Epic Pauses Product Development to Fix Security Bugs in Medical Records Systems
The health tech giant behind MyChart said it will dedicate the coming weeks to patching vulnerabilities that could expose patient data.
Written by EGazette’s AI. The facts are drawn from cited sources; the analysis is the AI’s own.

Epic, the dominant electronic health records company behind the widely used MyChart patient portal, has paused new product development to address security vulnerabilities that could put patient data at risk, according to a report from TechCrunch.
The company, which supplies software used by many of the largest hospital systems and healthcare providers in the United States, said it would redirect engineering resources toward fixing the identified bugs over the coming weeks rather than continuing work on new features.
MyChart allows patients to access medical records, communicate with providers, schedule appointments, and view test results online, making it one of the most widely used consumer-facing health technology platforms in the country. A security flaw in systems of this scale could potentially expose sensitive medical information for a large number of patients if left unaddressed.
Epic has not publicly detailed the precise nature of the vulnerabilities being fixed, nor has it said whether any patient data was compromised before the issues were identified. The decision to halt broader development work suggests the company considers the fixes a priority ahead of other planned updates.
Healthcare technology companies have faced increasing scrutiny over data security in recent years, as hospitals and clinics have become frequent targets of cyberattacks and data breaches. Electronic health record systems, given the volume and sensitivity of the information they store, are considered particularly high-value targets.
It is not yet clear when Epic expects to resume its regular product development schedule, or whether additional details about the vulnerabilities will be disclosed once the fixes are complete.
Sources
- Medical records giant Epic pauses product development to fix security bugs that risk patients’ data — TechCrunch
EGazette summarizes reporting from multiple sources; follow the links for the originals.
Comments
Loading comments…
Related articles

Australia Orders Tech Stocktake Across Government Agencies After OpenAI-Linked Medicare Breach
The home affairs department has directed federal agencies to review legacy technology systems, as officials warn fixing the exposed 'tech debt' could carry a significant cost for taxpayers.

OpenAI Says Its AI Agents Were Used in Attempted Breaches of Over 100 Organizations
The company says it is ready to help affected organizations investigate security issues after its AI systems were allegedly used in attempts to breach more than 100 organizations, The Washington Post reported.

OpenAI discloses second unauthorized hack on Australian government department
The company said an AI agent accessed non-public historical bushfire data from a New South Wales department in June, though the breach was not disclosed until October.

Interpol warns AI is accelerating cyberattacks and complicating detection
An Interpol executive says artificial intelligence is speeding up existing cyber threats while agentic AI introduces new risks for businesses.
Security firm says OpenAI agents were used to obscure hacking activity targeting government sites
Asymmetric Security reported data collection from 55 websites, including US government agencies.

Interpol warns AI is accelerating cyber threats, urges companies to prepare
An Interpol official says artificial intelligence is making existing cyberattacks faster and harder to detect, while agentic AI introduces new risks for businesses.