MyChart Phishing Scam Warnings Issued by U.S. Healthcare Providers

An unknown cybercriminal actor has been targeting patients across the country with phishing attempts mimicking the electronic health record (EHR) vendor Epic Systems. Epic is the largest EHR vendor by market share, and its EHR software is used by many of the largest health systems in the United States, including for their patient portals.

The phishing campaign impersonates Epic and appears to have been sent via the Epic MyChart patient portal. The messages include the MyChart image; however, they have not been sent by Epic nor any of its healthcare provider clients. Warnings about the phishing attempts have been issued by Epic and dozens of U.S. healthcare systems in the past days and weeks.

It is unclear from reporting and alerts exactly what the campaign attempts to achieve, although it is likely that the threat actor seeks login credentials for the MyChart portal, which provide access to sensitive health information. They may also seek to obtain personal and financial information.

“We’ve seen an uptick in scammers trying to trick patients by using the MyChart name or logo to make emails, text messages, phone calls, and websites look official. Some might try to steal your login information or promise free gifts if you enter payment details,” explained Trevor Berceau, Director R&D, Epic. “The increase in attempts is due to scammers taking advantage of the popularity of the MyChart brand rather than any security concern, so you can continue to use MyChart as normal. If something doesn’t feel right, however, stop and check. The Staying Safe page on MyChart.org has a few simple habits that go a long way toward keeping you safe.”

The phishing attempts reported to date are standard phishing fare, offering the recipient a free item that they have won/been awarded. The phishing messages have offered a “MyChart Medicare Kit” or a “2026 MyChart Senior Care Package,” which include various Medicare wellness benefits. Messages may also be sent offering other rewards, awards, or free gifts.

To obtain the free item/reward, the recipient is required to take an action – click the link in the email and provide personal, financial, or login information. While this appears to be an email-only campaign, text messages may be used, and it is possible that the campaign may also be extended to telephone calls. While the campaign involves offers of free gifts, other tactics may be adopted, such as security alerts that require a login to the portal to fix.

HIPAA
Compliance
Checklist

Simple Guidelines
Immediate PDF Download

Immediate Access

Privacy Policy

Download Free Checklist
MyChart Phishing Scam

Example of a phishing email impersonating MyChart from the current campaign.

Any patient receiving a message via email or text message that appears to have been sent by their healthcare provider, Epic, or MyChart, should check the message carefully, including the email address of the sender and the domain used (e.g., epic.com; premierhealth.com). For instance, Premier Health has issued an alert warning patients that any genuine communications will come from [email protected].

The advice offered in case of receipt of a suspicious communication is:

  • Delete the email immediately.
  • Do not click any links, including any “unsubscribe” links.
  • Do not provide personal, financial, or health information.
  • Do not reply to the email.

If you are unsure whether a MyChart-related email is legitimate, you should contact your healthcare provider using verified contact information, which can be obtained from the official healthcare provider website. Never use any contact information provided in the message. If you have already responded, log in to your MyChart portal immediately via the genuine patient portal address and change your password.

About Liam Johnson

Liam Johnson has produced articles about HIPAA for several years. He has extensive experience in healthcare privacy and security. With a deep understanding of the complex legal and regulatory landscape surrounding patient data protection, Liam has dedicated his career to helping organizations navigate the intricacies of HIPAA compliance. Liam focusses on the challenges faced by healthcare providers, insurance companies, and business associates in complying with HIPAA regulations. Liam has been published in leading healthcare publications, including The HIPAA Journal. Liam was appointed Editor-in-Chief of The HIPAA Guide in 2023. Contact Liam via LinkedIn: https://www.linkedin.com/in/liamhipaa/