The MyChart ‘Medicare Kit’ Scam: Six Screens, One Rule That Stops It
Bottom line up front
Emails and texts offering a free “2026 Medicare Health Kit” or a “senior health package” from MyChart are phishing, and they are not coming from your doctor’s office or from Epic. Becker’s has counted 41 health systems warning their patients about it, and Epic’s own security team has published the whole funnel, screen by screen. You do not need to recognize any of those screens. MyChart is a medical records portal and it does not run giveaways — that one fact rules out every version of this message, including the ones that have not been written yet.
A patient portal is an odd thing to be phished through, and that is exactly why it works. For fifteen years health systems have been telling people to stop calling the front desk and use the portal instead. Check your results there. Message your doctor there. Pay your bill there. Then one morning an email arrives with the MyChart name on it, and the habit that has been trained into you says: open it.
The version going around right now is the friendliest phishing email I have seen in a while. Nobody is arrested, nothing is overdue, no account is suspended. You have simply been selected for a free kit.
If one of these is on your screen right now
Short version first, in case you are mid-decision and the page has a clock on it.
- Do not click, and do not tap “unsubscribe” either. Both tell the sender the address is live, and unsubscribe links in phishing mail routinely lead somewhere worse than the original.
- Report it as junk or phishing in your mail app, then delete it. Epic points out that this is the single most useful thing a recipient can do, because it teaches the filter to catch the next one for everybody, not just for you.
- If you want to check whether something real is waiting, open MyChart the way you always do. The app on your phone, or your own bookmark. Never the link in the message.
- If you typed your name, address or phone into a form, nothing catastrophic has happened yet. Write down which fields you filled in. Expect calls and mail. Do not answer follow-up questions from anyone who rings about it.
- If you entered card details, call your bank today and ask for the card to be replaced. Not just a dispute on the one charge — a new number. Epic’s guidance says the same thing, and the reason is that the charge is designed to repeat.
- If a page told you to press keys — Windows key, then R, then Ctrl and V, then Enter — treat the computer as compromised. Disconnect it from the internet and get it looked at before you use it for banking, email or anything from work.
Definition
The MyChart “Medicare Kit” scam is a phishing campaign that borrows the MyChart name and logo to offer patients a free Medicare kit or senior wellness package. The link leads to a survey, then a small shipping fee, then a card form. No kit exists; the fee and the personal details are the product.
What is actually going on
Epic, the company behind MyChart, said in late July that it had seen a rise in scammers using the MyChart name and logo across email, text, phone calls and look-alike websites. The framing in that post matters: Trevor Berceau, Epic’s director of research and development, attributed the increase to scammers taking advantage of how well known the MyChart brand is rather than to any security problem, and told patients they can keep using MyChart normally.
That is worth sitting with for a second, because it changes what you should do about it. Nothing was broken into. Your records were not taken. Someone put a well-known logo on an email, which anyone can do, and sent it to a very large number of people.
The scale of the response is the surprising part. On 24 August the American Hospital Association carried the warning to its members. By 27 August, Becker’s had assembled a running list of 41 health systems that had posted notices or whose patients had reported the emails — Cleveland Clinic, Mass General Brigham, Mount Sinai, MD Anderson, Emory, Northwell, and a long tail of community hospitals in Iowa, Oregon, Washington and Georgia. The list started at 21 and Becker’s has been adding to it.
I read a lot of these notices while writing this. The one from UMass Memorial has a detail I liked, because it is the kind of thing only the organization itself would know: UMass Memorial brands its portal with a lowercase m, as myChart. An email that writes “MyChart” is, for their patients specifically, already suspect. That tell does not transfer anywhere else, which is sort of the point — the checks that work best are the ones that come from your own provider rather than from a general list of phishing advice.
The six screens, in order
Most write-ups of a phishing campaign stop at “don’t click the link.” Epic did something more useful: its security team walked the whole thing and published every screen, with annotations. If you have an older relative who does not believe an email can be fake when it looks that ordinary, that page is the thing to show them.
Here is the sequence.
Sequence and figures as documented by Epic security investigations, summer 2026, published on MyChart.org. Amber marks the attacker’s setup; red marks the point where information and money leave.
Two things in that flow deserve more than a box.
The countdown clock
The survey page carries a timer and a banner claiming that more than $300,000 in MyChart products have already been given away. Neither number is real, and the survey answers are never read — Epic notes that the same reward appears no matter what you click. The clock is not there to manage inventory. It is there to stop you doing the one thing that would end the whole attempt, which is pausing long enough to wonder why a hospital records system is running a sweepstake.
Urgency is the common thread through nearly every scam we write about here, from the fake arrest warrant to the utility shutoff call. It shows up in a friendly form here rather than a frightening one, but it is doing the same job.
