🇸🇬 HireDeveloper.sg

320 Million Records and a 6-Week Freeze — What Epic’s AI-Found Bugs Changed About How I Hire in Singapore

Security engineer reviewing access logs and configuration settings on a dark monitor
Sebastian

Sebastian

Mobile App & Hiring Expert · October 3, 2026 · 10 min read

TL;DR

  • •What happened: on 2 October 2026 Epic paused most product development for about six weeks to fix MyChart flaws found by Anthropic’s Mythos model, on a platform holding 320M+ patient records.
  • •The detail that matters: the exposure lived in certain customer configurations — and the access left no intrusion log.
  • •Why that changes hiring: a config bug is partly your problem, and an unlogged read path means you can never prove it was not exploited.
  • •What I would change in a Singapore spec: hire for configuration ownership and detection engineering, not just secure coding — and for the judgment to triage AI-generated findings at volume.

Most security stories are not useful to a hiring manager. A vendor ships a patch, everyone upgrades, nothing about the team changes. The Epic story from 2 October 2026 is different, and the reason is buried in two clauses that are easy to read past: the exposure appeared in certain customer configurations, and the access left nothing in the logs. Those two clauses describe a kind of problem that no amount of secure coding would have prevented, and that most engineering organisations in Singapore have nobody specifically responsible for.

What Epic Actually Said

According to TechCrunch’s report on 2 October 2026, Epic has paused most new product development for roughly six weeks to remediate security vulnerabilities in MyChart, the patient portal that holds more than 320 million patient records across US healthcare providers. Founder and chief executive Judy Faulkner gave the six-week figure.

The flaws were not found by a penetration test or a bug bounty researcher. They were surfaced by Mythos, Anthropic’s frontier cybersecurity model, through Project Glasswing — a programme giving selected partners restricted access to the model specifically to find and fix vulnerabilities in their own software. Epic is a participant.

Epic chief security officer Stirling Martin told The New York Times that certain customer configurations of MyChart “could allow outsiders to access patient records without recording any intrusion”. Reporting also notes the model did not establish whether records could be silently altered, and that no breach has been confirmed. Corroborating coverage is available from Becker’s Hospital Review.

I want to flag the restraint in that last point before going further. Nobody has shown that patient data was taken. What has been shown is that if it had been, there would be no record of it — which is a different and in some ways worse position to be in.

Our expert take #1

Pay attention to the phrase “certain customer configurations”, because it quietly relocates the problem. A vulnerability in shipped code is the vendor’s to fix and yours to install. A vulnerability that only manifests under particular deployment settings is partly yours by construction — it depends on choices made in your instance, often years ago, usually by people who have left, and almost never documented with the reasoning attached. Every organisation I work with can tell me who owns their application code and who owns their cloud account. Almost none can tell me who owns the configuration posture of their vendor platforms. That role does not sit cleanly in engineering, or IT, or procurement, so it sits nowhere. This story is what nowhere costs.

Why This Reads Differently From Singapore

Epic’s installed base is American, and the direct regulatory consequences of this will be American. The structural lesson is not.

Singapore’s technology sector is unusually dependent on configured third-party platforms. A mid-sized bank, insurer, clinic group or logistics operator here typically runs a dozen or more vendor systems holding regulated personal data, each configured during an implementation project with a consultancy that has since rolled off. Under the Personal Data Protection Act, the obligation to protect that data sits with the organisation holding it, not with the vendor whose product it happens to be stored in. The configuration is yours. So is the consequence.

So the question this story poses to a Singapore engineering leader is not “are we running MyChart” — almost nobody here is. It is narrower and much less comfortable:

  • For each vendor platform holding personal data, who decided the current configuration, and when was it last reviewed against the vendor’s own hardening guidance?
  • For the most sensitive read path in each system, what log entry exists when a record is accessed — and how long is it retained?
  • If someone asked tomorrow whether that path had been abused in the last year, could you answer from data, or only from the absence of complaints?

In my experience most teams can answer the first question partially, the second rarely, and the third not at all. That is the hiring gap, and it is independent of industry.

Two Different Bugs, Two Different OwnersThe second kind does not get fixed by upgrading.Code vulnerabilityLives in shipped softwareVendor patches itYou schedule the upgradeOwner: clearConfiguration vulnerabilityLives in your deploymentSet years ago, undocumentedUpgrading changes nothingOwner: usually nobodyNow add: the access left no intrusion logYou can fix the setting. You can never prove it was not used.Prevention is a control you can buy. Detection is a capability you have to staff.Most security job specs are written almost entirely for the first one.

