Epic Systems Corporation

United States · owned by Independent (United States) · www.epic.com · 40 vendors

Epic Systems Corporation develops electronic health record (EHR) software used by hospitals, clinics, and healthcare organizations of all types. Their software supports over 325 million patient records and is used across academic medical centers, community hospitals, independent practices, and more. Epic is employee-owned, developer-led, and invests approximately 35% of operating expenses in R&D.

Resilience scores

Disruption prediction

Epic Systems Corporation has an estimated 11% probability of disruption in the next 6 months.

18 of Epic Systems Corporation's 40 vendors monitored for disruptions.

Technology vendors

Services catalogue

8 services in catalogue across 3 categories; runs on 40 sub-vendors.

Insights

Last updated 2026-07-09 · revision 18

40 direct vendors, 335 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 4/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Epic Systems demonstrates medium migration readiness, leaning towards the lower end, primarily due to significant regulatory, data residency, and architectural complexities. Financially, Epic is well-positioned to fund a migration, with strong and consistent revenue growth. Their tech stack includes modern components like Golang, public cloud infrastructure, IaC, and DevOps tooling, and the open.epic platform with 750+ APIs offers interoperability opportunities. However, the company maintains a significant on-premises footprint, including a primary 100,000 sq ft data center, indicating a hybrid architecture that is not fully cloud-native, making a comprehensive migration complex. The regulatory environment is highly stringent, with strict HIPAA and GDPR compliance, and 'Assessment Required' for NIS2 and SOC2, which would add substantial overhead and risk to any migration effort. Furthermore, global operations necessitate compliance with multiple, often conflicting, data residency and sovereignty requirements, requiring region-specific data handling and local processing capabilities. This poses a major challenge for data relocation and architectural consolidation. The critical dependency on vendors like Change Healthcare, as evidenced by the 2024 disruption, highlights a significant vendor lock-in risk for crucial services, making disentanglement and migration from such integrated partners extremely difficult and costly. While Epic's open platform offers some flexibility, the deep integration of its core EHR system within healthcare workflows and the high regulatory and data residency hurdles present substantial barriers to a swift or easy migration.

Compliance

10 in-scope frameworks identified; showing 3.

CPRA — Compliant

Epic explicitly publishes a CCPA Privacy Notice on its legal disclosures page, demonstrating active compliance with California privacy law. Risk is Low because Epic has publicly acknowledged and addressed CCPA obligations, and the CCPA/CPRA medical information exemption (for HIPAA-covered data) significantly reduces Epic's direct CCPA exposure for most of its core healthcare data processing activities.

Evidence: https://www.epic.com/epic/page/epic-privacy-notice-california-residents, https://www.epic.com/legal-disclosures/

ISAE 3000 (source) — Assessment Required

ISAE 3000 is relevant for organizations providing assurance reports on non-financial information, including sustainability, privacy, and security controls. For Epic Systems, ISAE 3000 could be relevant in the context of: (1) ISAE 3402 (equivalent to SOC 1) for hosted service controls affecting customer financial reporting; (2) privacy assurance reports for EU customers. Risk is Low because ISAE 3000 is not a primary regulatory requirement for US-headquartered healthcare IT vendors, and Epic's primary assurance framework would be SOC 2 (AICPA) rather than ISAE 3000 (IAASB). However, EU customers may request ISAE 3000-based assurance reports as an alternative to SOC 2.

Evidence: https://www.epic.com/legal-disclosures/, https://www.iaasb.org/publications/international-standard-assurance-engagements-isae-3000-revised-assurance-engagements-other-audits

ONC Health IT Certification — Compliant

ONC Health IT Certification is a core regulatory requirement for Epic as a US EHR vendor. The 21st Century Cures Act (2016) and its implementing rules mandate information blocking prohibitions and interoperability requirements for certified EHR technology (CEHRT). Risk is High because: (1) Epic is the dominant US EHR vendor and a primary focus of ONC and CMS interoperability enforcement; (2) information blocking violations carry civil monetary penalties up to $1M per violation; (3) Epic has historically been scrutinized for interoperability practices; (4) TEFCA (Trusted Exchange Framework and Common Agreement) participation is increasingly expected. Epic has publicly committed to interoperability through its Open@Epic program.

Evidence: https://open.epic.com, https://www.healthit.gov/topic/certification-ehrs/certification-health-it, https://chpl.healthit.gov/, https://www.healthit.gov/topic/interoperability/policy/trusted-exchange-framework-and-common-agreement-tefca

Financials

Three-year financials

Financial Resilience Score: 9/10

Epic Systems demonstrates exceptional financial resilience despite being a private company with limited public disclosure. The company has a dominant market position in U.S. acute-care hospital EHR software, with the leading market share per KLAS Research. Its business model generates highly recurring revenue through long-term license, hosting, and support contracts with large health systems, and customer retention is extremely high due to prohibitive switching costs in EHR systems. Founder and CEO Judy Faulkner has repeatedly stated that Epic has been profitable every year since founding and carries no debt, having self-funded all growth including its expansive 1,000+ acre Verona, WI campus. The company faces meaningful risks, however. Growth is bumping against a finite number of large U.S. health systems, requiring international expansion and adjacent modules for continued growth. Regulatory pressure from ONC information-blocking rules, TEFCA, and the 21st Century Cures Act creates ongoing compliance burdens. Competition from Oracle Health (Cerner), Meditech, and cloud-native entrants including Microsoft/Google/Amazon on the AI layer is intensifying. Key-person risk around Faulkner and succession, plus antitrust/privacy scrutiny, are additional concerns. The lack of audited financials itself represents an opacity risk for counterparties.

Key strengths: Dominant U.S. EHR market position (leading share per KLAS), Recurring revenue from long-term contracts with large health systems, No external debt and no venture/PE ownership; fully self-funded, Very high customer retention due to prohibitive EHR switching costs, Cash-funded R&D and campus expansion from operating cash flow, Consistently profitable every year since 1979 founding, International traction across Europe, Middle East, Canada, and APAC

Risk factors: Customer concentration in finite U.S. large-hospital segment, Regulatory and interoperability pressure (ONC, TEFCA, Cures Act), Competition from Oracle Health, Meditech, and cloud-native/AI entrants, Key-person and succession risk around founder Judy Faulkner, Antitrust and privacy scrutiny around data access and ecosystem control, Financial opacity itself is a counterparty risk

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report