MyChart Phishing: When the Attack Targets Your Patients, Not Your Network
Bottom line up front
Two phishing campaigns wearing MyChart’s name are running right now, and by 27 August Becker’s counted 41 health systems that had posted patient warnings about one of them. Neither campaign touches your network, your Epic build, or a single record you hold — which is the hard part, because there is nothing in your security stack for this to hit. What you control is whether a patient can tell your real message from the fake one, what the front desk says when the calls start, and whether the staff member who opens the same email at work knows to stop.
Look at the screenshots Epic published before you read anything else. A patient lands on a page with their portal’s layout, their portal’s logo, their portal’s shade of blue. A panel slides up to say an “AI-powered review” has found critical patterns in their blood work that need immediate attention. The name on the chart is invented. The date of birth is invented. The lab values are invented. The urgency is the only real thing on the screen, and it is enough, because a person who has just been told something is wrong with their blood will do the next thing they are told to do.
The next thing they are told to do is hold the Windows key, press R, then Ctrl and V, then Enter.
Those three keystrokes open a command box, paste in whatever the page quietly put on the clipboard, and run it. Security teams have been watching that technique — ClickFix — move through fake CAPTCHA pages and bogus browser updates for a while now. This is the first time I have seen it dressed as a lab result.
Epic put that walkthrough on the public MyChart site, alongside a second campaign offering a free “2026 Medicare Health Kit,” and the American Hospital Association carried it as a headline on 24 August. Three days later, Becker’s was tracking 41 health systems that had warned patients or whose patients had reported the emails — Mass General Brigham, Cleveland Clinic and MD Anderson at one end of the list, Van Buren County Hospital in Keosauqua, Iowa at the other.
If you run a practice, a clinic, or a small system on Epic, some of your patients have already received one of these. Some of them have already called. And there is nothing on your network to fix.
The first 72 hours, in order
If the phones have already started, this is the sequence that helps. If they haven’t, this is what you want written down before they do.
- Say something before you have all the answers. Patients are not waiting for your investigation to close. Virtua Health’s notice went up on 26 August with the sentence that does the most work: “there is no sign that Virtua or MyChart has been hacked.” That answers the question the patient actually has, which is not “what are the red flags” but “did somebody get my chart.”
- Put it where patients already are. The portal login screen, the top of the website, the hold message on the main line. A press release nobody visits is not a control.
- Give one instruction, not six. Every notice in that list of 41 carries roughly the same advice — check the sender, watch for typos, be wary of free offers. It’s fine advice. But the instruction that survives a worried 74-year-old is shorter: open the app, or the bookmark you already have. Never the link in the message.
- Brief the phones before you publish, not after. Whoever answers is about to have the same conversation forty times in a week. If they are improvising, some of them will improvise badly. There’s a script further down.
- Warn staff in the same breath. The lure that promises lab results works fine on the person who schedules the lab results, and their machine is on your network.
- Check whether anything actually happened on your side. Portal sign-ins from new geographies, a spike in password resets, failed-login patterns against the portal, and endpoint alerts for a command shell or PowerShell spawned by a browser process. You are not hunting the campaign. You are hunting the use of whatever it collected.
- Write down the notification decision early, with counsel. Not because it’s a close call — see the next section — but because somebody will eventually ask, and “we considered it on 31 August and here is the reasoning” is a much better answer than reconstructing it in November.
- Log every report. Which patient called, what the message said, which address it pointed at. That log is the only visibility you get into a campaign running entirely outside your walls, and it is what you hand your registrar when you ask for a takedown.
What patient portal phishing is
Patient portal phishing impersonates a health system’s portal — its name, logo, and message style — to reach patients directly by email, text, or phone. The attacker never enters the provider’s network. The borrowed brand does the persuading, and the credentials, card details, or malware land on the patient’s own device.
Two campaigns, two endings, one logo
Epic’s security team published both, with screenshots, on the MyChart help site, describing them as examples from its own investigations over the summer. It is an unusually candid piece of writing for a vendor, and it is the best primary source available on either campaign. Both start the same way and end somewhere very different.
Stages assembled from Epic’s published MyChart security walkthroughs (summer 2026), the American Hospital Association headline of 24 August 2026, and Becker’s Hospital Review, 27 August 2026. Compiled by ScamDrill, August 2026.
Ending A: the results that are not yours
It opens as a “your recent results are ready” email carrying the MyChart logo and a sign-in button. The button does not go to MyChart. It goes to a copy of the sign-in page — Epic says the attackers lifted the real site’s code — hosted at addresses like mychart-epic[.]com, with the browser bar in Epic’s screenshot reading my-chart[.]org. One hyphen, one character of difference, and a page that is pixel-correct because it is literally the same markup.
Enter an email address and password there and you land on a fake chart with an invented name, birthday and patient number, and then the pop-up about the AI review of your blood work. Then the human-verification step, which is not verification at all. Then the keystrokes.
