The MyChart ‘Medicare Kit’ Scam: Six Screens, One Rule That Stops It

Cover graphic on a deep navy field. The headline reads The kit is free, the shipping is not, above the line a patient portal holds records, it does not run giveaways. To the right, a dark reward card labelled 2026 Medicare Health Kit shows $149 struck through in red beside a large amber $0, an amber countdown pill reading expires in 05:52, a shipping line of $13.77 in red, and a red claim reward button. An amber tag underneath reads no kit ever ships.

Bottom line up front

Emails and texts offering a free “2026 Medicare Health Kit” or a “senior health package” from MyChart are phishing, and they are not coming from your doctor’s office or from Epic. Becker’s has counted 41 health systems warning their patients about it, and Epic’s own security team has published the whole funnel, screen by screen. You do not need to recognize any of those screens. MyChart is a medical records portal and it does not run giveaways — that one fact rules out every version of this message, including the ones that have not been written yet.

A patient portal is an odd thing to be phished through, and that is exactly why it works. For fifteen years health systems have been telling people to stop calling the front desk and use the portal instead. Check your results there. Message your doctor there. Pay your bill there. Then one morning an email arrives with the MyChart name on it, and the habit that has been trained into you says: open it.

The version going around right now is the friendliest phishing email I have seen in a while. Nobody is arrested, nothing is overdue, no account is suspended. You have simply been selected for a free kit.

If one of these is on your screen right now

Short version first, in case you are mid-decision and the page has a clock on it.

  1. Do not click, and do not tap “unsubscribe” either. Both tell the sender the address is live, and unsubscribe links in phishing mail routinely lead somewhere worse than the original.
  2. Report it as junk or phishing in your mail app, then delete it. Epic points out that this is the single most useful thing a recipient can do, because it teaches the filter to catch the next one for everybody, not just for you.
  3. If you want to check whether something real is waiting, open MyChart the way you always do. The app on your phone, or your own bookmark. Never the link in the message.
  4. If you typed your name, address or phone into a form, nothing catastrophic has happened yet. Write down which fields you filled in. Expect calls and mail. Do not answer follow-up questions from anyone who rings about it.
  5. If you entered card details, call your bank today and ask for the card to be replaced. Not just a dispute on the one charge — a new number. Epic’s guidance says the same thing, and the reason is that the charge is designed to repeat.
  6. If a page told you to press keys — Windows key, then R, then Ctrl and V, then Enter — treat the computer as compromised. Disconnect it from the internet and get it looked at before you use it for banking, email or anything from work.

Definition

The MyChart “Medicare Kit” scam is a phishing campaign that borrows the MyChart name and logo to offer patients a free Medicare kit or senior wellness package. The link leads to a survey, then a small shipping fee, then a card form. No kit exists; the fee and the personal details are the product.

What is actually going on

Epic, the company behind MyChart, said in late July that it had seen a rise in scammers using the MyChart name and logo across email, text, phone calls and look-alike websites. The framing in that post matters: Trevor Berceau, Epic’s director of research and development, attributed the increase to scammers taking advantage of how well known the MyChart brand is rather than to any security problem, and told patients they can keep using MyChart normally.

That is worth sitting with for a second, because it changes what you should do about it. Nothing was broken into. Your records were not taken. Someone put a well-known logo on an email, which anyone can do, and sent it to a very large number of people.

The scale of the response is the surprising part. On 24 August the American Hospital Association carried the warning to its members. By 27 August, Becker’s had assembled a running list of 41 health systems that had posted notices or whose patients had reported the emails — Cleveland Clinic, Mass General Brigham, Mount Sinai, MD Anderson, Emory, Northwell, and a long tail of community hospitals in Iowa, Oregon, Washington and Georgia. The list started at 21 and Becker’s has been adding to it.

I read a lot of these notices while writing this. The one from UMass Memorial has a detail I liked, because it is the kind of thing only the organization itself would know: UMass Memorial brands its portal with a lowercase m, as myChart. An email that writes “MyChart” is, for their patients specifically, already suspect. That tell does not transfer anywhere else, which is sort of the point — the checks that work best are the ones that come from your own provider rather than from a general list of phishing advice.

