October 4, 2026
AI Can Find Software Flaws Faster Than Hospitals Can Fix Them
Epic slowed most new work to patch MyChart weaknesses that Anthropic's Claude Mythos helped uncover. The fixes now fall to hospital IT teams, and the scam emails fall to patients.

The Short Version
In late September, Epic Systems founder and CEO Judy Faulkner told a health care conference that her company was pausing most new technology work for about six weeks. The reason was security. Last week, Epic's security chief, Stirling Martin, told The New York Times that some MyChart setups could let someone view patient records without leaving a trace in the audit trail. That's the log hospitals use to see who opened a chart. Epic found the weakness while testing its own code with Claude Mythos, Anthropic's restricted security model. Epic's software holds records for more than 300 million patients. Nobody has reported that the gap was used, and Epic says its product roadmap is unchanged. The hard part starts now. Martin's advice to hospitals was to get ready to "patch, patch, patch." AI can now find flaws faster than hospital IT teams can safely install fixes. While they work, criminals are using AI to write fake MyChart emails polished enough to fool careful patients.
A Gap in the Log of Who Looked
Every time a nurse, billing clerk or doctor opens your chart, the system is supposed to write it down. Federal privacy rules require hospitals and their vendors to run systems that "record and examine activity" wherever protected health information lives. That record is how a hospital catches an employee snooping on a neighbor's test results, and it's how investigators piece together a breach after the fact.
Martin's description was specific. Certain customer configurations of MyChart could allow someone to view records without the access being logged. Whether someone could also change a record is murkier. "Whether things can be changed is more complicated, and depends on other parts of the technology and not necessarily Epic's in that case," he said.
A few limits belong right here. The finding comes from Epic itself. As of Sunday morning I couldn't find a public advisory naming the affected configurations. I also found no outside test that reproduced the problem and no report that attackers used it. Epic told TechCrunch it has no direct access to its customers' medical data. The hospitals and clinics that run MyChart hold that data, so the patching lands on them too.
Why the Fixes Pile Up at the Hospital
Epic saw this coming. At the company's users group meeting in August, Martin described pointing AI models at Epic's own code. "Despite a codebase that is several 100 million lines large, AI models can easily make observations that our expert developers can't see," he said. He told health system IT teams to expect a higher-than-usual number of urgent security fixes.
Anthropic has been candid about the downstream problem. Project Glasswing is the program that gives selected companies access to Mythos for defensive work. In a May update, Anthropic said the model had found more than 10,000 high- or critical-severity flaws in widely used software. At that point, 75 of the 530 serious bugs Anthropic had reported to software maintainers had been patched. Some maintainers asked it to slow its reports because they needed time to design fixes, and the average serious bug took about two weeks to patch. "The relative ease of finding vulnerabilities compared with the difficulty of fixing them amounts to a major challenge for cybersecurity," Anthropic wrote.
Hospitals sit at the slow end of that chain. Health-ISAC, the health sector's threat-sharing group, said in a July white paper that the multi-week patch cycle no longer matches the speed at which flaws surface. It urged members to push vendors toward fixes in "hours or days." In August its security chief, Errol Weiss, wrote that a hospital team might spot a flaw in an afternoon. Installing the fix safely then runs into vendor testing, scheduled downtime and the pace of a working hospital. His advice was to limit what an attacker can do while an update rolls out.
Epic's six weeks put that tension on a calendar. Discovery now moves at machine speed. Installing a fix still means a person schedules downtime, tests the screens nurses depend on, and confirms the overnight shift can still pull up a medication list. Martin's warning to hospitals went one step further: "As soon as they think they are patching fast enough, they need to patch faster."
One Clinic's Next Six Weeks
Picture Dana, the IT manager at a regional orthopedic group with a few dozen doctors and three IT staff. Thousands of patients use the group's MyChart portal to book visits and read results. Over the next few weeks she can expect more urgent Epic fixes than usual, stacked on her normal workload.
This example assumes her group runs its own Epic system. A practice that uses a hospital's Epic setup would ask the hospital who tests, installs and schedules downtime, then track that handoff.
Before the first one lands, she needs a current list of the MyChart features her group has switched on and customized. Epic's warning is about configurations, and hers are specific to her group. She also needs the name of the person who approves downtime. And she should confirm the front desk still knows the paper procedure for days when the portal goes dark.
Then she starts small. She applies the first urgent fix in a test copy of the system and has a nurse and a scheduler run their ten most common tasks. Once both sign off, she moves it to the live system during a quiet evening window. Her baseline is the average number of days her group took to install an Epic security fix over the past year. Beating that number is progress she can show the partners.
Counting a fix as finished takes one extra step that's easy to skip under pressure. A fix is done when it's installed and when a test login opening a test patient's chart shows up in the audit report afterward. That check takes a few minutes, and it covers the exact thing this flaw put at risk.
