The short answer
Epic, the largest US electronic health record vendor, has frozen most new product work for roughly six weeks to fix security flaws, after AI scanning of its code exposed weaknesses including MyChart setups that could allow unlogged access to patient records. No breach has been confirmed, and Epic has not published technical details. Hospitals and the vendors that integrate with Epic should prepare for more urgent patches than usual.
For anyone building in HealthTech, this is less about one vendor and more about a new pace of security work. When the platform at the center of US clinical data stops shipping features to fix bugs, every app, integration and data pipeline connected to it inherits the patch schedule, the testing load and the questions about what the logs did not record.
What did Epic announce?
Speaking at Modern Healthcare's Leadership Summit on 22 September 2026, Epic founder and CEO Judy Faulkner said the company was pausing most technology development to concentrate on securing its systems. She put the remaining work at about six weeks, which points to early November if the timeline holds, and said product development would then continue at a slower pace.
Epic's public line is that the product plan still stands. A spokesperson told Fierce Healthcare that the development roadmap had not changed since it was presented at the company's Users Group Meeting in August, and that Epic was “participating in Project Glasswing and using AI tools to stay ahead of cybersecurity threats”. On 2 October TechCrunch added the detail that matters most to hospitals: what kind of flaw had been found.
What is wrong with MyChart?
MyChart is Epic's patient portal, the app patients use to see results, message clinicians and pay bills. According to TechCrunch, Epic chief security officer Stirling Martin told The New York Times that some customer configurations of MyChart could allow outsiders to access patient records without the intrusion being recorded in the software's logs. Martin said it was not yet clear whether the flaws could also be used to change records without detection.
Epic has not disclosed the specific bugs, and there is no public indication that they were exploited. The phrase “customer configurations” is important. Each health system runs and configures its own Epic environment, and Epic says it does not access customers' medical data. Fixing the flaws is therefore a shared job: Epic ships the patches, and each provider has to apply them and check its own setup.
The missing log trail is what makes this serious. Under the HIPAA Security Rule, covered entities must record and examine activity in systems holding electronic health information. If the application log can miss an intrusion, the usual way of proving that nothing happened stops working.
Why is AI finding bugs that people missed?
Epic joined Anthropic's Project Glasswing, an initiative that gives selected organizations access to the unreleased Claude Mythos model to find vulnerabilities in critical software. Anthropic widened the group in June to include healthcare. At the August user group meeting, Martin said Epic's codebase runs to several hundred million lines and that AI models “can easily make observations that our expert developers can't see”, in particular by chaining unrelated issues into a new attack path.
That is the larger shift. Large, long-lived codebases contain bugs that only become exploitable in combination, and those are exactly the ones human review tends to miss. Once a vendor has a tool that finds them quickly, the backlog of fixes appears all at once. Epic chose to stop feature work and clear it. Other vendors with similar tools will face the same choice, and attackers with comparable models will be looking at the same code.
What it means for US & EU software teams
Your Epic integration now has a faster patch cycle. Digital health apps, SMART on FHIR tools, patient engagement products and analytics pipelines that talk to Epic will see more urgent updates over the next weeks. Each one can change behavior at an API, an authentication flow or a MyChart extension point. Teams that cannot rerun integration tests within days will end up either delaying security fixes for their hospital clients or shipping blind.
Roadmaps that depend on Epic may slip. Epic says its roadmap is unchanged, but Faulkner also said development will continue at a slower pace after the pause. If your launch depends on a new Epic API, an App Market listing or a joint pilot with a health system's Epic team, plan for delay. Hospital IT teams busy with urgent patches will have less time for new integrations.
Do not rely on one log. The main engineering lesson is that audit evidence should not live in only one layer. If you build on top of an EHR, record access at your own API gateway, identity provider and data store as well, so there is an independent trail if the platform log misses something. That is also what a solid HIPAA-compliant architecture should already require, and it helps with SOC 2 and, for EU deployments, GDPR accountability.
AI-assisted security review is no longer optional. If AI models can find chained flaws in Epic's code, they can find them in yours, and so can attackers. Running AI-assisted code and configuration review on your own health data systems, before someone else does, is now a reasonable expectation from hospital security teams and auditors.
What to do right now
- Map your Epic dependencies. List every integration with Epic and MyChart: FHIR APIs, SMART on FHIR launches, interface engines, embedded MyChart features and data exports.
- Get integration tests ready to run fast. Make sure you can regression-test each integration against a patched Epic environment within days, not weeks.
- Talk to your hospital clients. Ask their Epic teams about patch windows and change freezes so your releases do not collide with urgent security updates.
- Add independent access logging. Record who accessed patient data at your gateway, identity and database layers, and keep those logs long enough to reconstruct events later.
- Revisit your HIPAA risk analysis. Add unlogged platform access as a scenario, and check that your incident response plan and business associate agreements cover how you would investigate it.
- Re-plan dependent launches. Assume features that need new Epic capabilities will arrive later than promised, and tell stakeholders now.
This is not legal advice, and the details of the MyChart flaws are still not public. The direction is clear: the biggest health IT vendor in the US has decided that fixing security debt comes before new features, and anyone building on top of it should plan the same way.
Frequently asked questions
Why did Epic pause product development?
Epic CEO Judy Faulkner said on 22 September 2026 that the company was pausing most technology development to focus on security, after AI models Epic pointed at its own code surfaced vulnerabilities. She said the security work would take about six more weeks, after which product development would resume at a slower pace.
What is wrong with MyChart?
Epic has not published technical details. Its chief security officer, Stirling Martin, told The New York Times that some customer configurations of MyChart could let outsiders access patient records without the intrusion being recorded in the software's logs. He said it was not yet clear whether the flaws could also let someone alter records without detection.
Were patient records actually breached?
No breach has been confirmed. TechCrunch reported there is no indication the flaws were exploited. The problem is that a flaw which leaves no trace in application logs makes it harder to prove either way, so providers should check their own logging rather than rely on the absence of alerts.
What role did AI play?
Epic is a participant in Anthropic's Project Glasswing and has used the unreleased Claude Mythos model to scan its codebase. Martin said the models spot issues expert developers miss by chaining unrelated weaknesses into new attack paths, and warned customers to expect a higher-than-usual number of urgent security fixes.
What should HealthTech teams that integrate with Epic do?
Plan for more frequent urgent Epic updates, keep regression tests for MyChart, FHIR and SMART on FHIR integrations ready to run on short notice, add logging at your own API gateway and identity layer so access is recorded even if the application log misses it, and check your HIPAA risk analysis and incident response plan against the possibility of unlogged access.
Sources
TechCrunch — Medical records giant Epic pauses product development to fix security bugs that risk patients' data, 2 October 2026
Fierce Healthcare — Epic shifts focus to cybersecurity while AI, interoperability agenda still on track, company says, 23 September 2026 (includes Epic statement)
Modern Healthcare — Epic Systems pauses product development to focus on cybersecurity
The New York Times — interview with Epic CSO Stirling Martin, as reported by TechCrunch