Epic’s Reported Development Pause Highlights AI’s New Role in Security Priorities


TechCrunch
news
Medical records giant Epic pauses product development to fix security bugs that risk patients’ data
Tech Beat
news
Epic Pauses Development After AI Finds MyChart Security Flaws
Grab The Axe
news
OpenAI Notifies 100+ Organizations Its Models Reached (10/02/2026)
Epic pause
Epic reportedly paused most product development for about six weeks after Anthropic’s Mythos model found MyChart security flaws.
Silent access
Some MyChart configurations could reportedly allow patient-record access without creating intrusion log entries.
AI pressure
Frontier cyber models are accelerating vulnerability discovery, forcing vendors to weigh feature roadmaps against urgent remediation.
Epic Systems has reportedly paused most product development for several weeks to address security flaws identified by Anthropic’s Mythos cybersecurity model. The move underscores how frontier AI systems are beginning to reshape software-release priorities for vendors in critical sectors such as healthcare.1
The reported pause centers on MyChart, Epic’s widely used patient portal. According to TechCrunch, Epic founder and CEO Judy Faulkner told Modern Healthcare the pause was expected to last about six weeks while the company worked to safeguard its products after Mythos surfaced flaws that could allow access to patient data.1 Epic Chief Security Officer Stirling Martin told The New York Times that some MyChart customer configurations could allow outsiders to access patient records without creating an intrusion record in the software’s logs, TechCrunch reported.1
Epic has not publicly disclosed technical details of the bugs, which configurations may be affected or whether any exploitation occurred. Several reports emphasized that there has been no confirmed breach, victim count or regulatory investigation tied to the specific MyChart issue.46
For health technology and security executives, the significance extends beyond one vendor’s remediation effort. AI-assisted security testing is shortening the time needed to find complex flaws, including logic and configuration risks that may fall outside conventional vulnerability scanning. That acceleration can shift a software organization’s top priority from shipping features to validating, fixing and coordinating patches for weaknesses that AI systems expose.
MyChart supports access to medical information across hospitals and physician practices. TechCrunch reported that Epic’s MyChart software is used to maintain more than 320 million patient records in the United States, while noting that Epic says healthcare providers, not Epic, control customer medical data.1 DiarioBitcoin similarly reported that the figure reflects the scale of potential exposure, but does not mean all records were compromised or that every Epic customer was affected.4
The most sensitive reported risk is not only unauthorized access. It is the possibility that some access might not appear in logs hospitals use to detect intrusions, investigate incidents and support breach determinations.15 AsumeTech described the concern as “silent access,” meaning an unauthorized user could potentially view sensitive data while bypassing internal audit logs in certain MyChart configurations.5
That distinction matters for healthcare operators. If a conventional breach leaves log evidence, security teams can scope the intrusion, notify affected parties and preserve forensic records. If a vulnerability undermines logging, defenders may not be able to rule out access by searching audit trails. Grab The Axe advised hospitals and clinics running Epic to ask which configurations are affected and whether their deployments are among them, warning that a flaw that leaves no log entry cannot be excluded through log searches alone.3
The reported Epic response illustrates a governance shift: when AI finds credible weaknesses in critical software, remediation may compete directly with product delivery. Tech Beat characterized the six-week effort as a rare development pause driven by concern that AI can accelerate both vulnerability discovery and exploitation.2
That dynamic is becoming a sectorwide issue. Professional Security Magazine, citing Forrester predictions, described a “hamster wheel of AI-assisted vulnerability discovery” in which patch volume and remediation pressure increase as AI systems expose weaknesses faster than traditional engineering workflows can absorb.8 The same report said software engineers may face pressure from major vendors issuing very large patch releases across many products at once.8
The implication for executives is that AI-assisted testing is not just another application-security tool. It can become a release-management event. Vendors may need standing processes for triaging AI-generated findings, validating exploitability, prioritizing fixes, coordinating with customers and deciding when roadmap commitments should yield to security work.
The Epic case also reflects the dual-use problem shaping frontier cyber models. A model capable of finding subtle flaws for defenders may also reveal pathways attackers could pursue if comparable capabilities become widely available.
Google’s launch of Gemini 4 Argon shows the same tension. TechRepublic reported that Google is giving trusted cyber defenders early access to the model’s full security capabilities, including vulnerability hunting, validation and patching, while keeping broader access controlled because those capabilities could pose misuse risks.7 In early testing, the model reportedly helped uncover a previously unknown critical healthcare software vulnerability that exposed sensitive personal information, though Google did not identify the software.7
That pattern suggests a near-term model for the industry: powerful cyber AI systems may first be deployed through restricted programs, selected partners and controlled evaluations. But even under controlled access, their findings can create urgent obligations for vendors whose software handles sensitive records, payments, identity or infrastructure operations.
Epic has disputed parts of the development-pause narrative. Unbiased Headlines reported that after Faulkner’s reported comments about pausing most new product development, Epic later said its product roadmap remained on track.6 AsumeTech also noted tension between the reported “security sprint” and Epic’s roadmap messaging, suggesting that non-security feature work may be deferred while engineers focus on hardening the codebase.5
For customers, the practical questions are narrower: whether their configurations are affected, when fixes will arrive, whether compensating controls are available and how to validate historical exposure if logging could have been bypassed. Public reporting so far has not identified affected customers or confirmed unauthorized access.346
The healthcare context raises the stakes. TechCrunch cited the 2024 Change Healthcare ransomware attack, which exposed health data on more than 192 million people, and noted that recent healthcare and technology breaches have affected tens of millions of Americans.1 Tech Beat reported that the Department of Health and Human Services lists a DentaQuest breach affecting 15 million people as the largest healthcare-related breach of 2026 so far.2
For software vendors, the lesson is that AI-assisted vulnerability discovery may require preplanned escalation paths beyond the security team. Product leaders, legal teams, customer success teams and executives may need to decide quickly whether to slow feature development, issue urgent configuration guidance or disclose limited details before full technical fixes are ready.
For healthcare providers, the episode is a reminder that vendor security posture is now part of operational resilience. As frontier models improve, the organizations best positioned to benefit will be those that can patch faster, verify configurations, demand clear vendor communications and treat AI-discovered vulnerabilities as board-level release and risk-management issues — not just bug backlogs.

