Table of Contents
Epic Identifies Schemes in the MyChart Phishing Scam
A phishing scam impersonating Epic’s MyChart is targeting patients at health systems across the U.S. Fraudulent emails and text messages use fake offers, urgent alerts, and other tactics to trick recipients into clicking malicious links or providing personal or financial information.
Epic has identified two active schemes. One promotes a “MyChart Medicare Kit,” “Senior Health Package” or similar free offer, then directs recipients to a bogus survey with a countdown timer designed to collect personal and payment information. The other uses a fake “critical” lab result to pressure patients into downloading and running malicious software.
Dozens of health systems have warned patients about the scams or received reports of fraudulent messages, including Cleveland Clinic, MD Anderson Cancer Center and Mount Sinai Health System.
The messages do not come from Epic or the affected health systems. According to Epic, scammers are exploiting the familiarity and trust associated with the MyChart name, not a security vulnerability in the platform. There is no indication that MyChart itself has been breached, and patients can continue using MyChart normally.
How Does the MyChart Phishing Scam Work?
The scams use the MyChart name and logo to make fraudulent communications appear legitimate. In one campaign identified by Epic, recipients are told they have been selected to receive a free “2026 Medicare Health Kit.” After clicking a link, victims are eventually directed to a form requesting their name, email address, phone number and mailing address, followed by credit card information to cover a small shipping fee.
Epic has also identified a scam that directs patients to a fake MyChart login page designed to steal credentials. The fake site may display fabricated medical results and use alarming health information to create urgency. In some cases, victims are instructed to run commands or download software that can install malware on their computers.
What Can Healthcare Organizations Do About the MyChart Phishing Scam?
Although these scams do not indicate that MyChart or the affected health systems have been breached, healthcare organizations can take steps to protect patients and make impersonation attacks less effective.
Organizations should proactively warn patients through their websites, patient portals and other trusted communications and explain what legitimate MyChart communications look like. They should also provide a clear way for patients to verify suspicious messages and report potential phishing attempts.
Healthcare organizations can also monitor for fake websites, look-alike domains and other attempts to impersonate their organization or MyChart. When patients report compromised credentials, organizations should be prepared to quickly help secure the account and investigate suspicious activity.
The HHS Office for Civil Rights recommends that HIPAA-regulated organizations address social engineering threats through security awareness and training, anti-phishing technologies, link and attachment scanning, access controls and other safeguards. Organizations should also incorporate phishing and other reasonably anticipated cyber threats into their security risk analysis and risk management processes.
If a phishing incident results in unauthorized access to an organization’s systems or electronic protected health information (ePHI), the organization should investigate the incident and determine whether HIPAA breach notification requirements apply. HHS OCR has emphasized risk analysis, audit controls, system activity reviews, authentication and incident response as important safeguards for protecting ePHI.
How to Help Patients Avoid the MyChart Phishing Scam
The scam also highlights a broader challenge: As phishing messages become increasingly sophisticated, patients cannot be expected to identify every fake. Healthcare providers must organizations should communicate with patients in clear, consistent ways that help build trust and make fraudulent messages easier to recognize.
Passing along the following tips can help patients identify and avoid fraudulent messaging.
- Don’t click unexpected links or attachments. Instead, access MyChart through the official app or your healthcare provider’s website.
- Check the sender and web address carefully. Look for unfamiliar addresses, misspellings or extra words.
- Be skeptical of unsolicited free offers. MyChart does not offer giveaways such as Medicare kits or other prizes.
- Never provide passwords or verification codes in response to an email, text or phone call. Epic and healthcare organizations will not ask for them this way.
- Never follow instructions to run computer commands or download software to access medical information.
- Report suspicious messages as phishing or spam and delete them.
What Happens If You Fall for the Scam?
The consequences depend on what information a victim provides. According to MyChart.org, scammers may collect names, email addresses, phone numbers and mailing addresses that can be sold or used for additional scams.
Some versions also request credit card information for a small shipping fee associated with the supposedly free health kit. No kit is shipped, and charges may repeat or increase.
If MyChart login credentials are stolen, criminals could potentially gain unauthorized access to an account containing sensitive health information. Victims should immediately reset their MyChart password, review the contact information associated with the account and contact their healthcare organization’s help desk. If credit card information was provided, Epic recommends contacting the bank, reporting the charge as fraud and requesting a replacement card.
As phishing attacks become more convincing, protecting patients requires more than asking them to spot suspicious messages. Healthcare organizations can reduce risk through clear, consistent communication, patient education, and strong security practices that make impersonation scams easier to recognize.
MyChart Phishing Scam FAQs
MyChart is widely used and familiar to millions of patients, making it an attractive brand for impersonation. Scammers exploit that familiarity to make fraudulent emails and texts appear more credible and increase the likelihood that recipients will respond. No. The phishing campaign does not indicate that Epic’s MyChart platform or the affected healthcare organizations have been breached. Scammers are impersonating the trusted MyChart brand to make fraudulent messages appear legitimate. Scammers may send emails or texts promoting a “MyChart Medicare Kit,” “Senior Health Package” or other free offer. Other messages may claim patients have a critical lab result. The goal is to persuade recipients to click malicious links, download software or provide personal or financial information. Patients should be cautious of unexpected messages that create urgency, offer free products, request payment information, or direct them to unfamiliar websites. When in doubt, patients should access MyChart through their healthcare provider’s website or the official MyChart app rather than clicking a link. Patients who clicked a suspicious link or provided information should immediately contact their healthcare organization and financial institution, change potentially compromised passwords, and monitor their accounts for suspicious activity. Anyone who downloaded software should also have the device checked for malware. Healthcare organizations can clearly explain how they communicate with patients, quickly warn them about known scams, and provide an easy way to verify suspicious messages. Consistent communication, patient education, and strong security practices can make impersonation attacks less effective.
Enhance Your Cybersecurity Posture
As cybercriminal activity and data breaches continue to rise, up to 90% of breaches start with a phishing email, making your users the last line of defense. That’s why we offer managed phishing and cybersecurity awareness training services.