Our expert take #2

The six-week pause is being read as a cost. I read it as the only honest option available, and as a signal about what Epic concluded it could not parallelise. Halting most product development across an organisation of that size is extraordinarily expensive and politically brutal; nobody does it to look diligent. You do it when remediation requires the same senior people the roadmap requires, and when shipping features into an unresolved configuration problem would expand the surface you are trying to close. For a Singapore engineering leader the transferable question is uncomfortable: could you pause? If a finding of this shape landed on your platform next month, is there a mechanism by which the roadmap stops, and does anyone have the authority to invoke it — or would remediation be squeezed into the margins of a quarter that has already been committed to the board? Most organisations have no such mechanism. Epic’s willingness to use theirs is the most instructive part of this story.

The 3 Things I Would Change in a Singapore Security Spec

I review a lot of security job specifications for employers here. Nearly all of them are written around prevention, and the Epic story is a clean argument for rebalancing. Three concrete changes.

1. Name configuration ownership as a responsibility, not a task

Add a line that makes somebody accountable for the configuration posture of third-party platforms holding personal data: reviewing each against vendor hardening guidance on a stated cadence, recording the justification for deviations, and flagging settings whose original rationale nobody can reconstruct.

This is deeply unglamorous work and it is almost never in a job description, which is precisely why it accumulates. The candidate signal to look for is someone who talks about configuration drift and documented exceptions rather than about tools. If you are building this capability from scratch, building a cybersecurity engineering team in Singapore covers how the first three hires should be sequenced.

2. Put detection engineering on equal footing with prevention

The unlogged access path is the expensive part of this story. Prevention failures are recoverable; a missing audit trail is permanent, because the data that would have answered the question was never written.

So test for it directly. My preferred interview question takes two minutes: pick the most sensitive read path in our system, and tell me what evidence would exist tomorrow morning if it were abused tonight. Strong candidates ask about log retention and log integrity before answering. Weaker ones describe a SIEM product. The role this points at is covered in hiring application security engineers in Singapore, and in regulated sectors the fintech variant in hiring DevSecOps engineers for fintech.

3. Hire for triage capacity, because discovery is no longer the bottleneck

This is the structural shift and it is worth being explicit about. A frontier model running against a large codebase, under a controlled access programme, found what conventional review and years of commercial penetration testing had not. Whatever else that means, it means discovery volume is going up.

The constraint moves to the human work after discovery: validating each finding, deciding whether it is reachable in your deployment rather than in principle, assessing blast radius, and sequencing remediation against a committed roadmap. That is senior judgment and it compresses badly. The practical consequence for a hiring plan is that engineers who can triage and prioritise security findings at volume become more valuable, and engineers whose main contribution was finding issues one at a time become relatively less so. Write the specification for the first group. The adjacent skill set is covered in hiring AI security engineers in Singapore.

Not sure whether your spec tests for detection or just prevention?

We review security engineering job specifications and technical screens for Singapore employers, and say plainly which parts of the role nobody currently owns.

Discutons-en — talk to our Singapore team
Where the Bottleneck MovedDiscovery got cheap. Everything after it did not.DiscoveryModel scans atvolumecheap now→ReachabilityTrue in YOURdeployment?human→Blast radiusWhat data, whose,how much?human→SequencingAgainst a roadmapalready committedthe real bottleneckEpic’s answer to the sequencing problem: stop the roadmap for ~6 weeks.Most organisations have no mechanism to do this, and no one with authority to invoke it.Hiring consequenceValue rises for engineers who can triage and prioritise findings at volume.Value falls for those whose contribution was finding issues one at a time.

Our expert take #3

One caution, because the obvious conclusion from this story is “get a model to scan our code” and that conclusion will waste a quarter if taken naively. Epic had restricted access under a structured programme, with the engineering depth to act on what came back and a chief executive willing to freeze the roadmap. Strip any of those three away and you do not get Epic’s outcome — you get a backlog of unvalidated findings that nobody owns, which is strictly worse than not having scanned, because it is now documented that you knew. Before commissioning any AI-assisted security review, I would want two things in place: a named owner for triage with the authority to stop other work, and an agreed definition of what makes a finding real in your deployment. Without those, the scan produces liability rather than security. Capability first, then discovery.

