Epic halts new development to address critical security flaws in patient portal
Epic Systems, the dominant provider of electronic health‑record software in the United States, announced that it will suspend all non‑essential product development for the next several weeks to concentrate on repairing security vulnerabilities that could expose patient information.
The move centers on MyChart, Epic’s widely deployed patient‑portal application that lets individuals view test results, schedule appointments and communicate with clinicians. The company said the bugs identified in recent internal audits could allow unauthorized access to health data if left unaddressed.
Epic’s decision comes amid a broader wave of scrutiny over health‑tech security, after a series of high‑profile data breaches at hospitals and clinics that rely on its platform. Regulators, including the U.S. Department of Health and Human Services, have heightened expectations for protecting electronic protected health information under the HIPAA rule, prompting vendors to prioritize vulnerability remediation.
By redirecting engineering resources away from feature work, Epic aims to patch the flaws, conduct thorough testing, and roll out updates to its client network before any exploit is observed in the wild. The company has not disclosed the exact number of affected installations, but its client base includes roughly a third of U.S. hospitals and many large health systems.
Healthcare providers that use MyChart may see a temporary slowdown in new functionality releases, but Epic assured that critical maintenance and support services will continue uninterrupted. Hospitals are expected to apply the forthcoming security patches as soon as they become available, a process that typically involves coordination with IT departments and, in some cases, temporary system downtime.
Analysts view the pause as a pragmatic response that could bolster confidence among providers and patients alike. While the immediate impact is limited to development timelines, the longer‑term benefit may be a more resilient platform that better safeguards sensitive health records against cyber threats.
Comments (0)
Be the first to comment.
Join the discussion