Epic, the software technology company that develops the widely used MyChart system for accessing patient medical data, has paused most of its product development. This pause is to allow the company to focus on safeguarding its software and systems from potential cyberattacks.
Judy Faulkner, Epic's founder and chief executive, stated last month that the pause is expected to last six weeks. This decision follows the discovery of security flaws by Anthropic’s Mythos cybersecurity model, which could potentially allow access to patient data.
While the specific nature of the bugs has not been disclosed, Epic's chief security officer, Stirling Martin, indicated that certain customer configurations of MyChart might allow external access to patient records without recording any intrusion in the software's logs. Martin noted that the AI model did not specify if the bug could be exploited to alter records undetected, but considered the risk significant enough to warrant remediation.
MyChart software is used to manage over 320 million patient records across healthcare providers in the United States. Epic states it does not have access to customer medical data, with this responsibility falling to healthcare providers. However, an unknown bug could potentially allow hackers to compromise multiple affected MyChart systems and access stored data.