Skip to main content
Back to News
news/AI Safety

AI Security Model Uncovers Data Flaws in Epic Patient Records

Anthropic's Mythos model found logging gaps in Epic's MyChart records software, pushing the healthcare giant to pause most development for six weeks.

Stefan Trbojevic

Stefan Trbojevic

2 October 20262 min read
LinkedIn
Abstract network of routing nodes converging on a hardened data vault, representing an AI security audit

The takeaway

AI security models now find vulnerabilities faster than organisations can patch them, so automated triage and faster patch cycles are the real bottleneck.

Why it matters for builders

Security review is becoming an agent workload: scan a codebase in an isolated container, validate findings automatically, and route them into ticketing. Teams that automate triage will absorb the coming wave of AI-discovered vulnerabilities; teams that do not will stall their own roadmaps, exactly as Epic did.

AI Security Model Uncovers Flaws in Epic Patient Records

Epic Systems, the company behind the MyChart patient portal, has paused most of its product development for roughly six weeks after an Anthropic cybersecurity model surfaced flaws that could expose patient records. It is one of the clearest cases yet of AI doing security work at a scale human reviewers cannot match, and of the disruption that follows.

What happened

Epic founder and chief executive Judy Faulkner told Modern Healthcare that most new development was halted while the company works on safeguarding its products. The flaws surfaced after Epic pointed Mythos, Anthropic's frontier cybersecurity model, at its own software.

Chief security officer Stirling Martin told The New York Times that some customer configurations of MyChart could let outsiders read patient records without writing an entry to the software's access logs. The model could not confirm whether records could also be altered undetected, but Martin judged the risk serious enough to remediate.

MyChart carries more than 320 million patient records across US hospitals and clinics. Epic does not hold customer medical data itself, so a configuration flaw can be replicated across many provider deployments at once. Epic participates in Project Glasswing, Anthropic's programme that gives roughly 50 partners early access to Mythos for defensive work.

Diagram of stacked data layers scanned for hidden fracture lines by a security model

Why it matters

Volume is the story. In the first month of Project Glasswing, partners used Mythos to find more than ten thousand high- or critical-severity vulnerabilities, according to Anthropic. Cloudflare alone found 2,000 bugs across critical-path systems, 400 of them high or critical severity. Anthropic's own scans of over 1,000 open-source projects turned up an estimated 6,202 high- or critical-severity flaws, with 90.6 percent of the 1,752 externally reviewed findings confirmed as real.

Patch throughput has not kept pace. Anthropic reported in its Mythos capabilities assessment that fewer than one percent of the vulnerabilities the model surfaced had been fully patched by their maintainers. Some open-source maintainers have asked the company to slow down disclosures so they can absorb the queue.

The builder takeaway

  • Treat AI-driven security review as an agent workload. An isolated container, a source tree, a prompt, and an agent that hypothesises, runs the software, and writes a proof of concept is now a realistic pipeline you can assemble.
  • Automate triage, not just scanning. Thousands of findings a month break any manual queue. Deduplicate, score severity, route to owners, and open tickets without a human in the loop.
  • Assume the same capability on the attacker side. If a model can find a decades-old flaw in hours, your patch window is shrinking faster than your release cycle.
  • Treat audit logging as a security control. The Epic issue was partly about access that left no trace, which is the failure mode that makes everything else undetectable.
Share𝕏

The Automation Brief

Read 5 AI stories instead of 50.

The essential moves in AI agents, models, automation and infrastructure — filtered for builders and operators, with the part that actually matters.

No noise. Unsubscribe anytime.

Editorial notes

Reported by

Stefan Trbojevic

Edited by

n8n Lab Editorial

Published

2 October 2026

Updated

2 October 2026

AI disclosure: AI assisted with research and drafting. Factual claims are reviewed by an editor.

n8n Lab is an independent service provider. We are not affiliated with, endorsed by, or sponsored by n8n GmbH. “n8n” is a trademark of n8n GmbH and is used here only to describe the platform-specific implementation and automation services we provide.