Epic’s cybersecurity push: 6 things to know

Advertisement

Epic has put cybersecurity increasingly at the center of its strategy in 2026, from deploying advanced AI against its own software to pushing faster patching and scrutinizing access to patient records through national data exchanges.

The focus intensified in recent months after AI-assisted testing uncovered potential security weaknesses and CEO Judy Faulkner disclosed that the company had paused most technology development while hundreds of projects underwent heightened cybersecurity review. Epic has said its broader technology roadmap remains unchanged.

Here are six things to know about Epic’s cybersecurity push in 2026, as reported by Becker’s:

1. Epic shifted significant attention toward cybersecurity.

Ms. Faulkner said Sept. 22 at Modern Healthcare’s Leadership Summit that Epic had paused most technology development as the company worked to ensure its systems were secure and not vulnerable to cyberattacks. The work involved hundreds of projects and was expected at the time to continue for about six more weeks. Ms. Faulkner also said she suspected development was continuing in some areas, and Modern Healthcare reported that product development would continue at a slower pace.

Epic subsequently told Becker’s that its development roadmap had not changed since the company presented it at its August Users Group Meeting. The company said work was continuing on initiatives including expanded AI capabilities, Agent Factory, EpicOps and interoperability tools to speed prior authorization.

2. Epic is using Anthropic’s restricted cybersecurity AI against its own code.

Epic publicly confirmed at its August Users Group Meeting that it is participating in Anthropic’s Project Glasswing and is a heavy user of Claude Mythos, an unreleased AI model with advanced cybersecurity capabilities.

Epic Chief Security Officer Stirling Martin said the company has pointed the technology at its codebase, which spans several hundred million lines, and that the AI surfaced potential vulnerabilities its own expert developers had missed. He said newer models have become increasingly capable of linking otherwise unrelated weaknesses into potential attack paths.

3. The testing found flaws that could allow patient-record access without appearing in audit trails.

Epic is patching security flaws found after testing its software with Mythos. Certain software configurations could potentially allow someone to view sensitive patient records without that access appearing in a digital audit trail, Mr. Martin told The New York Times.

Mythos did not determine whether an attacker could alter records, though Mr. Martin said the testing raised that possibility. He said whether records could be changed would depend on other parts of the technology and would not necessarily involve Epic software.

4. Epic is telling health systems to prepare for faster patching.

The AI-assisted security work could change the cadence at which Epic customers receive fixes.

Mr. Martin told UGM attendees to expect a higher-than-usual number of urgent security fixes as Epic continues testing its software. He also said the traditional goal of patching within 30 days is no longer sufficient.

Sha Edathumparampil, chief digital and information officer of Coral Gables, Fla.-based Baptist Health South Florida, told Becker’s that Epic had begun giving hospitals that host their own Epic systems specific guidance to help accelerate their patching schedules.

5. Epic has taken action over questionable access to records exchanged outside its platform.

Epic’s security focus has also extended to how patient records are accessed through nationwide interoperability networks.

On Jan. 13, Epic, Portland, Ore.-based OCHIN, Richmond, Ind.-based Reid Health, Livonia, Mich.-based Trinity Health and Worcester, Mass.-based UMass Memorial Health filed a federal lawsuit. The suit accuses Health Gorilla and other defendants of improperly obtaining and monetizing nearly 300,000 patient records by allegedly claiming the information was needed for treatment. Health Gorilla has denied the allegations.

Pittsburgh-based UPMC and Ann Arbor-based Michigan Medicine later disclosed that Epic had alerted them to questionable activity involving their patients’ records. UPMC said Epic flagged that Health Gorilla had requested patient data under the guise of coordinating care for mutual patients. Michigan Medicine said Epic alerted it to unusual activity tied to third-party companies requesting records.

6. MyChart’s scale has created a separate cybersecurity challenge.

Epic has said MyChart’s security is unaffected, but scammers have increasingly used the MyChart name in phishing campaigns targeting patients.

By early September, Becker’s had tracked more than 40 health systems warning patients about fraudulent “MyChart Medicare Kit” messages. The messages direct recipients to a fake website intended to collect login credentials and personal information.

Epic attributed the scam attempts to criminals taking advantage of the popularity of the MyChart brand rather than a security vulnerability in the platform.

Advertisement

Next Up in EHRs / Interoperability

Advertisement