More than 320 million patients keep their medical histories inside software from a single company, and that company has just pressed pause on almost everything. Electronic health records giant Epic has frozen most product development for six weeks to close security holes in its flagship MyChart (the online patient portal where people check lab results, appointments, and prescriptions). The scale of the decision alone sends a message: this is not an ordinary software bug, but the private data of millions.
Inside the six-week freeze
The trigger was Epic's own security test. Founder and chief executive Judy Faulkner told Modern Healthcare that the work would take roughly six weeks while her teams shifted to a safeguarding sprint. The tripwire was Mythos , the cybersecurity model from Anthropic: unleashed on the company's systems, it surfaced weaknesses that could open a path to patient data. At a moment when artificial intelligence is making attackers faster, the same technology scoring a critical find on defense is a striking turn.
The most frightening detail is how ghost-like the flaw behaves. According to chief security officer Stirling Martin, speaking to the New York Times (nytimes), some customer installations of MyChart could let an outsider view patient files while the software's audit log (the tracking mechanism that records who accessed which data and when) captured nothing at all. An intrusion could happen and leave no trace behind. The company admits it is not even clear whether records could be altered undetected through the same path, yet judged the risk serious enough to fix without delay.
The weight Epic carries becomes clearer in the numbers: MyChart manages over 320 million patient records across hospitals and clinics in the United States, and company statements carried by the New York Times (nytimes) put the figure at 325 million including patients abroad. Epic stresses that it cannot see customer data itself and that responsibility sits with hospitals and practices. But a flaw unknown even to Epic could leave many MyChart installations scattered across the country exposed at once; a single unknown can unlock hundreds of hospitals.
AI as both magnifier and menace
Understanding what Mythos is explains why this matters. Per technical notes published by Anthropic, Mythos Preview is a frontier model able to find and weaponize zero-day flaws missed for decades at machine speed, and the lab built the Project Glasswing consortium of around 50 members to steer that power toward defense. Analysis from the cybersecurity firm Tenable points the same way: frontier models surface critical weaknesses that classic scanners missed for years, shrinking the window between a flaw's discovery and its weaponization to hours. What Epic just lived through may count as one of this new era's first big field cases.
The tremor at Epic echoes because of the company's size. Founded in 1979 by Judy Faulkner and run privately from Verona, Wisconsin, it has become the heart of US hospital IT: KLAS Research data published in Fierce Healthcare (fiercehealthcare) shows Epic reaching a 43.7 percent share of acute care hospitals and 56.9 percent of hospital beds in 2025, while rival Oracle Health slid to 22.9 percent. When one vendor dominates this thoroughly, every flaw it harbors has national-scale consequences.
Monopoly shadows and a breach wave that never ends
That dominance is also the source of the harshest criticism aimed at Epic. Health startup Particle Health filed an antitrust suit alleging Epic strangles competition by blocking data sharing; as reported by HealthExec, a federal judge in Manhattan ruled the case can proceed, with Particle claiming health data of 94 percent of Americans sits under Epic's control. Epic calls its software open and interoperable and rejects the claims. The breach toll behind the story is grim too: records kept by HIPAA Journal (hipaajournal) confirm the 2024 Change Healthcare attack stole data of more than 192 million people, the US health department lists the 15-million-person DentaQuest incident as 2026's largest health breach so far, and the CareCloud, McKesson, and Craneware breaches reached tens of millions more.
AI commentary
"What strikes me most here is less the flaw itself than the honesty of Epic's response: the company caught it with its own AI screening and gave up six weeks of development. Yet the prospect of access that leaves no audit trace, combined with claims of 94 percent data control, leaves one question hanging: in a system this centralized, what is the next unknown?"
AI assessment
First, steelman the other side: Epic looks like the responsible party here. It found the flaw with its own security screening, sacrificed six weeks of development instead of burying the problem, and disclosed the risk publicly. The monopoly critique sits on a different plane from this security episode: the Particle Health allegations remain unproven in court, and Epic maintains its platform is open. In short, there is no verified evidence to charge the company with both negligence and a deliberate cover-up at once.
Still, the picture has gaping holes. The nature of the flaws stays undisclosed: nobody knows which versions or configuration options are affected. More importantly, unanswered questions linger over whether anyone already slipped through these paths and whether records could have been silently altered. An Epic executive left a TechCrunch request for comment unanswered, leaving hospitals guessing about what to patch and how fast. The unknowns outnumber the knowns.
For readers, the practical takeaway is clear. Hospital IT teams should treat this as a signal to reaudit MyChart installation settings and access logs from scratch: patch calendars must move up and anomalous-access alerts must tighten. On the patient side the advice is simple: watch account activity, take any unusual access notification seriously, and contact your provider. The broader lesson belongs to the whole sector: AI-assisted security screening is no longer a luxury but standard duty for every provider serious about its HIPAA obligations.
Sources
7 links; no other published story cites them. Stories sharing a link do not confirm each other; a source's origin is not inferred from how often it is cited.
epic systems · mychart · cybersecurity · patient data · artificial intelligence · hipaa · health tech