MyChart Phishing: When the Attack Targets Your Patients, Not Your Network

Cover graphic on a deep navy field reading 41 health systems, one borrowed logo, above a browser address bar showing the look-alike domain mychart-epic[.]com in amber, tagged not your domain.

Bottom line up front

Two phishing campaigns wearing MyChart’s name are running right now, and by 27 August Becker’s counted 41 health systems that had posted patient warnings about one of them. Neither campaign touches your network, your Epic build, or a single record you hold — which is the hard part, because there is nothing in your security stack for this to hit. What you control is whether a patient can tell your real message from the fake one, what the front desk says when the calls start, and whether the staff member who opens the same email at work knows to stop.

Look at the screenshots Epic published before you read anything else. A patient lands on a page with their portal’s layout, their portal’s logo, their portal’s shade of blue. A panel slides up to say an “AI-powered review” has found critical patterns in their blood work that need immediate attention. The name on the chart is invented. The date of birth is invented. The lab values are invented. The urgency is the only real thing on the screen, and it is enough, because a person who has just been told something is wrong with their blood will do the next thing they are told to do.

The next thing they are told to do is hold the Windows key, press R, then Ctrl and V, then Enter.

Those three keystrokes open a command box, paste in whatever the page quietly put on the clipboard, and run it. Security teams have been watching that technique — ClickFix — move through fake CAPTCHA pages and bogus browser updates for a while now. This is the first time I have seen it dressed as a lab result.

Epic put that walkthrough on the public MyChart site, alongside a second campaign offering a free “2026 Medicare Health Kit,” and the American Hospital Association carried it as a headline on 24 August. Three days later, Becker’s was tracking 41 health systems that had warned patients or whose patients had reported the emails — Mass General Brigham, Cleveland Clinic and MD Anderson at one end of the list, Van Buren County Hospital in Keosauqua, Iowa at the other.

If you run a practice, a clinic, or a small system on Epic, some of your patients have already received one of these. Some of them have already called. And there is nothing on your network to fix.

The first 72 hours, in order

If the phones have already started, this is the sequence that helps. If they haven’t, this is what you want written down before they do.

  1. Say something before you have all the answers. Patients are not waiting for your investigation to close. Virtua Health’s notice went up on 26 August with the sentence that does the most work: “there is no sign that Virtua or MyChart has been hacked.” That answers the question the patient actually has, which is not “what are the red flags” but “did somebody get my chart.”
  2. Put it where patients already are. The portal login screen, the top of the website, the hold message on the main line. A press release nobody visits is not a control.
  3. Give one instruction, not six. Every notice in that list of 41 carries roughly the same advice — check the sender, watch for typos, be wary of free offers. It’s fine advice. But the instruction that survives a worried 74-year-old is shorter: open the app, or the bookmark you already have. Never the link in the message.
  4. Brief the phones before you publish, not after. Whoever answers is about to have the same conversation forty times in a week. If they are improvising, some of them will improvise badly. There’s a script further down.
  5. Warn staff in the same breath. The lure that promises lab results works fine on the person who schedules the lab results, and their machine is on your network.
  6. Check whether anything actually happened on your side. Portal sign-ins from new geographies, a spike in password resets, failed-login patterns against the portal, and endpoint alerts for a command shell or PowerShell spawned by a browser process. You are not hunting the campaign. You are hunting the use of whatever it collected.
  7. Write down the notification decision early, with counsel. Not because it’s a close call — see the next section — but because somebody will eventually ask, and “we considered it on 31 August and here is the reasoning” is a much better answer than reconstructing it in November.
  8. Log every report. Which patient called, what the message said, which address it pointed at. That log is the only visibility you get into a campaign running entirely outside your walls, and it is what you hand your registrar when you ask for a takedown.

What patient portal phishing is

Patient portal phishing impersonates a health system’s portal — its name, logo, and message style — to reach patients directly by email, text, or phone. The attacker never enters the provider’s network. The borrowed brand does the persuading, and the credentials, card details, or malware land on the patient’s own device.

Two campaigns, two endings, one logo

Epic’s security team published both, with screenshots, on the MyChart help site, describing them as examples from its own investigations over the summer. It is an unusually candid piece of writing for a vendor, and it is the best primary source available on either campaign. Both start the same way and end somewhere very different.

