Epic shifts focus to cybersecurity while AI, interoperability agenda still on track, company says

Epic Systems is placing greater emphasis on cybersecurity protections as cyber threats continue to escalate, while also keeping its product roadmap on schedule.

During Modern Healthcare's Leadership Summit on Tuesday, CEO Judy Faulkner said the company was pausing most technology development to focus on system security. The work to safeguard Epic's systems will take another six weeks, Faulker said, and product development will continue at a slower pace, Modern Healthcare's Joyce Famakinwa reported.

When contacted by Fierce Healthcare, an Epic spokesperson said the company's development roadmap hasn’t changed since it was presented at Epic's August 2026 Users Group Meeting (UGM).

"We’re participating in Project Glasswing and using AI tools to stay ahead of cybersecurity threats that are growing across all industries," Epic's spokesperson said. "We’re also continuing rapid progress in many areas: expanded AI capabilities, Agent Factory, EpicOps, interoperability to speed up prior authorization, and more."

Anthropic's Project Glasswing is an AI cybersecurity initiative that brings together major technology companies along with organizations responsible for maintaining critical digital infrastructure. During Epic's UGM in August, Stirling Martin, Epic's chief security officer, confirmed that Epic was participating in the initiative. 

At the center of the project is Anthropic's unreleased Claude Mythos model that partner organizations are using to find software vulnerabilities and strengthen defensive security, according to Anthropic. Anthropic announced 50 initial partners in April and then expanded the project in June to include organizations representing industries not well represented in its initial cohort, including power, water, healthcare, communications and hardware, the company said.

"This year, we pointed these advanced AI models at our own code. Despite a codebase that is several 100 million lines large, AI models can easily make observations that our expert developers can't see. In each successive model, the AI gets better and better at finding potential vulnerabilities, and that's stringing unrelated issues together into a novel attack path. These are not obvious issues, but the nuanced interplay between unrelated parts of the software," Martin told the audience at UGM.

Epic's heightened focus on cybersecurity comes as healthcare organizations rapidly adopt AI tools, even as the industry grapples with the risks of accelerating innovation and mounting calls from some leaders to slow AI development.

Martin said during UGM that health system IT teams should expect to see a "higher-than-usual number of urgent security fixes" from Epic. 

"We're moving fast because speed is the whole game now, and these tools have given us a head start," he said. "It's part of our commitment to you to build things that last on infrastructure you can count on. We're not alone in this. Across the tech sector, critical security patches have surged this spring and summer."

During UGM, Epic unveiled a new suite of AI tools, new capabilities for clinical decision-making at the point of care and workflow automation, all building on initiatives announced at the 2025 UGM and also at industry conferences throughout the past year. A big headline during Epic's presentation was the rollout of its Agent Factory, the company's platform for building, running and monitoring AI agents that can reason and act across workflows.