Epic moved engineers off new product work to fix the flaws. Judy Faulkner, Epic’s founder and CEO, told Modern Healthcare the work would likely take about six weeks. Epic later said its AI and interoperability plans remained on track, Fierce Healthcare reported.
Mythos did not determine whether the flaws could be used to alter records without detection, TechCrunch reported. Martin said the risk was high enough to fix. MyChart supports more than 320 million patient records across U.S. hospitals and doctors’ offices. Epic says providers, not Epic, control that data.
AI Finds Flaws That Years of Review Missed
Epic is part of Project Glasswing, Anthropic’s program that gives selected organizations access to the unreleased Mythos model for defensive security work. Martin confirmed Epic’s participation at the company’s August user group meeting, Fierce Healthcare reported. He told health system IT teams to expect a “higher-than-usual number of urgent security fixes.”
We’d love to be your preferred source for news.
Please add us to your preferred sources list so our news, data and interviews show up in your feed. Thanks!
Anthropic launched Glasswing on April 7 with partners including Amazon Web Services, Apple, Cisco, CrowdStrike, Google, JPMorgan Chase and Microsoft, the company said. Mythos found a 27-year-old flaw in the OpenBSD operating system, according to Anthropic. It also found a 16-year-old flaw in FFmpeg video software that automated testing had hit 5 million times without catching.
Healthcare breaches cost an average of $6.64 million, the highest of any industry for the 13th straight year, IBM found in its 2026 Cost of a Data Breach Report. The 2024 ransomware attack on Change Healthcare, a UnitedHealth unit, exposed health data on more than 192 million people, TechCrunch reported.
Patching Becomes the Bottleneck
About 50 Glasswing partners found more than 10,000 high- or critical-severity vulnerabilities in the program’s first month, Anthropic reported in a May update. Cloudflare alone found 2,000 bugs, 400 of them high or critical. Of 530 high- or critical-severity bugs Anthropic disclosed to open-source maintainers, 75 had been patched at the time. A fix took about two weeks on average. Anthropic said security progress is now limited by how fast defenders can verify, disclose and patch flaws, not how fast they find them.
Banks are adjusting to the same volume. Mythos has found several hundred to thousands of low- to moderate-ranked vulnerabilities in banks’ technology, and banks now patch flaws in days instead of weeks, PYMNTS reported. Anthropic CEO Dario Amodei said in May that organizations have six to 12 months to fix vulnerabilities before other AI models match Mythos, PYMNTS reported.
Few companies pause development to fix security bugs. Epic’s choice put a security finding ahead of new features for about six weeks. Each Epic fix also lands on the hospital IT teams that run MyChart, the same teams Martin told to expect more urgent updates.
For all PYMNTS AI coverage, subscribe to the daily AI Newsletter.