Epic reportedly paused most product development for about six weeks while it worked to address security flaws that could put patient data at risk. That account, published by TechCrunch on October 2, 2026, does not match neatly with Epic’s September 23 statement that its development roadmap had not changed. The reports do not establish a companywide halt, a confirmed data breach, or that patient records were accessed.
What Epic’s reported pause means—and what it doesn’t
TechCrunch reported on October 2, 2026, citing Modern Healthcare and The Times, that Epic founder and CEO Judy Faulkner said the pause would likely last six weeks as the company worked to safeguard its products. TechCrunch described the move as a pause to most product development. Becker’s Hospital Review separately reported a pause involving hundreds of projects and said security work could continue for about six more weeks; it is corroborating coverage, not an independent technical account. TechCrunch and Becker’s Hospital Review provide the reported accounts.
These reports describe a pause in active development work, not necessarily a change to Epic’s longer-term roadmap. On September 23, an Epic spokesperson said the roadmap had not changed since the company’s August 2026 Users Group Meeting. The available accounts do not explain how that roadmap statement relates to the reported pause, so neither should be treated as proof that every project stopped or that no work was affected. IBMadison reported Epic’s statement.
What security concern has been reported
TechCrunch said the security work followed deployment of Anthropic’s cybersecurity model Mythos, which reportedly uncovered flaws that could allow access to patient data. Epic had not publicly disclosed the nature of the bugs in the reporting reviewed.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstall#1 Best Overall
TechCrunch also attributed to Epic chief security officer Stirling Martin, speaking to The Times, a concern that certain customer MyChart configurations could allow outsiders to access patient records without the access appearing in software logs. Martin did not say whether a flaw could enable undetected changes to records. These are reported risks, not evidence that anyone exploited a flaw: the accounts do not establish that records were accessed, altered, or stolen.
Epic’s roadmap statement and ongoing work
As reported by IBMadison on September 23, an Epic spokesperson said: “Our development roadmap hasn’t changed since we presented it at our August 2026 Users Group Meeting.” The spokesperson also said: “We’re participating in Project Glasswing (for critical software security) and using AI tools to stay ahead of cybersecurity threats that are growing across all industries.” These quotes are attributed through IBMadison’s report, rather than to a direct Epic-hosted transcript.
Epic also said it was continuing progress on expanded AI capabilities, Agent Factory, EpicOps, and interoperability work intended to speed up prior authorization. That list indicates the company said some initiatives were advancing; it does not resolve which other development projects were paused.
How to understand the MyChart reference
MyChart is the patient-facing portal used by healthcare organizations that run Epic software. Epic’s patient information says people whose healthcare provider uses Epic likely have secure online access through MyChart. It also describes a share code patients can generate to give another person temporary access to health information. This context explains the product named in the reporting; it does not show that all MyChart installations, healthcare organizations, or patients are affected. Epic’s patient information describes MyChart and sharing.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errorsWhat patients, researchers, and Epic community members should do
Epic’s vulnerability reporting guidance directs people to different channels depending on their relationship to the software:
- Patients: Contact the healthcare organization where you receive care with concerns about your account or records. Each organization maintains and configures its own Epic instance.
- Security researchers and others: Contact Epic’s security team directly to report a suspected vulnerability.
- Epic community members: Contact your technical services representative or technical coordinator.
Epic says it does not offer compensation for vulnerability reports. Its guidance is a reporting route, not confirmation that a particular vulnerability affects a patient or organization. Epic’s security guidance provides the reporting details.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What remains unknown
The reporting reviewed does not identify the specific vulnerabilities, the customer configurations that may be affected, whether attackers exploited any flaw, whether patient information was actually accessed, or the exact remediation status. Until those details are made public, the most accurate description is a reported security risk and reported development pause—not a confirmed breach or confirmed disclosure of patient records.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




