cd /news/ai-safety/epic-mychart-flaw-found-by-ai-320m-r… · home › topics › ai-safety › article
[ARTICLE · art-145913] src=byteiota.com ↗ pub= topic=ai-safety verified=true sentiment=↓ negative

Epic MyChart Flaw Found by AI: 320M Records at Risk

Epic Systems paused hundreds of product development projects for roughly six weeks after Anthropic's Claude Mythos AI found a MyChart configuration flaw that could let outsiders read patient records without any trace in the audit log, with over 320 million records in scope, CEO Judy Faulkner disclosed at the Modern Healthcare Leadership Summit. Epic chief security officer Sterling Martin told the New York Times the model could not determine whether those records could be silently altered, and he told provider customers to "get ready to patch, patch, patch." No breach has been confirmed; Mythos, launched in April 2026 under the restricted Project Glasswing program with about 150 vetted organizations across 15 countries, autonomously produced 181 Firefox exploits versus 2 from Opus 4.6 at the same effort level, and Glasswing partners have found more than 10,000 high or critical-severity flaws.

read4 min views1 publishedOct 6, 2026
Epic MyChart Flaw Found by AI: 320M Records at Risk
Image: Byteiota (auto-discovered)

Epic Systems d hundreds of product development projects for six weeks after Anthropic’s Mythos AI surfaced something its years of HIPAA audits had not: a configuration flaw in MyChart that let outsiders read patient records without leaving any trace in the audit log. Over 320 million records were in scope. No breach has been confirmed — but Epic decided that was not the bar. CEO Judy Faulkner disclosed the development freeze at the Modern Healthcare Leadership Summit.

The Flaw That Leaves No Trace #

The specific threat is what makes this story unusual. Sterling Martin, Epic’s chief security officer, told the New York Times that certain MyChart configurations could allow an outsider to view patient records without their access ever appearing in the system’s audit logs. No flag. No alert. No record that anything happened. Martin also acknowledged that Anthropic’s model could not determine whether those records could be altered silently — which remains the darker open question.

Healthcare compliance is built on audit trails. HIPAA’s Access Control and Audit Controls rules exist precisely to catch unauthorized access. A flaw that bypasses logging is not a gap in a compliance checklist — it is a hole in the entire accountability model that compliance is supposed to enforce. Epic’s system had passed those reviews for years before Mythos looked at it.

What Mythos Is — and Why It Is Not Publicly Available #

Anthropic launched Claude Mythos in April 2026 as its most capable cybersecurity model, alongside a restricted access program called Project Glasswing. The model is not available to the public. Anthropic has released it only to vetted organizations — currently around 150 across 15 countries — because it is explicitly designed to find and exploit vulnerabilities at a level that most human security researchers cannot match. In Anthropic’s own benchmarks, Mythos autonomously produced 181 Firefox exploits compared to 2 from Opus 4.6 at the same effort level. Glasswing partners have collectively found more than 10,000 high or critical-severity security flaws so far.

Epic was one of those partners. The company deployed Mythos against its own infrastructure and the AI surfaced what years of traditional auditing had not. That is the intended use case for Project Glasswing. It is also a preview of what happens when an AI security model finds something real.

A Six-Week Freeze — Before Any Confirmed Breach #

The freeze covering hundreds of Epic projects is a deliberate choice, not a crisis response. No confirmed breach. No active exploitation. Epic knew about the flaw, assessed the risk against 320 million patient records, and decided to halt feature development entirely until the issue was fixed. Faulkner’s public statement was direct: the would last roughly six weeks while the team worked on “safeguarding” its products. Her longer warning was blunter — “new flaws will be found as fast as old ones are fixed.”

Martin’s message to Epic’s healthcare provider customers was similarly unambiguous: “get ready to patch, patch, patch.” That is not typical enterprise communications language. That is a CSO telling an industry it needs to change how fast it responds to security updates.

Healthcare Security Is Having a Rough Week #

The Epic story did not arrive in isolation. The same week, Denmark’s central population register was breached — 8.8 million records, no exploit required. CareCloud’s 3.75 million patient breach from March 2026 is still in active remediation. The US Senate passed its first dedicated hospital cybersecurity statute by unanimous vote this week. According to healthcare cybersecurity analysts, the Epic incident was “the biggest health-data security event of the fortnight” — and that was a competitive field.

What Developers Should Take From This #

Three things are now true that were not widely accepted twelve months ago:

  • HIPAA compliance is a floor, not a ceiling. Audit-trail requirements did not catch a flaw that bypasses audit trails. AI-powered security auditing surfaces classes of vulnerability that compliance frameworks were not designed to find.
  • Roadmap disruption is a legitimate security outcome. When Epic’s AI found a real flaw, the right answer was to stop everything else. That decision will be replicated across enterprise software. If you maintain sensitive data, an AI security audit is no longer a backlog item.
  • The offense side is scaling too. Security researcher Bruce Schneierwarned in April that attackers using equivalent older models already have capabilities beyond their traditional skill level . The defender advantage exists today. It will not last indefinitely.

Epic’s six-week freeze will be studied for a long time — not because something went wrong, but because a company did something rare: it caught a critical infrastructure flaw before an attacker did, disclosed it publicly, and halted its engineering roadmap to fix it. That is what proactive AI-driven security looks like in practice. Meanwhile, the broader question of how AI is reshaping traditional security programs is only getting louder. The question for every software team is no longer whether to run AI security audits — it is how fast you can start, and what you will find when you do.

── more in #ai-safety 4 stories · sorted by recency
── more on @epic systems 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/epic-mychart-flaw-fo…] indexed:0 read:4min 2026-10-06 · —