Epic Pauses MyChart Development Over Critical Security Flaws

Epic Systems Halts Development to Fix MyChart Security Flaws

HIGH
October 4, 2026
1m read
Security OperationsVulnerabilityCloud Security

Impact Scope

People Affected

Over 320 million patient records managed

Industries Affected

HealthcareTechnology

Geographic Impact

United States (national)

Related Entities

Organizations

Products & Tech

MyChart Mythos

Other

Anthropic

Full Report

Executive Summary

Epic Systems, a leading provider of electronic health records (EHR), has initiated a company-wide pause on most product development to address critical security flaws in its widely used MyChart patient portal. The development freeze, expected to last around six weeks, was triggered by the discovery of vulnerabilities by an advanced AI cybersecurity model named Mythos from Anthropic. The flaws could allow an external party to access sensitive patient medical records without leaving a trace in system logs. Given that MyChart manages data for over 320 million patients, the potential impact is massive, prompting Epic to take this proactive and drastic measure to safeguard patient data.


Vulnerability Details

While Epic has not disclosed the specific technical nature of the vulnerabilities, the core issue revolves around the potential for undetected access to patient data. According to Epic's Chief Security Officer, certain customer configurations of MyChart are susceptible. The flaw allows an attacker to view patient medical records, but the system would fail to log this unauthorized access. This

Timeline of Events

1
October 4, 2026
This article was published

MITRE ATT&CK Mitigations

Audit

M1047enterprise

Implementing out-of-band monitoring and logging at the network or host level can help detect access that bypasses application-level logging.

Healthcare organizations using MyChart must prepare to apply the forthcoming patches from Epic as soon as they are available.

Ensuring the MyChart application is properly isolated can limit the potential for an attacker to leverage a flaw to access other parts of the network.

Reviewing and hardening MyChart configurations as per vendor best practices can mitigate risks, as the report mentions the flaw affects 'some customer configurations'.

D3FEND Defensive Countermeasures

Given that the vulnerability allows for access that is not recorded in system logs, application-level detection is insufficient. Healthcare organizations must implement Network Traffic Analysis (NTA) to monitor all data flows to and from MyChart servers. By establishing a baseline of normal traffic patterns, security teams can detect anomalies that could indicate a breach. Specifically, they should configure alerts for large or unusual data transfers from MyChart servers to external IP addresses, or for access patterns that don't correlate with known legitimate user sessions. This provides a critical, independent layer of detection that does not rely on the compromised application's logging.

The primary remediation for this issue will be a software patch from Epic. Healthcare IT departments must treat this as a critical, emergency update. They should establish a clear plan for testing and deploying the patch across all MyChart instances as soon as it is released. Given the six-week development pause, organizations have a window to prepare their environments, schedule maintenance windows, and ensure they have the resources allocated for a rapid rollout. Verifying the patch's successful application and confirming that the logging issue is resolved will be a crucial final step.

The reports state that the vulnerability affects 'some customer configurations.' This implies that misconfiguration is a key factor. While awaiting the patch, organizations using MyChart should immediately conduct a thorough review of their system configurations against Epic's security best practices and hardening guides. Any deviations from recommended settings should be investigated and corrected. This proactive hardening can potentially mitigate the vulnerability or reduce the attack surface before the official patch is even available, providing an immediate risk reduction.

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Editorial Standards & Analyst Review

CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.

Tags

HealthcareEHRMyChartEpic SystemsVulnerabilityData PrivacyAI

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

⚡ Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.