Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitchesEpic reportedly paused most product development for about six weeks while addressing security flaws that could put patient data at risk. But Epic’s public statement on September 23, 2026, said its development roadmap had not changed and named several initiatives still progressing. The available accounts do not explain how those descriptions fit together, and they do not establish that anyone accessed or altered patient records.
What was reported about Epic’s development pause
On October 2, 2026, TechCrunch reported—citing reporting by Modern Healthcare and The Times—that Epic founder and CEO Judy Faulkner said the pause would likely last six weeks as the company worked to safeguard its products. TechCrunch described the pause as covering most product development. Becker’s Hospital Review separately reported that Faulkner had described a pause involving hundreds of projects and that security work could continue for about six more weeks. That is corroborating coverage, not a separate technical disclosure.
TechCrunch linked the security work to the deployment of Anthropic’s cybersecurity model Mythos, which reportedly uncovered flaws that could allow access to patient data. Epic has not publicly described the specific bugs in the reporting reviewed here. The reported risk is not proof that attackers exploited a flaw or that patient information was exposed.
How Epic’s statement differs from the pause reports
In a September 23, 2026, report, IBMadison quoted an Epic spokesperson saying: “Our development roadmap hasn’t changed since we presented it at our August 2026 Users Group Meeting.” The spokesperson also said: “We’re participating in Project Glasswing (for critical software security) and using AI tools to stay ahead of cybersecurity threats that are growing across all industries.”
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →#1 Best Overall
Epic said it was continuing progress in expanded AI capabilities, Agent Factory, EpicOps, and interoperability work intended to speed up prior authorization. These statements address the roadmap and named initiatives; the later TechCrunch report describes a pause in most product development. The sources do not fully reconcile whether some work stopped, slowed, or continued under the unchanged roadmap. It would be inaccurate to present the coverage as proof of a companywide halt confirmed by Epic.
| Account | Date and attribution | What it describes |
|---|---|---|
| Most product development paused for likely six weeks | October 2, 2026; TechCrunch, citing Modern Healthcare and The Times | Reported scope and expected duration of a development pause while Epic worked on product security. |
| Pause involving hundreds of projects; security work for about six more weeks | Becker’s Hospital Review; date not stated in the reviewed material | Corroborating secondary coverage of the pause and duration. |
| Development roadmap unchanged; several initiatives advancing | September 23, 2026; Epic spokesperson quoted by IBMadison | Epic’s description of its roadmap and ongoing work, including security efforts. |
What the MyChart security concern does—and does not—show
TechCrunch attributed to Epic chief security officer Stirling Martin, speaking to The Times, a concern that some customer MyChart configurations could allow outsiders to access patient records without the activity being recorded in software logs. Martin did not say whether a bug could be used to alter records without detection, according to TechCrunch.
This is a reported concern about possible exposure and logging, not confirmation that records were accessed, stolen, or changed. The reviewed reporting does not identify affected customer configurations, disclose the vulnerability details, establish exploitation, or give a definitive remediation status.
MyChart is Epic’s patient portal. Epic says people whose healthcare provider uses Epic likely have secure online access through MyChart, and describes a share code that lets a patient give another person temporary access to health information. That general feature does not mean all MyChart installations or patients are affected by the reported concern.
What patients, researchers, and Epic customers should do
- Patients: Contact the healthcare organization where you receive care if you have a concern about your account or records. Epic says each organization maintains and configures its own Epic instance.
- Researchers and others reporting a vulnerability: Contact Epic’s security team through its vulnerability reporting guidance.
- Epic community members: Contact your technical services representative or technical coordinator.
Epic says it does not offer compensation for vulnerability reports. Its patient-facing information about MyChart is available at Epic’s MyChart page.
Quick Recap
Best Value
What remains unknown
- The technical details of the reported flaws and which customer configurations, if any, are affected.
- Whether an attacker exploited any flaw or accessed patient data.
- Whether records were altered or whether any such change could go undetected.
- The exact status and completion date of Epic’s remediation work.
- How the reported pause in active development relates to Epic’s statement that its roadmap was unchanged.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

