Nationwide Phishing Scams Exploit MyChart Brand to Target Patients
Dozens of healthcare systems are warning patients about phishing scams impersonating Epic's MyChart portal, using fake offers to steal personal information.

Healthcare organizations across the United States are issuing urgent alerts to patients regarding a widespread phishing campaign that leverages the trusted brand of Epic's MyChart patient portal. Attackers are employing deceptive emails, text messages, and phone calls to trick individuals into divulging sensitive personal information under the guise of offering rewards or benefits.
These scams often promise recipients a "2026 MyChart Senior Health Package," Medicare wellness benefits, a free health kit, or other incentives. To claim these supposed rewards, victims are prompted to click malicious links, confirm personal details, or provide other identifying information, thereby compromising their data and potentially their healthcare accounts.
Epic, the developer of the MyChart portal, has publicly acknowledged the threat, with Trevor Berceau, director of research and development, stating that scammers are exploiting the portal's popularity. "We've seen an uptick in scammers trying to trick patients by using the MyChart name or logo to make emails, text messages, phone calls and websites look official," Berceau noted in an alert on MyChart.org. He emphasized that these attacks are not indicative of a security flaw within MyChart itself but rather a tactic by cybercriminals to exploit user trust.
More than 30 healthcare systems that utilize Epic's electronic health record (EHR) systems and MyChart portals have released their own security warnings in recent weeks. Among the affected systems are Methodist Health System and Texas Health Resources in Texas, and Premier Health and MetroHealth in Ohio, with numerous other health systems nationwide joining the chorus of warnings.
Cybersecurity experts highlight that these campaigns are adapting traditional phishing tactics, creating a sense of urgency and prompting immediate action. "Cybercriminals are adapting traditional phishing tactics - creating urgency and prompting immediate action - to the patient portal environment," said Tom Walsh, founder and principal consultant at tw-Security. He added that scams might exploit fears about medical conditions, overdue bills, or denied insurance claims, or use routine matters like appointment confirmations to lure victims.
Furthermore, the sophistication of these attacks is being amplified by artificial intelligence. "AI enables cybercriminals to create more realistic fake patient portals, produce convincing and personalized phishing messages in multiple languages, and identify vulnerabilities that can be exploited," explained Walsh. This AI integration allows for faster, cheaper, and more scalable attacks, making it increasingly difficult for patients to distinguish legitimate communications from fraudulent ones.
While MyChart itself is not compromised, the potential impact on patients is significant. Beyond credential theft, these scams could evolve into more severe threats, such as watering hole attacks where compromised patient portals might be used to distribute malware to patients' home computers. The impersonation tactics can also extend to fabricating warnings about unauthorized access by proxy users, further increasing urgency and the likelihood of a successful scam.
Healthcare providers are urging patients to remain vigilant, scrutinize all communications, and verify the legitimacy of any requests for personal information. They advise patients to directly access their MyChart portal through official websites or mobile applications rather than clicking on links provided in suspicious emails or texts, and to report any suspected phishing attempts to their healthcare provider.