Epic notes that in August the same fake site appeared with a different last step: a table of alarming lab values, some of them redacted, behind an “Unlock Full Report & See Diagnosis” button that downloads a file called Full_Analysis_Report.exe. The page then coaches the patient through their own operating system’s warning — click “More info,” then “Run anyway.” Epic’s framing of that is the line worth stealing for your own patient-facing copy: a page that tells you to click past a security warning is telling you to ignore the one thing trying to protect you.
Ending B: the kit that does not exist
This is the one the 41 notices are about. Subject lines vary — “Your MyChart Medicare Kit Awaits!” is the common one, and Texas Health Resources warned patients about a “Senior Health Package” variant. Epic says the wording changed every time and that real patients reported these inside a two-week window.
The link text often reads mychart.org. Hovering shows something else. Clicking passes through several unrelated advertising sites before the destination loads, and per Epic the final address is different for every recipient — which is exactly why takedown requests lag the campaign instead of ending it.
The destination is a survey page with the portal logo, today’s date, a banner claiming more than $300,000 in products has already been given away, and a countdown clock. Epic’s read on that clock is the sharpest observation in the whole writeup: nothing real expires in six minutes, and the timer exists solely to stop the reader pausing long enough to ask whether any of this makes sense.
Then the kit is a $149 value, now $0, only a few left, reserved exclusively for you — and a shipping fee appears that was never mentioned. $13.77. Before the payment form there is a details form asking for name, email, phone and full mailing address, under a “Secure 256 Bit Encrypted Connection” badge. Epic points out the obvious thing about that badge: encryption only guarantees nobody read your details on the way to the criminal. Everything typed there is stolen whether or not the reader ever reaches the card page, which sits on a third site and offers a $2.87 discount for paying by Mastercard.
The small print signs off as “MyChart Health Network” at an address in Verona, Wisconsin — Epic’s own town, which is the detail that says somebody did a little homework. Epic’s response: “There is no such company, and the address is wrong.”
It is not your breach. That is the awkward part.
Nobody has said publicly how the operators built their target list. The HIPAA Journal’s read, the most careful I have seen, is that the addresses most likely came from a prior data breach — and not necessarily one at the patient’s own provider. Which means the answer to “where did they get my email” may have nothing to do with you, and you will still be the one asked.
It has been a rough year for that particular question in healthcare. In early August, 10.9 million email addresses from the Abbott / Exact Sciences breach were published with names, dates of birth and health data attached. I am not claiming that is the list behind this campaign — nobody has traced it, and I would not guess — but it is a fair illustration of what is available to anyone who wants to write a plausible email to a Medicare-aged patient this month.
Epic’s own position is that the spike reflects scammers “taking advantage of the popularity of the MyChart brand” rather than any security problem. That is a self-interested thing for a vendor to say, and it also appears to be true: forty-one health systems hit simultaneously with no common intrusion is the signature of a brand campaign, not a compromise.
Which brings up the question every compliance officer asks first. Generally, a reportable breach under the HIPAA Breach Notification Rule turns on an impermissible acquisition, access, use or disclosure of protected health information held by a covered entity or its business associate. A third party impersonating your brand, using contact data it obtained somewhere else, to phish people who happen to be your patients, does not on its own put PHI you held into anyone’s hands. So there is usually no notification obligation here, no 60-day clock, no OCR portal entry.
Where that gets less comfortable
I am not a lawyer and this is not legal advice — run it past counsel, particularly if any of your systems show signs of being touched, if the harvested credentials were used to reach real charts, or if the list plausibly traces to something you hold. State breach and consumer-protection law can also reach further than HIPAA does. The broader point is that “no obligation” cuts both ways: the notification rules exist partly as a forcing function, and here there isn’t one. Nothing compels you to act except the patients on the phone.
That 89% is the number I would put in front of a board. Patient portal adoption did not happen by itself — providers pushed it, deliberately and successfully, and the federal data shows the push worked. Encouraged patients access their records at 87%; unencouraged patients at 57%. The 51% proxy figure matters too, because the adult daughter checking her mother’s chart is exactly the reader a “Medicare Kit” email is written for.
The trust this campaign is spending is trust you built on purpose.
Your staff got the same email
Everyone in your building is somebody’s patient. The results lure does not know or care that the reader works in your billing office, and a fair number of people check personal email at work.
The difference is the endpoint. A patient who runs Full_Analysis_Report.exe has a bad week and a trip to a repair shop. A scheduler who runs it on a domain-joined workstation has handed someone a foothold inside a network that holds charts. Same lure, same three keystrokes, wildly different blast radius — and this is the shape of most of the healthcare incidents worth studying from the past year, including the 2026 medtech wave, where the only publicly confirmed initial-access vectors were all somebody being talked into something.
The credential half deserves a note too. Epic describes a copied sign-in page rather than a live relay, which is a lower bar to build and does not defeat MFA by itself — but it still gets a password, and password reuse between a patient portal and a work account is not a hypothetical. If you want the version of this that does walk through ordinary MFA, that is adversary-in-the-middle phishing, and it is the same afternoon’s work for the same crews.
