Over 320 million patient records managed
Epic Systems, a leading provider of electronic health records (EHR), has initiated a company-wide pause on most product development to address critical security flaws in its widely used MyChart patient portal. The development freeze, expected to last around six weeks, was triggered by the discovery of vulnerabilities by an advanced AI cybersecurity model named Mythos from Anthropic. The flaws could allow an external party to access sensitive patient medical records without leaving a trace in system logs. Given that MyChart manages data for over 320 million patients, the potential impact is massive, prompting Epic to take this proactive and drastic measure to safeguard patient data.
While Epic has not disclosed the specific technical nature of the vulnerabilities, the core issue revolves around the potential for undetected access to patient data. According to Epic's Chief Security Officer, certain customer configurations of MyChart are susceptible. The flaw allows an attacker to view patient medical records, but the system would fail to log this unauthorized access. This
Implementing out-of-band monitoring and logging at the network or host level can help detect access that bypasses application-level logging.
Healthcare organizations using MyChart must prepare to apply the forthcoming patches from Epic as soon as they are available.
Ensuring the MyChart application is properly isolated can limit the potential for an attacker to leverage a flaw to access other parts of the network.
Reviewing and hardening MyChart configurations as per vendor best practices can mitigate risks, as the report mentions the flaw affects 'some customer configurations'.
Given that the vulnerability allows for access that is not recorded in system logs, application-level detection is insufficient. Healthcare organizations must implement Network Traffic Analysis (NTA) to monitor all data flows to and from MyChart servers. By establishing a baseline of normal traffic patterns, security teams can detect anomalies that could indicate a breach. Specifically, they should configure alerts for large or unusual data transfers from MyChart servers to external IP addresses, or for access patterns that don't correlate with known legitimate user sessions. This provides a critical, independent layer of detection that does not rely on the compromised application's logging.
The primary remediation for this issue will be a software patch from Epic. Healthcare IT departments must treat this as a critical, emergency update. They should establish a clear plan for testing and deploying the patch across all MyChart instances as soon as it is released. Given the six-week development pause, organizations have a window to prepare their environments, schedule maintenance windows, and ensure they have the resources allocated for a rapid rollout. Verifying the patch's successful application and confirming that the logging issue is resolved will be a crucial final step.
The reports state that the vulnerability affects 'some customer configurations.' This implies that misconfiguration is a key factor. While awaiting the patch, organizations using MyChart should immediately conduct a thorough review of their system configurations against Epic's security best practices and hardening guides. Any deviations from recommended settings should be investigated and corrected. This proactive hardening can potentially mitigate the vulnerability or reduce the attack surface before the official patch is even available, providing an immediate risk reduction.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.