechCrunch
- Category
- technology
- Original URL
- https://techcrunch.com/2026/10/02/medical-records-giant-epic-pauses-product-development-to-fix-security-bugs-that-risk-patients-data/
- Source URL
- https://techcrunch.com/feed/
Summary
- Score
- 7.0
- Created
- 02 Oct 2026, 10:46 PM
- Tags
- Audience
- developersai_ml_learnerssaas_founders
What happened
Epic, which makes the MyChart patient portal used to maintain over 320 million patient records in the US, has paused most of its product development for roughly six weeks to fix security bugs, per founder and CEO Judy Faulkner speaking to Modern Healthcare. The flaws surfaced after a deployment of Anthropic's frontier cybersecurity model, Mythos, and chief security officer Stirling Martin told The Times that some customer configurations of MyChart could let outsiders read patient records without leaving any entry in the software's logs. Martin said the model did not establish whether records could also be altered undetected, but Epic judged the risk serious enough to remediate; TechCrunch notes Epic has not disclosed the nature of the bugs.
Why it matters
The concrete lesson is the logging gap, not the vendor: a read of patient records that leaves no trace in application logs defeats detection and audit entirely, and that class of bug is exactly what an AI security model found here at scale. If you ship anything with a permission model — patient data, tenant data, customer records — test whether privileged or misconfigured access paths produce an audit entry, and treat 'no log line' as a bug of its own. Also note the release-planning implication: a six-week freeze on most product development is what a serious finding costs, so teams running continuous release trains should decide in advance what triggers a stop-ship versus a patch-forward.
Discussion angle
If an AI model scanned your product tomorrow and found an access path that reads data without writing an audit log, would you even be able to confirm it — and would your team stop the release train for six weeks, or ship a patch alongside normal work?