Epic Pauses Development to Fix Patient Data Security

Most software companies fix vulnerabilities while continuing to ship features. Epic is taking a much more unusual approach: it has paused most product development.
The healthcare software giant behind MyChart is temporarily redirecting engineering resources toward security after AI-assisted testing uncovered flaws that could put patient data at risk.
Epic CEO Judy Faulkner said the pause could last around six weeks while the company focuses on safeguarding its products.
The decision is notable for two reasons.
Epic's software sits underneath enormous parts of the U.S. healthcare system.
And the vulnerabilities were surfaced using advanced AI cybersecurity tools.
MyChart sits close to extraordinarily sensitive data
Epic's MyChart software gives patients access to information held by hospitals and healthcare providers.
TechCrunch reports that Epic software is associated with more than 320 million patient records across U.S. hospitals and doctors' offices.
Epic says it does not itself own or centrally hold all of that customer medical information.
Healthcare providers remain responsible for their own patient data.
But vulnerabilities in widely deployed software can create systemic risk.
A single flaw can potentially affect many organizations using similar configurations.
Some configurations reportedly lacked proper logging
Epic has not publicly disclosed full technical details of the vulnerabilities.
But its security chief told The New York Times, according to TechCrunch, that certain MyChart configurations could potentially allow outsiders to access patient information without the event appearing correctly in intrusion logs.
That is particularly serious.
Security teams depend on logs to investigate suspicious behavior.
A system that allows data access without leaving the expected audit trail does more than create a vulnerability.
It makes detecting exploitation harder.
AI found the problem before attackers did — as far as we know
The vulnerabilities came to light after Epic deployed Anthropic's advanced cybersecurity model Mythos for security testing.
That gives the incident an unusual positive side.
AI is often discussed as a tool attackers can use to find vulnerabilities faster.
Here, a defender used AI to discover weaknesses and prioritize remediation first.
The incident therefore demonstrates both sides of the AI-security race.
More capable models make vulnerability discovery easier.
That helps attackers.
It also helps defenders.
Pausing development is a powerful signal
Software teams usually live under constant pressure to ship.
New features.
Customer requests.
Roadmap commitments.
Bug fixes.
Stopping most of that work carries real business cost.
Epic's decision suggests it views the identified risks as serious enough to justify that cost.
That is unusual in enterprise software.
It may also become less unusual as autonomous security systems expose vulnerabilities faster than companies can patch them.
Healthcare makes the consequences worse
Medical records contain some of the most sensitive information an organization can hold.
Diagnoses.
Medications.
Procedures.
Insurance information.
Personal identifiers.
Unlike a stolen password, a person's medical history cannot simply be reset.
That makes health systems particularly attractive to extortion groups.
Attackers know hospitals may face extraordinary pressure to prevent stolen health records from being published.
Healthcare security is already under strain
The industry has experienced repeated large-scale breaches.
TechCrunch notes that the 2024 Change Healthcare attack affected data associated with more than 192 million people, while several other significant healthcare and technology breaches have occurred in 2026.
This broader context matters.
Epic is not responding to a hypothetical market where patient-data attacks are rare.
Healthcare organizations are already major targets.
AI may force companies to rethink release cycles
There is a broader software-development implication.
If AI systems can inspect code and configurations much faster than traditional human teams, security reviews can become continuous.
That means vulnerabilities may surface faster.
But remediation teams still have limited human capacity.
Companies may increasingly face a difficult choice:
keep shipping,
or stop and fix the growing backlog of newly discoverable security issues.
Epic chose the second option.
What happens next?
Epic still has to complete remediation and help customers understand whether any configurations need urgent changes.
There is currently no public evidence in the reporting that the vulnerabilities were exploited broadly before discovery.
That distinction is important.
But the company's response sends a clear message.
AI security tools are becoming capable enough to force major software vendors to reconsider how they balance product velocity against protection.
The AI era may create more bugs faster.
It may also find old bugs faster.
For software handling hundreds of millions of patient records, that means security can no longer sit behind the product roadmap.
Sometimes the roadmap has to stop for security.
