The FTC Opens an Antitrust Probe Into Epic Systems: Why This One Matters

Reuters reported this week that the Federal Trade Commission has opened an antitrust investigation into Epic Systems, the dominant electronic health records vendor based in Verona, Wisconsin. The report, citing two sources familiar with the matter, says the FTC has already sent investigative demands to other companies in the health technology industry, seeking information about how Epic controls access to patient data. The agency has not confirmed the investigation publicly, and Epic disputes any suggestion that it restricts competitors from accessing data. But the timing and the substance of this probe are worth unpacking, because Epic’s market position makes this a genuinely significant antitrust matter, not a routine regulatory inquiry.
Why Epic’s Market Position Makes This Different
Epic is not just a large software vendor. It holds the medical records of hundreds of millions of Americans and controls roughly 44 percent of the U.S. acute care hospital EHR market according to industry research firm KLAS, making it the single largest player in a market where switching costs are enormous and provider organizations rarely change platforms once they’ve built clinical workflows around one. Its patient portal MyChart and its broader systems serve provider networks treating well over a quarter billion people. Epic also runs a research platform through which participating health systems can study data from over 300 million patients who have opted in.
That scale is precisely what makes data-access practices an antitrust question rather than just a technical interoperability dispute. When one vendor sits at the center of the pipes through which the vast majority of American clinical data flows, decisions about who gets access to that data, on what terms, and at what cost become decisions with market-wide competitive consequences. A dominant EHR vendor that makes it harder, slower, or more expensive for rival platforms to pull or exchange patient records isn’t just making a product design choice. It’s potentially shaping which competitors can survive in adjacent markets, including health information exchanges, care coordination platforms, and third-party data aggregation services.
A Pattern, Not an Isolated Complaint
What elevates this FTC inquiry beyond a one-off regulatory curiosity is that it lands in the middle of an existing pattern of legal challenges to Epic’s data-sharing conduct. Texas Attorney General Ken Paxton sued Epic in December, alleging the company used contractual restrictions and fee structures to discourage healthcare systems from adopting competing platforms. Separately, Particle Health, a company that operates in the market for insurer-facing platforms that aggregate and review medical records at scale, has an active lawsuit accusing Epic of erecting barriers that block Particle from serving prospective clients. Epic denies wrongdoing in both matters and maintains that access-control decisions belong to its provider customers, not to Epic itself, while also pointing to its own connectivity credentials, including being the first EHR vendor connected to TEFCA, the federally sponsored national interoperability framework, and its publication of more than a thousand APIs for third-party developers.

Multiple independent actors, a state attorney general, a private commercial competitor, and now apparently the FTC, examining the same category of conduct within the same roughly nine-month window is a meaningful signal regardless of how any individual matter resolves. Antitrust enforcers and private plaintiffs do not typically converge on the same target and the same theory by coincidence. It suggests there is a genuine factual dispute about how Epic’s technical and contractual architecture functions in practice, one that regulators believe warrants a closer look even in the face of Epic’s public statements about its interoperability record.
What an FTC Antitrust Theory Might Look Like Here
Without confirmation from the FTC about the scope or theory of its inquiry, any specifics are necessarily speculative. But the general shape of the concern being investigated, per Reuters’ sourcing, centers on how Epic grants or restricts data access to competitors, which tracks classic monopolization theories under Section 2 of the Sherman Act: refusal to deal, exclusionary contract terms, or self-preferencing that disadvantages rivals attempting to interoperate with a dominant platform. The fact that the FTC reportedly sent investigative demands to other companies in the industry, not just to Epic, suggests the agency is trying to build a market-wide picture of how data flows (or doesn’t) between Epic and non-Epic systems, rather than examining a single contractual dispute in isolation.
This is also a useful moment to note what is not in dispute. Epic’s own account of its interoperability infrastructure, daily exchange volumes in the tens of millions of records, a network built since 2008, thousands of active developer integrations, is not a fabricated narrative; those are real technical capabilities. The antitrust question, if there is one, will not turn on whether Epic has built interoperability infrastructure. It will turn on whether Epic’s terms of access, pricing structures, or technical gatekeeping around that infrastructure disadvantage competitors in a way that harms competition rather than simply protecting Epic’s commercial interests, a distinction that is often difficult to draw and even harder to litigate.
Why This Should Be on Every Health System Compliance Officer’s Radar
For hospital and health system compliance and legal teams, this development matters even if your organization is not a direct party to any of these disputes. A few practical points follow.
First, data-sharing agreements between health systems and EHR vendors, and between health systems and third-party platforms seeking to access patient data through those vendors, are likely to face increased scrutiny regardless of how the FTC matter resolves. Organizations should be reviewing their own data governance agreements now, understanding exactly what access rights they hold, what restrictions their EHR vendor contracts impose, and who actually controls downstream data-sharing decisions under those contracts.

Second, healthcare organizations sit in an unusual position in this dispute: they are simultaneously Epic’s customers and, per Epic’s own public position, the parties who control access to their patients’ data under the vendor’s contractual framework. If regulators or courts ultimately find that Epic’s contract terms effectively transferred practical control over data access away from provider organizations, health systems could find themselves needing to revisit vendor agreements that were signed with the understanding that they, not the vendor, held that control.
Third, this case sits squarely at the intersection of two regulatory frameworks compliance officers should already know well: the information blocking provisions under the 21st Century Cures Act, enforced by the HHS Office of Inspector General, and now potentially federal antitrust law. A finding of information blocking and a finding of anticompetitive conduct are not the same legal theory, but the underlying facts, restrictions on data portability and access, could plausibly support both. Compliance functions that have been treating information blocking compliance and antitrust risk as separate silos should reconsider that separation given how this matter is developing.
Bottom Line
The FTC investigation into Epic is still in its early, unconfirmed stages, and Epic has pushed back firmly on any suggestion of anticompetitive conduct. But when a dominant vendor holding this much of the national EHR market draws simultaneous scrutiny from a state attorney general, a private competitor, and now apparently a federal antitrust regulator, all over the same underlying question of data access and control, health systems and compliance officers should treat this as a live issue worth tracking closely rather than a dispute confined to Epic and its direct legal adversaries. The outcome here could reshape how EHR vendor contracts get negotiated across the entire industry.











