Epic Systems, the electronic health records company behind the MyChart patient portal, has paused most of its technology development to make sure its systems are secure against cyberattacks, founder and CEO Judy Faulkner said Tuesday at Modern Healthcare's Leadership Summit. She said the pause covers hundreds of projects and that the security work is expected to last about six more weeks.
A day later, the company offered a different emphasis. "Our development roadmap hasn't changed since we presented it at our August 2026 Users Group Meeting," an Epic spokesperson said in a statement to local media and other outlets.
Neither Faulkner nor Epic has said the company suffered a breach or attack. The remarks describe preventive work, but Epic software runs records systems at many of the country's largest hospitals and clinics. Any slowdown in updates or burst of security fixes can ripple into the daily routines of patients and health care workers.
Two Messages From One Company
According to Modern Healthcare's report, Faulkner said product development would continue at a slower pace during the security push, and she suspected work was still moving in some areas. Epic's spokesperson told Fierce Healthcare that progress continues on expanded AI features, the company's Agent Factory platform, its EpicOps business software, and interoperability work meant to speed up prior authorization.
Both accounts can hold at once if the security effort slows some projects without moving promised delivery dates. What remains unknown is which projects were paused, how many staff members were reassigned, and whether hospitals will see delays in features they were expecting.
The security focus predates this week. At its August meeting, Epic said it had pointed advanced AI models at its own code to look for weaknesses, Fierce Healthcare reported. "We're participating in Project Glasswing and using AI tools to stay ahead of cybersecurity threats that are growing across all industries," the spokesperson said.
Project Glasswing is an initiative led by AI company Anthropic in which partner organizations use an unreleased AI model to find software flaws and strengthen defenses. Anthropic expanded the project in June to include organizations from sectors such as health care, according to Fierce Healthcare. Finding and fixing weaknesses before attackers do is preventive work, not a response to a known incident.
Why Hospital Cybersecurity Matters to Patients
The stakes for patients are concrete. When a health system's records go offline, clinicians may fall back on paper charts, ambulances can be diverted, and patients may struggle to refill prescriptions or view test results. The 2024 ransomware attack on Ascension, for example, forced some of its hospitals to divert ambulances and switch to paper records for weeks.
Breaches are common. The Department of Health and Human Services publicly lists health data breaches affecting 500 or more people, and hacking and IT incidents make up a large share of recent reports. Smaller and rural hospitals often have fewer IT staff members and can take longer to recover from an attack.
For hospitals, the trade-off is workload. Each urgent security update must be tested and installed, sometimes during planned downtime that can briefly limit portal access, scheduling, or messaging.
Patient Portals and the Weeks Ahead
Most patients will not need to do anything differently, but a few habits help during any period of heavy security updates. Watch for notices from your hospital or clinic about scheduled portal maintenance. Keep a current list of your medications, allergies, and upcoming appointments outside the portal, and turn on two-step verification for MyChart if your health system offers it.
Be cautious with emails or texts that mention an Epic security update and ask you to click a link or enter a password. Your health system manages your account, so log in through the organization's official website or app rather than a link in a message. If you need urgent care during an outage, go to an emergency department or call 911 instead of waiting for the portal to return.
People managing complex care, such as cancer treatment, dialysis, or a high-risk pregnancy, may want to confirm how to reach their care team by phone if the portal is briefly unavailable. Caregivers who manage a parent's or child's MyChart account through proxy access should do the same.
Several questions remain open. Epic has not released a list of affected projects, and no hospital has publicly reported new delays tied to the pause. If Faulkner's six-week estimate holds, the security work would wrap up around early November. MedicalDaily will follow whether health systems report delays, new security updates, or changes to promised tools.
Key Questions Answered
Did Epic suffer a cyberattack? No attack or breach has been reported. Faulkner described the pause as preventive work to make sure Epic's systems are not vulnerable.
How long will the security work last? Faulkner said it is expected to take about six more weeks, according to Modern Healthcare's report of her September 22 remarks.
Is Epic delaying new products? Faulkner said most development was paused and would continue at a slower pace. An Epic spokesperson said the company's roadmap has not changed since its August user meeting.
Will MyChart stop working? There is no indication of a MyChart shutdown. Some hospitals may schedule brief maintenance to install security updates, so watch for notices from your provider.
How can patients protect their accounts? Use a strong, unique password, turn on two-step verification if available, and log in only through your health system's official website or app.
Why does health care cybersecurity matter to patients? Attacks on hospitals have forced ambulance diversions, paper-based care, and delays in prescriptions and test results.
Published by Medicaldaily.com