The Cost of Speed: Epic's Security Pause is a Wake-Up Call for Health Tech

AI-generated image · Bay Street Wire
Opinion: The decision by medical records giant Epic to halt product development to fix security flaws reveals a dangerous industry trend of prioritizing growth over patient safety.
In the software world, the 'move fast and break things' mantra is often worn as a badge of honor. But when the 'things' being broken are the privacy and security of 320 million patient records, the cost of that velocity becomes unacceptable.
Epic, the giant behind the MyChart software used across U.S. hospitals and clinics, recently took the rare step of pausing most of its product development, as TechCrunch first reported. According to TechCrunch, founder and CEO Judy Faulkner told Modern Healthcare that this pause would likely last six weeks. The goal? "Safeguarding" the company's products after the deployment of Mythos—a frontier cybersecurity model from Anthropic—exposed security flaws that could jeopardize patient data.
While Epic's decision to stop the clock is a necessary corrective, it is also a damning admission. As Stirling Martin, Epic's chief security officer, told The New York Times, certain customer configurations of MyChart could potentially allow outsiders to access patient records without leaving a trace in the software's logs. While Martin noted to the Times that the AI model did not specify if these bugs could be used to alter records without detection, he argued the risk was sufficient to warrant remediation.
This is not an isolated incident of technical debt; it is a symptom of a systemic crisis in health tech. The industry has become a playground for hackers who gamble on the fact that providers will pay any price to keep sensitive data private. We have seen the wreckage of this approach. TechCrunch notes that a 2024 ransomware attack on Change Healthcare—owned by UnitedHealth—resulted in the theft of health data for over 192 million people, leading the company to pay hackers twice to prevent the data's publication.
The current year has only intensified the carnage. TechCrunch reports a string of breaches affecting tens of millions, including thefts from electronic health data storage firm CareCloud, pharmaceutical distributor McKesson, and the North American software operations of U.K.-based Craneware. Even the Department of Health and Human Services has flagged a breach at DentaQuest, a dental insurance company, as the largest healthcare-related breach of 2026 so far, affecting 15 million people.
Epic's defense—that the responsibility for medical data falls on the healthcare providers rather than the software vendor—is a convenient legal shield, but a poor security strategy. If a bug unknown to Epic allows hackers to raid multiple MyChart systems across the country, the vendor's lack of direct data access is a moot point. The vulnerability exists in the architecture itself.
The irony is that the very technology accelerating these threats—AI—is what finally forced Epic's hand. The ability of tools like Mythos to rapidly identify vulnerabilities means that the window for 'fixing it in the next update' has closed.
Epic is right to pause, but the industry should have paused long ago. When you are managing the intimate health details of a third of the American population, 'moving fast' is not an innovation strategy; it is a liability.