Figure 01 · Two endings, one logo
1STAGE 1 · THE LISTAn address that never came from youThe message arrives because a contact list was bought or breachedsomewhere else. Epic and the health systems posting notices both saythere is no sign either was hacked.2STAGE 2 · THE NAMEYour portal’s logo, your patient’s inbox“Your recent results are ready.” Or “Your MyChart Medicare Kit Awaits!”Nothing in the message belongs to you. All of it looks like it does.3STAGE 3 · THE PAGEA domain one hyphen away from realmychart-epic[.]com. my-chart[.]org. Or a chain of ad redirects with adifferent address for every recipient, which is why takedowns lag thecampaign.TWO ENDINGS, ONE LOGO4ENDING A · THE FAKE CHART“Run this to unlock your results”A pop-up claims an AI review found critical patterns in the blood work.Three keystrokes, or one downloaded .exe, and malware is on thepatient’s computer.5ENDING B · THE FREE KIT$149 value, now $0 — just cover shippingA countdown clock, a survey nobody reads, then name, address, phoneand card details typed across three different sites. No kit ever ships.

Stages assembled from Epic’s published MyChart security walkthroughs (summer 2026), the American Hospital Association headline of 24 August 2026, and Becker’s Hospital Review, 27 August 2026. Compiled by ScamDrill, August 2026.

Ending A: the results that are not yours

It opens as a “your recent results are ready” email carrying the MyChart logo and a sign-in button. The button does not go to MyChart. It goes to a copy of the sign-in page — Epic says the attackers lifted the real site’s code — hosted at addresses like mychart-epic[.]com, with the browser bar in Epic’s screenshot reading my-chart[.]org. One hyphen, one character of difference, and a page that is pixel-correct because it is literally the same markup.

Enter an email address and password there and you land on a fake chart with an invented name, birthday and patient number, and then the pop-up about the AI review of your blood work. Then the human-verification step, which is not verification at all. Then the keystrokes.

Epic notes that in August the same fake site appeared with a different last step: a table of alarming lab values, some of them redacted, behind an “Unlock Full Report & See Diagnosis” button that downloads a file called Full_Analysis_Report.exe. The page then coaches the patient through their own operating system’s warning — click “More info,” then “Run anyway.” Epic’s framing of that is the line worth stealing for your own patient-facing copy: a page that tells you to click past a security warning is telling you to ignore the one thing trying to protect you.

Ending B: the kit that does not exist

This is the one the 41 notices are about. Subject lines vary — “Your MyChart Medicare Kit Awaits!” is the common one, and Texas Health Resources warned patients about a “Senior Health Package” variant. Epic says the wording changed every time and that real patients reported these inside a two-week window.

The link text often reads mychart.org. Hovering shows something else. Clicking passes through several unrelated advertising sites before the destination loads, and per Epic the final address is different for every recipient — which is exactly why takedown requests lag the campaign instead of ending it.

The destination is a survey page with the portal logo, today’s date, a banner claiming more than $300,000 in products has already been given away, and a countdown clock. Epic’s read on that clock is the sharpest observation in the whole writeup: nothing real expires in six minutes, and the timer exists solely to stop the reader pausing long enough to ask whether any of this makes sense.

Then the kit is a $149 value, now $0, only a few left, reserved exclusively for you — and a shipping fee appears that was never mentioned. $13.77. Before the payment form there is a details form asking for name, email, phone and full mailing address, under a “Secure 256 Bit Encrypted Connection” badge. Epic points out the obvious thing about that badge: encryption only guarantees nobody read your details on the way to the criminal. Everything typed there is stolen whether or not the reader ever reaches the card page, which sits on a third site and offers a $2.87 discount for paying by Mastercard.

The small print signs off as “MyChart Health Network” at an address in Verona, Wisconsin — Epic’s own town, which is the detail that says somebody did a little homework. Epic’s response: “There is no such company, and the address is wrong.”

It is not your breach. That is the awkward part.

Nobody has said publicly how the operators built their target list. The HIPAA Journal’s read, the most careful I have seen, is that the addresses most likely came from a prior data breach — and not necessarily one at the patient’s own provider. Which means the answer to “where did they get my email” may have nothing to do with you, and you will still be the one asked.

It has been a rough year for that particular question in healthcare. In early August, 10.9 million email addresses from the Abbott / Exact Sciences breach were published with names, dates of birth and health data attached. I am not claiming that is the list behind this campaign — nobody has traced it, and I would not guess — but it is a fair illustration of what is available to anyone who wants to write a plausible email to a Medicare-aged patient this month.

Epic’s own position is that the spike reflects scammers “taking advantage of the popularity of the MyChart brand” rather than any security problem. That is a self-interested thing for a vendor to say, and it also appears to be true: forty-one health systems hit simultaneously with no common intrusion is the signature of a brand campaign, not a compromise.