The six screens, in order

Most write-ups of a phishing campaign stop at “don’t click the link.” Epic did something more useful: its security team walked the whole thing and published every screen, with annotations. If you have an older relative who does not believe an email can be fake when it looks that ordinary, that page is the thing to show them.

Here is the sequence.

Figure 01 · What the “free kit” email actually does
1THE EMAILSelected for a 2026 Medicare Health KitSometimes a delivery notice for a kit already on its way, sometimes athank-you to a valued member. The wording changes every time.2THE LINKA different web address for every recipientClicking it bounces through several unrelated advertising sites first.That is part of why the campaign is so hard to shut down.3THE SURVEYEasy questions, and a countdown clockA banner claims more than $300,000 in products already given away.The answers are never read — the reward is the same whatever youclick.4THE SWITCHA $149 value, now $0 — then a shipping feeThis is the hinge of the whole thing. Free becomes almost free, andalmost free needs a card. The “5 remaining” counter resets on reload.5THE FORMLOSS BEGINSName, email, phone, full mailing addressTaken the moment you type it, whether or not you ever pay. It is sold,and it feeds the next round of calls and mail.6THE PAYMENTTHE POINT$13.77, on yet another unrelated siteCard number, expiry, the three digits on the back. No kit ships. Thecharge is small on purpose, so it is easy to miss until it repeats.

Sequence and figures as documented by Epic security investigations, summer 2026, published on MyChart.org. Amber marks the attacker’s setup; red marks the point where information and money leave.

Two things in that flow deserve more than a box.

The countdown clock

The survey page carries a timer and a banner claiming that more than $300,000 in MyChart products have already been given away. Neither number is real, and the survey answers are never read — Epic notes that the same reward appears no matter what you click. The clock is not there to manage inventory. It is there to stop you doing the one thing that would end the whole attempt, which is pausing long enough to wonder why a hospital records system is running a sweepstake.

Urgency is the common thread through nearly every scam we write about here, from the fake arrest warrant to the utility shutoff call. It shows up in a friendly form here rather than a frightening one, but it is doing the same job.

The switch from free to almost free

This is the hinge. The kit is presented as a $149 value, now $0, with a few left in stock. You click to claim it, a pop-up confirms one has been reserved for you, and then a step appears that was never mentioned: the shipping fee. $13.77.

A prize you have to pay for is not a prize. And the amount is chosen with some care — small enough that arguing feels petty, small enough that it can sit on a statement for months without drawing a second look, small enough to repeat. The card details are what the whole funnel was built to reach.

The form before it is arguably worse, though, and it gets less attention. Before you can pay, the page collects your full name, email address, phone number and mailing address, behind a reassuring padlock and a “256 bit encrypted” badge. Epic’s note on this is blunt: that information is taken the moment you type it, whether or not you ever complete the payment. Encryption only means nobody could read your details on the way to the scammer.

So a person who filled in the form, felt uneasy at the card page and closed the tab has not escaped. They have handed over a verified name-address-phone-email set attached to a person who is on Medicare and responds to health offers. That is a good lead, and it gets sold.

Why the portal is a hard brand to doubt

Think about what a patient portal has spent a decade teaching you.

It sends you email you did not ask for, and those emails are legitimate. It tells you a message is waiting without saying what it is, so vagueness is normal. It asks you to log in, frequently. It is where genuinely important news arrives — results, referrals, a change to a prescription. And it is operated by an organization you already trust with considerably more than your email address.

Every one of those trained reflexes is useful to an attacker. Compare it with a bank, where most people have absorbed the rule that the bank never emails asking you to log in. There is no equivalent folk rule for the portal, because the portal does email you asking you to log in. That is what it does all day.