Google is positioning Gemini 4 Argon as a frontier model for software engineering, enterprise automation and cyber defense, but it is not releasing the system broadly. Instead, the company is making vetted access, monitoring and security governance part of the product itself.

Circuit Breaker Labs is testing chatbots with AI-generated users that vary by age, language, culture and communication style. The shift points to a new safety benchmark for consumer AI: whether systems can recognize psychological risk as it develops over time, not just refuse a dangerous prompt.

Fortinet says CVE-2026-104286, a critical FortiMail path traversal vulnerability, is being exploited in the wild, and CISA has set an October 4 remediation deadline for federal agencies. Enterprise defenders should treat patching or mitigation as only the first step, then validate exposure, logs, files, indicators of compromise and possible abuse of the email gateway control plane.

Apple says it will add stricter controls around macOS Full Disk Access as AI agents seek broad local access to files, messages, mail and browsing history. The shift signals that desktop operating systems may need new consent, auditing and privilege models for agentic apps.
MyChart
Epic’s patient portal software, widely used by hospitals and physician practices to let patients access medical records, appointments and related services.
Audit logs
System records that show who accessed data and when; healthcare organizations rely on them to detect intrusions and investigate possible breaches.
Frontier cyber model
An advanced AI model trained or adapted for cybersecurity tasks such as finding, validating and sometimes helping patch software vulnerabilities.
Silent access
A reported class of risk in which unauthorized access may occur without creating the log evidence defenders normally use to detect it.
Comments