Epic Paused Development to Address Security Flaws
The company halted product work for six weeks to remediate vulnerabilities identified in its MyChart software.
Updated on Oct. 2, 2026 in Cybersecurity

Live Poll
Do you trust that medical record software companies adequately protect your sensitive health data?
Epic has paused the majority of its product development for six weeks after the Mythos cybersecurity model identified security flaws. These vulnerabilities in MyChart configurations could potentially allow unauthorized access to patient records.
Why it matters
The preemptive measure aims to safeguard sensitive health data across systems that maintain over 320 million patient records. This decision reflects an industry-wide prioritization of data protection following recent high-profile cybersecurity incidents.
MyChart software currently manages more than 320 million patient records across its network. The development halt is scheduled to last for a duration of six weeks to facilitate the remediation of security gaps.
The players
Epic
Epic is a major provider of electronic health record software used by healthcare systems.
Judy Faulkner
Judy Faulkner is the CEO of Epic.
Change Healthcare
Change Healthcare is a health technology firm that suffered a major ransomware attack in 2024.
DentaQuest
DentaQuest is a dental benefits provider that experienced a significant data breach in 2026.
The details
The Mythos cybersecurity model uncovered flaws that could enable unauthorized access to patient information, prompting the company to pause development work. This move is designed to fortify product security and prevent potential data breaches similar to past incidents at other healthcare entities.
Timeline
The Change Healthcare ransomware attack occurred in 2024.
CEO Judy Faulkner discussed the pause in September 2026.
Epic confirmed the product development pause in October 2026.
The development pause is scheduled to last for the next six weeks.
The Tech Race
This defensive pivot follows the industry-wide security scrutiny sparked by the 2024 Change Healthcare ransomware attack. Epic is shifting from a rapid release model to a security-first posture to prevent the systemic compromises seen in previous major healthcare breaches.
The pause in product development could lead to temporary delays in the rollout of new software features or updates for clinical users. Patients and providers should expect ongoing security maintenance efforts that aim to protect the privacy of digital medical records.
The takeaway
Healthcare providers should utilize this pause to audit their own internal security configurations and compliance protocols. Prioritizing robust cybersecurity frameworks is essential for maintaining the long-term integrity of patient-centered digital health platforms.
Further reading
For broader trends in health sector data safety, visit the Cybersecurity section.
Live Poll
Do you trust that medical record software companies adequately protect your sensitive health data?