Three cheap controls do most of the useful work: block newly registered domains at the DNS resolver, alert on cmd.exe or powershell.exe spawned by a browser process, and make sure your endpoint policy blocks unsigned browser downloads on clinical workstations rather than merely warning about them. If you have no IT team, our practice-sized ransomware guide covers the same ground at that scale.
Five moves you actually control
You cannot patch someone else’s use of your logo. You can change the odds that a patient recognises the difference, and you can shorten the gap between the first report and a coherent response.
Compiled by ScamDrill, August 2026, from the patient guidance published by Epic and by the health systems issuing notices, mapped to the control that owns each step inside a provider organisation.
1. Make your real mail boring and predictable
A patient can only spot the fake if the genuine article is dull enough to recognise. One sending domain. One link pattern. No attachments. No offers, no giveaways, no urgency language, no “limited time” anything, ever — because the moment your marketing team sends one promotional-looking message from the portal, you have taught your patients that the fake ones are plausible. This is a governance decision more than a technical one, and it usually needs somebody senior to say no to a campaign.
2. Publish one page that answers “is this real?”
Short URL. Linked from the portal login screen. Updated in place when the next campaign lands rather than replaced with a new address, so the link you gave a patient in August still works in March. Staff should be able to say it out loud on the phone without spelling anything. Almost every organisation on the Becker’s list built one of these last week; the ones who will be glad in six months are the ones who built it at a permanent address.
3. Give the front desk a script, not a policy
Two sentences and one instruction, rehearsed before the volume arrives. There’s a starting version in the next section.
4. Watch the name, not only the network
Look-alike domain monitoring on your organisation’s name and your portal’s subdomain, plus DMARC at p=reject on every domain you own — including the parked ones nobody gets round to. Honestly, the limits here are real: this campaign did not spoof anyone’s domain, and monitoring will not buy fast takedowns when the destination rotates per recipient. It catches the next crew, who will be lazier.
5. Drill the version aimed at your own people
Not a slide deck. An actual email, in the inbox, on a Tuesday, that looks like the thing that is circulating — and a landing page that teaches instead of scolds. The number you want is not the click rate. It is the report rate, and whether it went up after the last round.
Your patients got the email. So did your schedulers.
ScamDrill runs email phishing simulations for organisations, including healthcare-flavoured lures like the one circulating now, so you find out who clicks before somebody with a payload does.
See how organisation drills workWhat the front desk should say
Six calls cover most of the volume. Adapt the wording to your own voice, but keep the structure: name the situation, remove the blame, give one action. The right-hand column is there because the wrong answer to a worried patient is usually a hedge.
| The patient says | Say this | Not this |
|---|---|---|
| “I got an email about a free Medicare kit.” | That one is fake and it is going around the whole country. Please delete it without clicking anything, including unsubscribe. Nothing was taken from us and nothing has happened to your chart. | “Let me check whether that came from us.” It didn’t, and the hedge tells them it might have. |
| “I clicked the link but I didn’t type anything.” | Then you are most likely fine. Close the page and don’t go back to it. Don’t click unsubscribe — that only confirms your address is real. | “You should be OK.” Vague reassurance without the unsubscribe warning invites the second mistake. |
| “I typed my portal password in.” | Change your portal password now, from the app or your own bookmark rather than any link. If you use that password anywhere else, change it there too. I’ll flag your account for our team. | “We’ll reset it for you.” Do it if you can, but the reused-password question is the one that matters more. |
| “I gave them my card details.” | Call the number on the back of your card, report it as fraud, and ask for a replacement card — not just a dispute on the one charge. | “Dispute the charge.” A small charge that repeats is the actual business model. |
| “They had me run something on my computer.” | Disconnect that computer from the internet and have someone look at it before you use it for banking, email or anything medical. | “Run a virus scan.” Not wrong, but it is the wrong first move and it keeps the machine online. |
| “Is my medical record safe?” | Yes. There is no sign our systems or the portal were breached. This is people using our name from the outside, which is why the message came to your personal email and not through the portal. | “We’re investigating.” True and useless. Say the specific reassuring thing you can actually stand behind. |
Have somewhere to send the patient afterwards, too. Our link checker is free and needs no account, and for the older patients generating most of these calls, the warning signs worth taping next to the phone is a printable page you can hand over at the desk.
The part that lingers
This campaign will burn out. Most do. The pattern behind it will not, because brand impersonation is the cheapest attack available in healthcare: the trust is already built, the audience is already trained, and the attacker does not have to breach anything to spend either one. My read is that the next round wears a payer’s name, or a national lab’s, or yours — and lands on the same patients, who by then have been told twice that free health kits are a scam and once that their results are ready.
Which is the argument for building the page and the script now rather than during the next one. The second time you do this, the only new thing should be the name of the brand being borrowed. For the wider picture, our healthcare overview covers where drills sit alongside the technical controls, and the help-desk vishing playbook covers the version of all this that arrives by phone.