What I Would Do This Month

Four steps, none of which requires a budget approval, and in this order:

  1. List the vendor platforms holding personal data and name a human owner for the configuration of each. Where there is no owner, that is the finding.
  2. Pick your single most sensitive read path and establish, from data rather than assumption, what gets logged, how long it is retained, and who could alter the log.
  3. Write down who can stop the roadmap. If the answer is nobody, you have discovered why remediation always gets squeezed into the margins.
  4. Add one detection question to your security screen. It costs nothing and it changes which candidates look strong.

None of this is reactive to Epic specifically. It is the work the story makes legible, and it was overdue before 2 October. For the broader pattern of vendor-platform exposure driving hiring here, our write-up of the Citrix NetScaler zero-days added to the CISA KEV catalogue is the closest recent parallel.

You cannot staff detection with a prevention job spec

We place security and platform engineers with Singapore employers, and help leaders work out which part of this capability to hire for first.

Discutons-en — brief our Singapore team

Frequently Asked Questions

What exactly did Epic announce on 2 October 2026?

Epic paused most new product development for roughly six weeks to remediate security vulnerabilities in MyChart, the patient portal that holds more than 320 million patient records across United States healthcare providers. The flaws were surfaced by Mythos, Anthropic’s frontier cybersecurity model, through Project Glasswing, a programme that gives selected partners restricted access to the model to find and fix software vulnerabilities. Epic chief security officer Stirling Martin told The New York Times that certain customer configurations of MyChart could allow outsiders to access patient records without the access being recorded in any intrusion log. Founder and chief executive Judy Faulkner put the pause at about six weeks. Reporting notes that the model did not establish whether records could also be altered without detection, and that no breach has been confirmed. The story was reported by TechCrunch on 2 October 2026 and corroborated by Becker’s Hospital Review among others.

Why does a configuration bug matter more than a code bug for customers?

Because a code bug is the vendor’s problem and a configuration bug is partly yours. When the vulnerability lives in shipped code, the vendor patches it and you upgrade. When the vulnerability only appears in certain customer configurations, the exposure depends on choices made during your own deployment, often years ago, frequently by people who have since left, and almost never written down with the reasoning attached. That changes what you need from your team. A patch you can schedule. A configuration audit requires somebody who can reconstruct why your instance was set up the way it was, decide which of those settings are still justified, and do that across every vendor platform you run rather than just the one currently in the news. Most organisations have no owner for that work at all, because it does not belong cleanly to engineering, to IT or to the vendor relationship. It is the gap this story exposes, and it is not specific to healthcare.

What does the missing-log detail actually tell a hiring manager?

It tells you that the most expensive part of this incident is epistemic rather than technical. Access that leaves no log entry means that after you fix the configuration you still cannot answer the only question anyone will ask, which is whether it was ever exploited. There is no dataset to go back to. For a Singapore employer this should redirect hiring attention from prevention toward detection. Most security job specifications I review are written almost entirely around prevention: secure coding, reviews, scanning, hardening. Detection engineering, the discipline of making sure that sensitive actions are observable and that the observations are retained and queryable, is usually one line in a longer list or absent entirely. The practical interview question is simple and almost nobody asks it. Pick the most sensitive read path in your system and ask the candidate what evidence would exist tomorrow if it were abused tonight. Strong candidates will ask about retention periods and log integrity before they answer.

Should Singapore employers now expect AI models to find bugs in their own stack?

Expect it, plan the triage capacity for it, and do not assume it reduces your headcount need. The Epic case is an early instance of a pattern that is clearly arriving: a frontier model running against a large codebase, under a structured access programme, producing findings that conventional review and years of penetration testing had not surfaced. The bottleneck in that workflow is not discovery any more. It is the human judgment required to validate each finding, decide whether it is reachable in your actual deployment, assess blast radius, and sequence the remediation against everything else the roadmap committed to. That is senior work and it does not compress well. The honest read for a hiring plan is that AI-assisted discovery raises the value of engineers who can triage and prioritise security findings at volume, and lowers the relative value of engineers whose contribution was mainly finding issues one at a time. Write the specification for the first group.

Sebastian

Sebastian

Mobile App & Hiring Expert at HireDeveloper.sg. Reviews engineering job specifications and technical screens for Singapore platform and security teams.