# Epic Paused Most Development After Anthropic's AI Found a Hidden MyChart Flaw

> Source: <https://startupfortune.com/epic-paused-most-development-after-anthropics-ai-found-a-hidden-mychart-flaw/>
> Published: 2026-10-02 20:23:36+00:00

*Epic Systems holds the medical records of more than 320 million patients. An Anthropic AI model found a way into those records that wouldn't show up in any log.*

Judy Faulkner doesn't make announcements like this often. Epic's founder and CEO told attendees at Modern Healthcare's Leadership Summit this week that the company had paused most of its product development for roughly six weeks, not because of a breach, but because its own security testing turned up something worse: a blind spot. Certain customer configurations of Epic's software, including the widely used MyChart patient portal, could let an outsider view sensitive patient records without the access ever appearing in the digital audit trail. No alert. No trace. Nothing for a hospital's security team to catch after the fact.

Epic found the flaw by testing its own systems against Mythos, Anthropic's frontier cybersecurity model, deployed through a program the company calls Project Glasswing. Stirling Martin, Epic's chief security officer, told The New York Times that the testing also raised the possibility that an attacker who found this gap could alter records, not just read them, though Mythos itself didn't confirm that an attacker could actually pull that off. Martin's own words to the Times are blunt enough to stand on their own: "Ultimately they need to get ready to patch, patch, patch. As soon as they think they are patching fast enough, they need to patch faster."

That urgency is the real story here. Epic is not a startup with a few thousand users to notify. It is the dominant electronic health record vendor in the United States, the system hospitals and clinics rely on to store the records patients and doctors both depend on. According to TechCrunch's reporting, Epic's software underpins medical records for more than 320 million patients across American hospitals and physician offices. When a company that size tells its engineering staff to drop the roadmap and fix access controls instead, that is not routine maintenance. That is a company that looked at what its own AI model found and decided nothing else mattered more this quarter.

Epic didn't stumble into this. The company deliberately ran Mythos against its own infrastructure looking for exactly this kind of gap, and the model found one that had apparently sat unnoticed through years of normal security review. That's worth sitting with for a second: Epic has its own security staff, goes through routine audits, and serves healthcare systems bound by HIPAA. None of that caught a hole that let someone view records invisibly. An AI model built specifically to probe for this kind of weakness did.

[OpenAI Plugs ChatGPT Into Epic's Health Records for 325 Million Patients](https://startupfortune.com/openai-plugs-chatgpt-into-epics-health-records-for-325-million-patients/)

OpenAI has integrated ChatGPT with Epic's electronic health record system, giving clinicians at UCSF Health read-only access to notes, labs, medications and specialist records for more than 325 million patients. The rollout adds role-based access, SSO, audit logs and BAA support for HIPAA compliance as OpenAI pushes deeper into hospital... - [ChatGPT integration with Epic electronic health records system](https://startupfortune.com/openai-plugs-chatgpt-into-epics-health-records-for-325-million-patients/) - [how doctors access patient records through ChatGPT pilot](https://startupfortune.com/openai-plugs-chatgpt-into-epics-health-records-for-325-million-patients/)

This is the flip side of every story this year about AI making phishing emails more convincing or helping write better malware. Epic is also fighting exactly that problem right now. The company has separately flagged a phishing campaign where criminals are using AI tools to generate convincing fake emails aimed at MyChart users, Modern Healthcare has reported. So the same wave of model capability that's sharpening attacks against Epic's customers is also what caught the defect before anyone malicious apparently found it. Both things are true at once, and neither cancels the other out.

Epic has been careful to say its broader plans haven't changed. According to Fierce Healthcare, the company maintains that its AI and interoperability agenda, including tools like Agent Factory and EpicOps, is still on track despite the security-driven pause. Epic has also pointed out that it doesn't hold customers' medical data directly. Hospitals and physician practices do, running Epic's software on their own infrastructure, which is exactly why the flaw lived in "certain customer configurations" rather than in Epic's core code everywhere at once.

Frankly, the six-week number is the part worth watching closest. Security teams almost always lowball how long a real fix takes once they're elbow-deep in it, especially across a customer base as fragmented as Epic's, where every hospital runs its own version of the configuration that caused the problem in the first place. If Epic comes back in November still patching, that tells you more about the actual scope of this than Faulkner's conference remarks did.

There's no clean answer yet on whether anyone exploited this gap before Mythos found it. Epic hasn't said, and an audit trail that doesn't record the access in question isn't exactly going to produce an answer later, either.

**Also read:** [Intel stock jumps 14% as Meta's Muse AI agent flips the chip trade](https://startupfortune.com/intel-stock-jumps-14-as-metas-muse-ai-agent-flips-the-chip-trade/) • [JPMorgan flips bullish on IREN weeks after telling investors to sell it](https://startupfortune.com/jpmorgan-flips-bullish-on-iren-weeks-after-telling-investors-to-sell-it/) • [IREN Stock Falls Below $41 Even As Its AI Cloud Backlog Tops $13 Billion](https://startupfortune.com/iren-stock-falls-below-41-even-as-its-ai-cloud-backlog-tops-13-billion/)

*This article is posted in [AI News](https://startupfortune.com/category/ai/), check it out for more related stories.*

[Washington's AI export controls are handing Asian labs the frontier race they were supposed to lose](https://startupfortune.com/washingtons-ai-export-controls-are-handing-asian-labs-the-frontier-race-they-were-supposed-to-lose/)

Washington's decision to ban Anthropic's Fable 5 and Mythos from foreign users triggered a swift competitive response from Asian AI labs, with Tokyo's Sakana AI launching Fugu as an orchestration system explicitly designed to sidestep export control risk, and Beijing's 360 Security unveiling Tulongfeng as a direct Mythos rival. The two-week ban... - [US AI export controls impact on](https://startupfortune.com/washingtons-ai-export-controls-are-handing-asian-labs-the-frontier-race-they-were-supposed-to-lose/) - [Claude Mythos and Fable model restrictions](https://startupfortune.com/washingtons-ai-export-controls-are-handing-asian-labs-the-frontier-race-they-were-supposed-to-lose/)

## Join the discussion

[Open in the community →](https://startupfortune.com/community/)

Almost there. Sign in and your reply posts straight away.
