Unbiased headlines. Facts, not spin.
Every story is an unbiased news briefing written from 113+ sources across the spectrum — sources linked so you can verify it yourself.
Epic Found a MyChart Bug That Could Hide Hacker Access to Patient Records, Then Disputed Its Own Pause-in-Development Story

Epic Systems, the company behind MyChart, says an AI model it ran against its own software found a security flaw serious enough to shake up its development schedule. The company then muddied the story about how serious that shake-up actually was.
Epic CEO Judy Faulkner disclosed the issue at an industry conference in late September, telling Modern Healthcare the company would pause most new product development for about six weeks to fix it, according to reporting picked up by TechCrunch. Faulkner framed it as an unusual, company-wide response to a vulnerability found during a security review.
Then Epic walked part of that back. Quartz, citing the New York Times, reported that after initially saying most new product development had been paused, Epic later said its product roadmap remained on track. A software vendor whose platform underpins hospital record-keeping for over 320 million patients telling the public two different things about how seriously it is treating a known security gap is newsworthy.
What the bug actually does
The flaw was surfaced by Mythos, Anthropic's frontier cybersecurity model, which Epic deployed through Anthropic's Project Glasswing program. Anthropic launched Glasswing with 50 initial partner organizations in April and expanded it in June to cover healthcare, power, water, communications, and hardware companies, according to Fierce Healthcare.
Epic's chief security officer, Stirling Martin, told the New York Times that certain customer configurations of MyChart could let outsiders access patient records without the intrusion showing up anywhere in the system's logs. Martin said Mythos did not determine whether the same flaw could be used to alter records undetected, only that unauthorized viewing was possible. "Whether things can be changed is more complicated, and depends on other parts of the technology and not necessarily Epic's in that case," Martin told the Times.
Kevin Fu, a professor who directs the Archimedes Center for Healthcare and Medical Device Cybersecurity at Northeastern University, told the Times that a flaw enabling silent, undetected manipulation of patient records "is the exact opposite of integrity." No source has confirmed that any patient record was actually accessed or altered through this bug. There is no announced breach, no confirmed victim, and no regulatory investigation tied to this specific vulnerability as of this writing.
Who's responsible, and the fair counter-argument
Epic has repeatedly said it does not itself hold customers' medical data. That responsibility sits with the hospitals and clinics running MyChart. The company also notes that the vulnerable configurations were choices made at the customer level. Large enterprise software is deployed differently by every hospital system, and a vendor cannot force every customer to run the most locked-down configuration available.
But that framing has limits. If Epic's own platform allowed a configuration to exist that could hide an intrusion from the audit trail entirely, that is a design and default-settings problem Epic built, even if a hospital IT department ultimately flipped the switch. Critics of the "it's the customer's responsibility" defense argue the burden belongs with the vendor that wrote the software capable of hiding the breach in the first place, not solely with hospital IT staffers who may not have known the risk existed.
The bigger threat picture
This isn't happening in a vacuum. Healthcare was the most targeted critical infrastructure sector in 2025, recording 460 ransomware incidents and 182 data breaches, according to FBI figures cited by Quartz. The 2024 ransomware attack on Change Healthcare, owned by UnitedHealth, exposed data on more than 192 million people, and the company paid the hackers twice to keep it from being published, per TechCrunch. In 2026 alone, breaches have hit CareCloud, McKesson, and UK-based Craneware, while the Department of Health and Human Services currently lists a 15-million-person breach at dental insurer DentaQuest as the year's largest healthcare-related incident.
Epic is also fighting a separate, live threat: a phishing campaign using AI-generated emails to impersonate MyChart and steal patients' credit card numbers and login credentials, according to John Riggi, national cybersecurity adviser for the American Hospital Association. Riggi said Epic and its hospital clients have spent the past month urging patients to access records only through the official MyChart app rather than clicking email links.
Martin's warning to hospital IT departments going forward was blunt: "Ultimately they need to get ready to patch, patch, patch. As soon as they think they are patching fast enough, they need to patch faster."
What's still unresolved: Epic has not disclosed the technical nature of the bug, which specific customer configurations were affected, or whether any hospital has confirmed unauthorized access occurred before the fix. Whether the six-week remediation window Faulkner cited in September holds, given the company's own conflicting statements about whether development ever actually stopped, is something hospital IT departments will be watching for in the weeks ahead.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.