The other thing working in the attacker’s favor is list quality. You do not need a health system to be breached to guess that a 70-year-old has a MyChart account; roughly everyone does. But the last two years have also put an enormous volume of genuinely health-adjacent contact data into criminal hands — the Exact Sciences breach alone indexed 10.9 million email addresses belonging to people who had used a cancer screening test. Nobody needs to know your diagnosis to send you this email. They only need to know you are the kind of person who opens health mail.

Not sure about an email that is sitting in your inbox?

Paste it into the free ScamDrill email scam checker and get an instant read on the sender, the links and the language. Nothing is stored, and you do not need an account.

Check an email

The other campaign wearing the same name

The Medicare Kit is the one making the news, because it is the one that generates phone calls to hospital switchboards. Running alongside it is a second campaign that is quieter and considerably more dangerous, and Epic documented that one too.

It starts with an email saying your recent results are ready. MyChart logo, a sign-in button. The button goes to a copy of the MyChart login page — the scammers lifted the real site’s code, so it is not an approximation — at an address like mychart-epic or my-chart, close enough to the real thing to survive a glance. You enter your email, then your password.

Then you are shown a chart. The name, birthday and patient number on it are invented. A pop-up announces that an “AI-powered review” has found critical patterns in your blood work requiring immediate attention.

And then, to see the results, you are asked to prove you are human. The page says a verification code has been copied for you, and walks you through three keystrokes: hold Windows, press R; press Ctrl and V; press Enter.

This is the attack

Those three keystrokes open the Windows Run box, paste in whatever the page quietly put on your clipboard, and execute it. Nothing visible happens afterwards. The technique is called ClickFix, and we wrote about it in detail when it was mostly showing up as a fake CAPTCHA. No real website has ever needed you to press keyboard shortcuts to prove you are a person.

In August, Epic saw the same fake site with the ending swapped out. This time the fake chart shows a table of alarming lab values with some of them redacted, and a button promising to reveal the full report. The button downloads a program, Full_Analysis_Report.exe, and the page then coaches you past your own computer’s security warning — click “More info,” then “Run anyway.”

Lab results live in MyChart. They do not arrive as a program you download. And a page telling you to click through a Windows security warning is asking you to ignore the one thing on the screen that was on your side.

Five rules that survive the next redesign

The wording of these emails changes constantly. Epic notes that within one two-week window, patients reported a congratulations letter, a delivery notice for a kit already on its way, and a plain thank-you to a valued member — all the same campaign. Advice pinned to the specific wording goes stale in a two weeks. These do not.

Figure 02 · Five rules, none of which require spotting a fake
1RULE 1 · THE ONE THAT DOES THE WORKA portal holds records. It runs no giveaways.MyChart has no prizes, no kits and no senior wellness packages. Anemail where MyChart is giving you a product is fake on that basisalone.2RULE 2 · EPICNobody asks for your password or login codeNot by phone, not by text, not by email. The only safe place to typeeither one is the MyChart app or your organization’s own MyChartsite.3RULE 3 · EPICNo real page asks you to press keyboard shortcutsA site that walks you through Windows-key R, Ctrl-V, Enter is notverifying you. It is running a command on your machine.4RULE 4 · FTCMedicare does not call you firstMedicare will not phone or visit to sell you anything, and asks for yournumber only when you made contact. Report fraud on1-877-808-2468.5RULE 5 · THE HABIT UNDERNEATHOpen the app, not the messageIf a health message might be real, close it and open MyChart the wayyou always do. Anything genuine is waiting for you there.

Rules 1–3 and 5 per Epic’s MyChart guidance on scams and fraud; rule 4 per the FTC consumer alert of 28 May 2026 and Medicare.gov. Senior Medicare Patrol: 1-877-808-2468.

Rule one carries most of the weight, and it is the only one worth memorising if you are going to memorise one. A records portal has no reason to give you a product. There is no scenario in which Epic is running a giveaway, and there is no health system that will mail you a wellness package because you answered four survey questions. So the moment a message combines the words MyChart and free, you are done thinking about it. You do not have to examine the sender address or hover the link or squint at the grammar, all of which an attacker can fix.

