Skip to content

Security3 publishers2 min readPublished

Epic pauses most development for about six weeks over MyChart flaws an AI model found

Epic has stopped most product development for roughly six weeks while it fixes MyChart flaws that an AI model uncovered, according to TechCrunch. No list of affected portal setups is public yet, so hospitals cannot check theirs against one.

The Watch · Security desk

What happened

  • Epic chief security officer Stirling Martin indicated that some MyChart configurations could let outside parties reach patient data without the access showing in system logs.
  • The AI model did not confirm whether patient records could also be altered without detection.
  • SC World, summarizing TechCrunch's reporting, described the pause as a proactive step to safeguard patient data.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure Hospitals running an affected MyChart configuration cannot use their own audit trail to show that outsiders did not read patient data.
  • decision For now, any hospital review is scoped to read access. A confirmed alteration path would widen it from who saw records to whether the records are still accurate.
  • cost Other Epic product work is deferred for roughly six weeks while effort goes to the fix.

A hospital that pulls its MyChart audit trail this week would see the same thing whether an outsider had read records or not [5]. Log review shows what a hospital's logs capture. By Martin's account, outside access through some configurations would not be in them [5].

Every detail so far comes from one report, TechCrunch's, as summarized by SC World [11]. Martin tied the problem to some configurations, so exposure will vary from one Epic customer to the next [5]. Epic has not disclosed the exact nature of the bugs [4]. The account describes potential weaknesses that could allow unauthorized access to patient records [3].

I'd expect the useful work before details arrive to be an inventory. It would cover which MyChart options a hospital has turned on, and which records of portal access it keeps outside MyChart itself. A hospital with that list can match its setup against the affected configurations quickly if Epic names them.

I think the clearest signal of how Epic rates the read-access risk is what it agreed to spend: most of its product development, for about six weeks [1][2]. Epic made that call while the question of undetected alteration was still open [7][6].

SC World places the pause beside breaches at Change Healthcare, CareCloud and McKesson that affected millions of people [8]. It also frames the episode as part of AI's dual role in finding and exploiting security flaws [10]. This report documents only the finding side. A model surfaced the weaknesses, and the vendor stopped work to fix them [3][1].

What to watch

  • Epic naming the affected MyChart configurations, the first point at which a hospital can check its own setup against a known list.
  • A finding on whether records could be altered without detection; a yes would widen hospital reviews to record integrity.
  • Whether the pause ends at about six weeks or runs longer.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories