Epic’s decision to pause much of its product development and shift engineering resources toward security deserves more attention from healthcare CIOs than another routine vulnerability announcement.
The immediate issue involves potential security weaknesses associated with certain MyChart configurations. According to TechCrunch reporting, Epic's Chief Security Officer said some configurations could allow unauthorized access to patient information without that activity appearing in the normal logs used to detect it. No public evidence shows these weaknesses were exploited or caused a health system breach.
That last point is important. We should not connect an unproven vulnerability to an attack simply because the timing looks interesting.
But CIOs should still ask a harder question.
Over the past several months, multiple health systems have experienced cyber incidents that disrupted patient portals and clinical operations. CIOs shouldn't retroactively blame Epic for these incidents. But Epic’s latest discovery changes the questions CIOs should ask when reviewing them.
Cyber investigations depend heavily on logs. We look for failed authentication attempts, unusual access, privilege escalation, and abnormal activity to reconstruct what happened.
If a vulnerability, under certain configurations, could permit access without generating the expected logging evidence, then saying “we found no evidence of unauthorized access” may not be enough.
The next question is: Were our controls capable of producing the evidence in the first place?
For Epic customers, remediation should therefore go beyond installing whatever fixes Epic provides. CIOs and CISOs should determine whether their MyChart configuration was potentially exposed, validate identity and authentication controls, review configuration changes that differ from Epic’s recommended standards, and determine whether additional forensic review of previous incidents is warranted.
Vendor-Management Lesson.
Health systems evaluate vendors on functionality, roadmap, interoperability, and price without security scoring. Security response capacity now deserves equal weight. When a security exposure is discovered, how quickly can the vendor redirect engineering resources, identify affected customers, communicate exposure, and remediate the problem?
Epic appears willing to slow feature development to answer that question. Healthcare CIOs should now determine whether their other critical technology vendors would do the same. Because after this disclosure, the question is no longer simply whether the logs show evidence of compromise. It is whether we could see the compromise at all.