One more small detail from Epic’s teardown that I keep coming back to: the fine print on the Medicare Kit email signs off as “MyChart Health Network,” at an address in Verona, Wisconsin. There is no such company, and the address is wrong — but Verona is where Epic’s campus actually is. Somebody did research, got close, and still could not make it land. Fake mail is often like that. Not obviously wrong, just faintly off, in a way you would only catch if you already suspected something.

If you already clicked, filled in a form, or paid

Take this in the order that matters, not the order of how bad it feels.

You clicked but entered nothing

You are almost certainly fine. Close the page. Do not reply and do not unsubscribe. Report the message as phishing in your mail app and delete it.

You entered a MyChart password

Change it now, at your health system’s real MyChart site or in the app. If you reused that password anywhere else — and most people have, at least once — change it there too, starting with email. Then open MyChart and check the email address and phone number on file, because changing those is how someone keeps access after you reset the password.

You filled in name, address and phone

No account was taken, so treat this as information loss rather than a break-in. Write down exactly which fields you completed. Then tell whoever else needs to know, because the practical consequence is a wave of calls and mail that will sound informed — the caller will have your name right, your address right, and a plausible reason to be calling about health coverage. That is what the data buys. Treat every one of those calls as hostile, and hang up on anyone who asks you to confirm a Medicare number.

You entered card details

Call the bank today. Report the charge as fraud and ask for the card to be replaced rather than only disputing the transaction, because the number is now in circulation. Then watch the statement for small recurring charges over the next few months.

You gave a Medicare number or a Social Security number

This is the one that takes longer to settle. Report it at IdentityTheft.gov, which generates a personalized recovery plan, and call your local Senior Medicare Patrol on 1-877-808-2468. Our step-by-step guide for an SSN given to a scammer covers the freeze-and-monitor sequence. Then read your Medicare Summary Notices when they arrive and question anything you do not recognize, because medical identity theft usually surfaces as a bill or a claim for care you never received.

The Medicare number, and the season ahead of us

Worth being precise here, because the two numbers get muddled. Medicare stopped putting Social Security numbers on cards years ago; the Medicare Beneficiary Identifier that replaced it is its own eleven-character string. Losing it is not the same as losing your SSN. It is still worth defending, because it is what a fraudulent provider needs to bill Medicare in your name.

The FTC’s May 2026 alert puts the scale of the problem at roughly $60 billion a year in Medicare losses from fraud, errors and abuse, and its first instruction is the one to carry into the autumn: never share your Medicare number with someone who contacts you unexpectedly. Medicare does not call or visit to sell you anything, and will only ask for information if you started the conversation.

$60 billion Estimated annual cost to taxpayers of Medicare losses from fraud, errors and abuse. Source: FTC consumer alert, 28 May 2026.

Medicare Open Enrollment runs from 15 October to 7 December, and the FTC’s standing guidance is that scam activity climbs every year in that window. Expect the volume of health-branded mail, calls and texts to rise sharply over the next month, and expect at least some of it to be legitimate, which is what makes the period awkward. My read is that the portal lure has an obvious future here: an email claiming your MyChart plan review is due, or that your coverage options are waiting in the portal, lands in a season when a version of that message is genuinely arriving from several directions.

The rule holds anyway. Anything real about your coverage will be in the portal when you open it yourself, or on the phone number printed on your card.

Helping a parent who is already on the list

If you are reading this on someone else’s behalf, the useful move is not a lecture about phishing. It is a shorter conversation and one shared habit.

Send them the Epic page with the actual screenshots. Abstract warnings about phishing slide off; a picture of the exact email they received, published by the company that makes the software, does not. Then agree on one rule between you, out loud: nothing in a health message gets acted on from the message itself. Close it, open the app, look there.

Add a second habit if they will take it. Anything with a clock on it gets a phone call to you first. That single step breaks most of these funnels, because the whole design assumes nobody else is in the room. If the wider picture is what you need, we keep a longer guide to protecting older parents from scams, and the three calls that do the most damage to older adults are laid out on our page of warning signs worth taping up near the phone.