The switch from free to almost free
This is the hinge. The kit is presented as a $149 value, now $0, with a few left in stock. You click to claim it, a pop-up confirms one has been reserved for you, and then a step appears that was never mentioned: the shipping fee. $13.77.
A prize you have to pay for is not a prize. And the amount is chosen with some care — small enough that arguing feels petty, small enough that it can sit on a statement for months without drawing a second look, small enough to repeat. The card details are what the whole funnel was built to reach.
The form before it is arguably worse, though, and it gets less attention. Before you can pay, the page collects your full name, email address, phone number and mailing address, behind a reassuring padlock and a “256 bit encrypted” badge. Epic’s note on this is blunt: that information is taken the moment you type it, whether or not you ever complete the payment. Encryption only means nobody could read your details on the way to the scammer.
So a person who filled in the form, felt uneasy at the card page and closed the tab has not escaped. They have handed over a verified name-address-phone-email set attached to a person who is on Medicare and responds to health offers. That is a good lead, and it gets sold.
Why the portal is a hard brand to doubt
Think about what a patient portal has spent a decade teaching you.
It sends you email you did not ask for, and those emails are legitimate. It tells you a message is waiting without saying what it is, so vagueness is normal. It asks you to log in, frequently. It is where genuinely important news arrives — results, referrals, a change to a prescription. And it is operated by an organization you already trust with considerably more than your email address.
Every one of those trained reflexes is useful to an attacker. Compare it with a bank, where most people have absorbed the rule that the bank never emails asking you to log in. There is no equivalent folk rule for the portal, because the portal does email you asking you to log in. That is what it does all day.
The other thing working in the attacker’s favor is list quality. You do not need a health system to be breached to guess that a 70-year-old has a MyChart account; roughly everyone does. But the last two years have also put an enormous volume of genuinely health-adjacent contact data into criminal hands — the Exact Sciences breach alone indexed 10.9 million email addresses belonging to people who had used a cancer screening test. Nobody needs to know your diagnosis to send you this email. They only need to know you are the kind of person who opens health mail.
Not sure about an email that is sitting in your inbox?
Paste it into the free ScamDrill email scam checker and get an instant read on the sender, the links and the language. Nothing is stored, and you do not need an account.
Check an emailThe other campaign wearing the same name
The Medicare Kit is the one making the news, because it is the one that generates phone calls to hospital switchboards. Running alongside it is a second campaign that is quieter and considerably more dangerous, and Epic documented that one too.
It starts with an email saying your recent results are ready. MyChart logo, a sign-in button. The button goes to a copy of the MyChart login page — the scammers lifted the real site’s code, so it is not an approximation — at an address like mychart-epic or my-chart, close enough to the real thing to survive a glance. You enter your email, then your password.
Then you are shown a chart. The name, birthday and patient number on it are invented. A pop-up announces that an “AI-powered review” has found critical patterns in your blood work requiring immediate attention.
And then, to see the results, you are asked to prove you are human. The page says a verification code has been copied for you, and walks you through three keystrokes: hold Windows, press R; press Ctrl and V; press Enter.
This is the attack
Those three keystrokes open the Windows Run box, paste in whatever the page quietly put on your clipboard, and execute it. Nothing visible happens afterwards. The technique is called ClickFix, and we wrote about it in detail when it was mostly showing up as a fake CAPTCHA. No real website has ever needed you to press keyboard shortcuts to prove you are a person.
In August, Epic saw the same fake site with the ending swapped out. This time the fake chart shows a table of alarming lab values with some of them redacted, and a button promising to reveal the full report. The button downloads a program, Full_Analysis_Report.exe, and the page then coaches you past your own computer’s security warning — click “More info,” then “Run anyway.”
Lab results live in MyChart. They do not arrive as a program you download. And a page telling you to click through a Windows security warning is asking you to ignore the one thing on the screen that was on your side.
Five rules that survive the next redesign
The wording of these emails changes constantly. Epic notes that within one two-week window, patients reported a congratulations letter, a delivery notice for a kit already on its way, and a plain thank-you to a valued member — all the same campaign. Advice pinned to the specific wording goes stale in a two weeks. These do not.
Rules 1–3 and 5 per Epic’s MyChart guidance on scams and fraud; rule 4 per the FTC consumer alert of 28 May 2026 and Medicare.gov. Senior Medicare Patrol: 1-877-808-2468.
Rule one carries most of the weight, and it is the only one worth memorising if you are going to memorise one. A records portal has no reason to give you a product. There is no scenario in which Epic is running a giveaway, and there is no health system that will mail you a wellness package because you answered four survey questions. So the moment a message combines the words MyChart and free, you are done thinking about it. You do not have to examine the sender address or hover the link or squint at the grammar, all of which an attacker can fix.