The added work is real. Each round eats testing hours, and a rushed install can break a scheduling screen on a Monday morning. The likeliest failure is an old custom setting that clashes with the new code, or an add-on from another vendor that stops talking to Epic. Dana should settle in advance who can halt a rollout mid-stream. I'd give that call to the practice administrator or medical director, in writing. Then the call gets made quickly at 7 a.m., with patients in the waiting room.
The Email That Looks Right
While hospitals patch, patients face a separate problem that lives outside Epic's code. In late August, Becker's counted 41 health systems that had warned patients about fake "MyChart Medicare Kit" emails and texts. Epic said those scams reflected criminals exploiting the popularity of the MyChart brand. Pennsylvania's attorney general warned that the links aim to steal passwords and get into patients' portals.
AI makes those fakes harder to spot. John Riggi, the American Hospital Association's national adviser for cybersecurity, told the Times that criminals are using AI to produce convincing fake MyChart emails. The targets are credit card numbers and logins. Several health system warnings from August still told patients to watch for grammatical errors. That tip ages fast once a language model writes the message.
The better defense is a habit that ignores how the email looks. Patients who open MyChart only from the official app or a saved bookmark skip the link-judging problem entirely.
Opportunity Radar
Small practices are about to absorb a burst of urgent vendor fixes with thin IT staff. Epic's flaw also involves the very log that compliance officers answer for. The pitch I'd test is a fixed-price "patch and prove" service for independent clinics and small hospital groups. You test each urgent fix against the practice's most common workflows and install it in an agreed window. Then you hand back a one-page record showing audit logging still works. The likely buyers are practice administrators and compliance officers, since federal rules already require their practices to keep audit controls. Demand is a hypothesis, so test it cheaply. Offer the service at cost to two or three practices you know during the next six weeks, and track hours per fix and whether the audit check ever catches a problem. Walk away if most small practices rely on a larger health system or Epic's own hosting for patching, or if they can't give you a test environment.
What You Can Do With This
If you use MyChart
Your hospital may schedule extra maintenance over the next month or so while it installs Epic's fixes. Open MyChart from the official app or a saved bookmark, and delete unexpected messages about free kits, refunds or urgent bills without clicking anything. Epic's MyChart safety page says that if you typed your password into a suspicious page, you should reset it through your health care organization's MyChart. If you entered card details, it says to call your bank and have the card replaced.
If you run IT or compliance at a hospital or clinic
Name one owner for Epic security notices and track the days from release to install. After each fix, confirm that a test chart view lands in the audit report. Decide who can stop a rollout before you need that person.
If you work a front desk or nursing unit
Plan for short system downtimes and know where the paper procedures live. When a patient calls about a strange MyChart email, have them check for the message inside the app, and forward the sample to your security team.
If you own a small business that runs on vendor software
Epic's pause is an early look at what happens when AI security testing reaches the software you rely on for payroll, scheduling or billing. Ask your key vendors how fast they ship security fixes and how they'll tell you about them.
The Bigger Picture
AI has made finding software flaws fast. Epic's six weeks show where the bill comes due. It lands on the people who install fixes, test clinical screens and field patients' calls. It also lands on patients, who now have to tell a real portal message from a polished fake. Treasury Secretary Scott Bessent, talking about AI with Axios in an interview published Saturday, put it this way: "We really need to start worrying more about resilience and defense, too." My read is that health care's next useful security number is how many days a fix takes to reach the bedside, and hospital budgets and staffing will set it. The six weeks run out around early November. I'd judge Epic's push then by one test: whether hospitals report that the fixes arrived, installed cleanly and left the audit trail working.
References
Staying safe from scams and fraud (MyChart, Epic Systems) Epic races to patch flaws that could allow undetected record access (Becker's Hospital Review, Oct 1, 2026) Medical records giant Epic pauses product development to fix security bugs that risk patients' data (TechCrunch, Oct 2, 2026) Epic shifts focus to cybersecurity while AI, interoperability agenda still on track, company says (Fierce Healthcare, Sept 23, 2026) Epic pauses product development amid cybersecurity concerns (SC Media, Oct 3, 2026) Project Glasswing: An initial update (Anthropic, May 22, 2026) 45 CFR 164.312(b), HIPAA Security Rule audit controls (eCFR, current) H-ISAC: Frontier AI leaves third-party patch timelines obsolete (Health System CIO, July 16, 2026) What happens when attackers move faster than healthcare can patch? (Health-ISAC, Errol Weiss, Aug 19, 2026) 41 health systems warn of MyChart Medicare kit scam (Becker's Hospital Review, Aug 27, 2026) AG Sunday warns Pennsylvanians of phishing scam targeting MyChart patient portal users (Pennsylvania Office of Attorney General, Aug 28, 2026) U.S. to propose emergency AI notification system with China (Axios, Oct 3, 2026)
AI Next Wave