Estimated reading time: 3 minutes · Last updated:
Joyce Famakinwa wrote on 22 September 2026 that Epic Systems paused most of its technology development to reallocate staff from new feature work into vulnerability assessment and remediation and to identify and fix weaknesses that could be exploited by cyberattacks; the item included a photograph of Epic founder and CEO Judy Faulkner at an event hosted by the outlet, as first reported by Modern Healthcare. Epic paused product development while it audits code, access controls and external interfaces to reduce exposure and prevent data breaches affecting health systems that rely on its electronic health record software.
Key takeaways
- Who acted: Joyce Famakinwa reported on 22 September 2026 that Epic Systems paused most of its technology development.
- Why: Epic said the pause is intended to verify its systems for vulnerabilities and to strengthen defenses against potential cyberattacks.
- Leadership noted: Judy Faulkner, Epic founder and CEO, is identified in the published coverage accompanying the announcement.
Table of contents
Why Epic paused development
Joyce Famakinwa wrote on 22 September 2026 that Epic has slowed new product work to concentrate on security. The company moved engineering resources from feature development into testing, code review and patching to reduce risk across its deployed electronic health record platform.
The decision frames security work as a near-term operational priority rather than a routine maintenance task. By pausing most product development, Epic intends to limit new code paths and third-party integrations while teams complete vulnerability scans and address identified weaknesses.
What the pause means for customers and partners
Hospitals and clinics that run Epic software depend on regular updates for interoperability, billing and clinical tools; a development pause may delay some planned feature releases. Customers will still need security patches and urgent fixes, and the company’s shift implies those items are being prioritised over enhancements.
Vendors and integration partners should expect tighter coordination around change windows and security testing. The reporting highlights a trade-off: slower product cadence now to reduce the likelihood of a disruptive cyberincident later.
How this fits broader health IT security practice
The action echoes a wider industry emphasis on hardening clinical systems after a string of health-sector cyberattacks in recent years. For a major EHR supplier, concentrating on access controls, encryption and patch management follows recommended best practice for reducing attack surface.
In short, the move treats security as an operational imperative that temporarily outweighs new development, a posture health systems increasingly expect from platform vendors responsible for sensitive patient data.
| Aspect | Before pause | After shift |
|---|---|---|
| Primary focus | New features and product development | Security audits, remediation and patching |
| Customer impact | Regular feature updates | Prioritised security fixes; feature timelines extended |
| Company message | Ongoing innovation | Reduce vulnerability to cyberattacks |
Potential near-term outcomes
The case for
- Reduced exposure to known vulnerabilities as audits and patches are applied.
- Stronger access controls and monitoring could lower the chance of a major data breach affecting clients.
The case against
- Planned feature releases for health systems may be delayed while engineering capacity is reallocated.
- Partners that depend on API changes or new integrations could face schedule and testing disruptions.
What to be careful about
- Delayed product enhancements that health systems planned to deploy, affecting interoperability or workflow improvements.
- Customer frustration or procurement pressure if feature roadmaps slip without clear timelines.
- Concentration of engineering resources on security could expose gaps elsewhere, such as performance tuning or support backlog.
The bottom line
Epic’s decision to pause most product development and focus resources on cybersecurity is a deliberate shift in priorities, Joyce Famakinwa reported on 22 September 2026. For hospital IT teams the move reduces immediate risk from unaddressed vulnerabilities, but it also creates uncertainty about delivery dates for planned enhancements. Integration partners should prepare for closer change coordination and possible schedule adjustments. Until Epic sets a public timeline or issues a formal remediation plan, customers and vendors will judge the action by the company’s follow-up communication and the pace of critical security updates.
What to watch
- Watch for an Epic announcement setting a timeline for when development will resume; no date has been set in the published coverage.
- Watch for customer advisories from hospitals using Epic about feature delays and scheduled security maintenance; no date has been set in the published coverage.
Frequently asked questions
Did Epic announce the pause publicly?
Yes. Joyce Famakinwa reported on 22 September 2026 that Epic Systems has paused most technology development to focus on security.
Who leads Epic and was named in the coverage?
Joyce Famakinwa identified Judy Faulkner as Epic’s founder and CEO; Faulkner appears in the photograph that accompanied Famakinwa's account.
Will customers still receive security patches during the pause?
The reporting indicates security work is the priority, which implies urgent patches and remediations remain in scope even as broader product development is paused, though no official Epic timeline was provided.
Related reading