Epic Paused Product Development for Security Audit

The company halted feature work for six weeks to address potential access vulnerabilities in its MyChart platform.

Updated on Oct. 2, 2026 in Cybersecurity

Bold vector editorial illustration of a secure steel-alloy latch mechanism, representing software structural integrity and security auditing.
Epic has halted most product development for six weeks to perform a security audit and refactor code within its MyChart platform. AI Illustration. Upload story photo >

Live Poll

Do you trust that medical record software companies adequately protect your sensitive health data?

Epic has initiated a six-week pause on most product development to address identified security vulnerabilities within its MyChart software. The flaws potentially allow unauthorized access to patient records, a critical concern for the platform that maintains over 320 million records.

Why it matters

This preemptive halt follows high-profile healthcare data breaches, reflecting an industry-wide shift toward hardening clinical software infrastructure. By prioritizing remediation, Epic aims to safeguard the integrity of patient data against potential cyberattacks.

The Mythos cybersecurity model identified flaws in specific MyChart configurations. These vulnerabilities potentially permit unauthorized access to patient data across a system supporting 320 million records.

The players

Epic

A dominant provider of electronic health record systems that manages patient data and clinical workflows for major hospitals in the United States.

Judy Faulkner

The founder and CEO of Epic who manages the company's strategic direction and software development roadmap.

The details

The Mythos model, a specialized framework for assessing cybersecurity risks in complex software, flagged configurations in MyChart that could be exploited. Remediation requires an engineering-wide freeze to audit and refactor the affected code paths. This process ensures that security patches are integrated directly into the software architecture, rather than applied as temporary overlays, to prevent unauthorized external access.

Timeline

  1. 2024: Change Healthcare suffered a major ransomware attack.

  2. September 2026: CEO Judy Faulkner discussed the necessity of the development pause.

  3. October 2026: Epic confirmed the initiation of the product development pause.

  4. Next six weeks: Expected duration of the current development halt.

The Tech Race

This development follows a pattern set by the 2024 Change Healthcare ransomware attack, where providers are increasingly forced to prioritize security over feature velocity. The move highlights an intense industry-wide race to harden critical infrastructure against sophisticated cyber threats.

Clinical workflows relying on MyChart may experience delays in feature updates or new deployments over the next six weeks. Patients and healthcare providers should monitor internal system announcements for potential maintenance windows or service adjustments.

The takeaway

Epic is shifting its focus to prioritize platform security following the identification of systemic configuration flaws. Stakeholders should track the conclusion of the six-week window in November 2026 to see if the company resumes its standard software release cadence.

What happens next

The product development pause is expected to conclude following the six-week remediation period ending in mid-November 2026.

Further reading

For broader context on current software vulnerabilities in health infrastructure, visit Cybersecurity.

Live Poll

Do you trust that medical record software companies adequately protect your sensitive health data?