One thing to avoid: do not make them feel foolish for having opened it. Roughly forty health systems put out public notices about this campaign. That is not a message that only catches careless people.

What to do now

If nothing has happened yet, the whole job is one rule and one habit. MyChart does not give away products, and health messages get checked by opening the app rather than the message. Say the rule to whoever else in the house gets these emails, because a rule one person knows is not a household control.

If something has happened, work down the list in the previous section, and do the bank call first if a card was involved. Report the message to the FTC at ReportFraud.ftc.gov and tell your health system — several of the notices on Becker’s list exist because a patient picked up the phone and said something.

And if you run a practice or a clinic rather than receiving these, the other half of this is written for you: what to post, what to say at the front desk, and what to check when patients start calling.

The best time to meet this email is before it is real

ScamDrill sends your family safe, realistic practice scams — the portal email, the fake results notice, the “just cover shipping” offer — and turns each one into a 30-second lesson the moment somebody clicks. Nobody is graded and nobody is told off.

See how it works

Frequently asked questions

Is the MyChart ‘Medicare Kit’ email real?

No. It is a phishing campaign that borrows the MyChart name and logo, and it does not come from Epic or from your health system. Epic's position is that the rise in these messages reflects scammers taking advantage of how well known the MyChart brand is rather than any security problem with the portal itself, so patients can keep using MyChart normally. By late August 2026, Becker's had counted 41 health systems posting warnings about it, from Cleveland Clinic and Mount Sinai down to single-site community hospitals.

Was my health data stolen in this?

Not through this campaign. Nothing was broken into and no records were taken. What is happening is that a familiar logo has been put on an email and sent very widely, which requires no access to anything. The information at risk is whatever you type into the fake pages: your name, address, phone number, email, card details, and in some versions a MyChart password. If you did not enter anything, you are almost certainly fine.

I filled in the form but closed the page before paying. Am I safe?

You are not exposed financially, but the personal details are gone. Epic's teardown is explicit that the form harvests what you type as you type it, whether or not the payment is ever completed, and that the full set — name, home address, phone and email — is sold and reused for later scam calls and mail. The practical consequence is that the next approach will sound informed, because it will have your details right. Treat any call about a Medicare kit, a health package or a coverage review as hostile.

A page told me to press Windows key, R, then Ctrl and V, then Enter. What happened?

Those keystrokes opened the Windows Run box, pasted in a command the page had quietly copied to your clipboard, and ran it. Nothing appears to happen afterwards, which is the point. Disconnect that computer from the internet and have it looked at before using it for banking, email or work. This technique is called ClickFix and it shows up in several campaigns, most commonly as a fake human-verification check. No legitimate website has ever needed keyboard shortcuts to confirm you are a person.

Why is $13.77 such a small amount to ask for?

Because small charges do not get argued with, and they do not get noticed. The figure is low enough that disputing it feels like more trouble than it is worth, low enough to sit unread on a statement for months, and low enough that a repeat or a slow escalation goes unchallenged. The fee is not really the revenue anyway — the card number is. If you entered card details, ask your bank to replace the card rather than only disputing the one transaction.

How do I tell a real MyChart message from a fake one?

Stop trying to tell them apart in the message, because everything visible there can be copied and the wording changes constantly. Use two habits instead. First, a records portal does not give away products, so any message combining MyChart with a free kit, prize or wellness package is settled before you examine anything else. Second, if a health message might be genuine, close it and open MyChart the way you always do — the app, or your own bookmark. Anything real is waiting for you there.

Does Medicare ever contact you about a free kit or a benefit?

Medicare does not call or visit to sell you anything, and will only ask for your information if you contacted them first. That single rule handles most of what arrives during Open Enrollment, which runs from 15 October to 7 December and is reliably the busiest stretch of the year for this kind of fraud. If you suspect Medicare fraud, call your local Senior Medicare Patrol on 1-877-808-2468 or Medicare on 1-800-MEDICARE, and report the message at ReportFraud.ftc.gov.