Skip to content

Anthropic's Mythos model found holes in MyChart, so Epic halted most new product development: the system holds over 320 million patient records

1 min read
Share
Anthropic's Mythos model found holes in MyChart, so Epic halted most new product development: the system holds over 320 million patient records

Epic, the company behind MyChart, the software through which patients in the US access their medical data, has halted most of its work on new products. Founder and CEO Judy Faulkner told Modern Healthcare last month that the pause will probably last six weeks, while work on "hardening" the products continues.

The trigger: Anthropic's Mythos model, which specialises in cybersecurity, discovered flaws that could have allowed access to patient data. The company hasn't disclosed the nature of the bugs, but chief security officer Sterling Martin told the New York Times that some MyChart configurations at client sites could have let outsiders access records without leaving a single trace in the logs.

Could the same flaw have been used to alter records without anyone noticing? Martin said the model didn't provide an answer to that, but the risk was big enough to be fixed. That's a sentence nobody wants to hear about their own medical record.

The numbers explain why this isn't a technical footnote. MyChart maintains more than 320 million patient records at hospitals and clinics across the US. Epic says it has no access to the medical data itself - hospitals and clinics are responsible for that. But a bug even Epic didn't know about could have opened a route for hackers into multiple systems across the country at once.

It's rare for a company to stop work to patch security holes. The reason is a new reality: AI tools that find and exploit flaws fast. The same kind of tool that showed Epic its holes today, in the wrong hands, shows them to someone else. Who finds them first - the defender or the attacker?

Health data is a favourite prize because attackers reckon institutions will pay to keep it from being published. In 2024 a ransomware attack on Change Healthcare, a company owned by insurance giant UnitedHealth that processes payments and billing for most Americans, made off with health data on more than 192 million people - the majority of the US population. The company paid the hackers twice not to publish it. The biggest health data breach this year, according to the US Department of Health, is at dental insurer DentaQuest, with 15 million people affected.

A medical record can't be changed like a password. Once it leaks, it has leaked forever. That's why the six-week pause is more than a PR move - it's also a reminder of how much of our most sensitive data depends on who finds the holes first. And is anyone even looking for the holes in hospital systems in our part of the world?