One more small detail from Epic’s teardown that I keep coming back to: the fine print on the Medicare Kit email signs off as “MyChart Health Network,” at an address in Verona, Wisconsin. There is no such company, and the address is wrong — but Verona is where Epic’s campus actually is. Somebody did research, got close, and still could not make it land. Fake mail is often like that. Not obviously wrong, just faintly off, in a way you would only catch if you already suspected something.
If you already clicked, filled in a form, or paid
Take this in the order that matters, not the order of how bad it feels.
You clicked but entered nothing
You are almost certainly fine. Close the page. Do not reply and do not unsubscribe. Report the message as phishing in your mail app and delete it.
You entered a MyChart password
Change it now, at your health system’s real MyChart site or in the app. If you reused that password anywhere else — and most people have, at least once — change it there too, starting with email. Then open MyChart and check the email address and phone number on file, because changing those is how someone keeps access after you reset the password.
You filled in name, address and phone
No account was taken, so treat this as information loss rather than a break-in. Write down exactly which fields you completed. Then tell whoever else needs to know, because the practical consequence is a wave of calls and mail that will sound informed — the caller will have your name right, your address right, and a plausible reason to be calling about health coverage. That is what the data buys. Treat every one of those calls as hostile, and hang up on anyone who asks you to confirm a Medicare number.
You entered card details
Call the bank today. Report the charge as fraud and ask for the card to be replaced rather than only disputing the transaction, because the number is now in circulation. Then watch the statement for small recurring charges over the next few months.
You gave a Medicare number or a Social Security number
This is the one that takes longer to settle. Report it at IdentityTheft.gov, which generates a personalized recovery plan, and call your local Senior Medicare Patrol on 1-877-808-2468. Our step-by-step guide for an SSN given to a scammer covers the freeze-and-monitor sequence. Then read your Medicare Summary Notices when they arrive and question anything you do not recognize, because medical identity theft usually surfaces as a bill or a claim for care you never received.
The Medicare number, and the season ahead of us
Worth being precise here, because the two numbers get muddled. Medicare stopped putting Social Security numbers on cards years ago; the Medicare Beneficiary Identifier that replaced it is its own eleven-character string. Losing it is not the same as losing your SSN. It is still worth defending, because it is what a fraudulent provider needs to bill Medicare in your name.
The FTC’s May 2026 alert puts the scale of the problem at roughly $60 billion a year in Medicare losses from fraud, errors and abuse, and its first instruction is the one to carry into the autumn: never share your Medicare number with someone who contacts you unexpectedly. Medicare does not call or visit to sell you anything, and will only ask for information if you started the conversation.
Medicare Open Enrollment runs from 15 October to 7 December, and the FTC’s standing guidance is that scam activity climbs every year in that window. Expect the volume of health-branded mail, calls and texts to rise sharply over the next month, and expect at least some of it to be legitimate, which is what makes the period awkward. My read is that the portal lure has an obvious future here: an email claiming your MyChart plan review is due, or that your coverage options are waiting in the portal, lands in a season when a version of that message is genuinely arriving from several directions.
The rule holds anyway. Anything real about your coverage will be in the portal when you open it yourself, or on the phone number printed on your card.
Helping a parent who is already on the list
If you are reading this on someone else’s behalf, the useful move is not a lecture about phishing. It is a shorter conversation and one shared habit.
Send them the Epic page with the actual screenshots. Abstract warnings about phishing slide off; a picture of the exact email they received, published by the company that makes the software, does not. Then agree on one rule between you, out loud: nothing in a health message gets acted on from the message itself. Close it, open the app, look there.
Add a second habit if they will take it. Anything with a clock on it gets a phone call to you first. That single step breaks most of these funnels, because the whole design assumes nobody else is in the room. If the wider picture is what you need, we keep a longer guide to protecting older parents from scams, and the three calls that do the most damage to older adults are laid out on our page of warning signs worth taping up near the phone.
One thing to avoid: do not make them feel foolish for having opened it. Roughly forty health systems put out public notices about this campaign. That is not a message that only catches careless people.
What to do now
If nothing has happened yet, the whole job is one rule and one habit. MyChart does not give away products, and health messages get checked by opening the app rather than the message. Say the rule to whoever else in the house gets these emails, because a rule one person knows is not a household control.
If something has happened, work down the list in the previous section, and do the bank call first if a card was involved. Report the message to the FTC at ReportFraud.ftc.gov and tell your health system — several of the notices on Becker’s list exist because a patient picked up the phone and said something.
And if you run a practice or a clinic rather than receiving these, the other half of this is written for you: what to post, what to say at the front desk, and what to check when patients start calling.
The best time to meet this email is before it is real
ScamDrill sends your family safe, realistic practice scams — the portal email, the fake results notice, the “just cover shipping” offer — and turns each one into a 30-second lesson the moment somebody clicks. Nobody is graded and nobody is told off.
See how it works