Which brings up the question every compliance officer asks first. Generally, a reportable breach under the HIPAA Breach Notification Rule turns on an impermissible acquisition, access, use or disclosure of protected health information held by a covered entity or its business associate. A third party impersonating your brand, using contact data it obtained somewhere else, to phish people who happen to be your patients, does not on its own put PHI you held into anyone’s hands. So there is usually no notification obligation here, no 60-day clock, no OCR portal entry.

Where that gets less comfortable

I am not a lawyer and this is not legal advice — run it past counsel, particularly if any of your systems show signs of being touched, if the harvested credentials were used to reach real charts, or if the list plausibly traces to something you hold. State breach and consumer-protection law can also reach further than HIPAA does. The broader point is that “no obligation” cuts both ways: the notification rules exist partly as a forcing function, and here there isn’t one. Nothing compels you to act except the patients on the phone.

89% of patients offered online access to their records say their provider encouraged them to use the portal. Nearly two-thirds of adults (65%) now access their records online, and caregiver or proxy access has doubled since 2020, to 51%. Source: ASTP/ONC Health IT Data Brief 77, “Individuals' Access and Use of Patient Portals and Smartphone Health Apps, 2024” (HINTS 7, n=7,278).

That 89% is the number I would put in front of a board. Patient portal adoption did not happen by itself — providers pushed it, deliberately and successfully, and the federal data shows the push worked. Encouraged patients access their records at 87%; unencouraged patients at 57%. The 51% proxy figure matters too, because the adult daughter checking her mother’s chart is exactly the reader a “Medicare Kit” email is written for.

The trust this campaign is spending is trust you built on purpose.

Your staff got the same email

Everyone in your building is somebody’s patient. The results lure does not know or care that the reader works in your billing office, and a fair number of people check personal email at work.

The difference is the endpoint. A patient who runs Full_Analysis_Report.exe has a bad week and a trip to a repair shop. A scheduler who runs it on a domain-joined workstation has handed someone a foothold inside a network that holds charts. Same lure, same three keystrokes, wildly different blast radius — and this is the shape of most of the healthcare incidents worth studying from the past year, including the 2026 medtech wave, where the only publicly confirmed initial-access vectors were all somebody being talked into something.

The credential half deserves a note too. Epic describes a copied sign-in page rather than a live relay, which is a lower bar to build and does not defeat MFA by itself — but it still gets a password, and password reuse between a patient portal and a work account is not a hypothetical. If you want the version of this that does walk through ordinary MFA, that is adversary-in-the-middle phishing, and it is the same afternoon’s work for the same crews.

Three cheap controls do most of the useful work: block newly registered domains at the DNS resolver, alert on cmd.exe or powershell.exe spawned by a browser process, and make sure your endpoint policy blocks unsigned browser downloads on clinical workstations rather than merely warning about them. If you have no IT team, our practice-sized ransomware guide covers the same ground at that scale.

Five moves you actually control

You cannot patch someone else’s use of your logo. You can change the odds that a patient recognises the difference, and you can shorten the gap between the first report and a coherent response.

Figure 02 · Five moves, and who owns them
1MOVE 1 · MARKETING + ITMake your real mail boring and predictableOne sending domain, one link pattern, no attachments, no offers, ever. Apatient can only spot the fake if the genuine article is dull enough torecognise.2MOVE 2 · WEB + COMMSOne page that answers “is this real?”A short URL staff can read aloud over the phone, linked from the portallogin screen, updated in place rather than replaced with a new addresseach time.3MOVE 3 · FRONT DESKA script, not a policyTwo sentences and one instruction, rehearsed before the call volumearrives. Staff who are guessing will improvise, and some of them willguess wrong.4MOVE 4 · IT / SECURITYWatch the name, not only the networkLook-alike domain monitoring, and DMARC at p=reject on every domainyou own — including the parked ones you have never sent a messagefrom.5MOVE 5 · EVERY STAFF INBOXDrill the version aimed at your own peopleThe results lure works on employees as well as patients, and their nextclick happens on a workstation inside your network.

Compiled by ScamDrill, August 2026, from the patient guidance published by Epic and by the health systems issuing notices, mapped to the control that owns each step inside a provider organisation.

1. Make your real mail boring and predictable

A patient can only spot the fake if the genuine article is dull enough to recognise. One sending domain. One link pattern. No attachments. No offers, no giveaways, no urgency language, no “limited time” anything, ever — because the moment your marketing team sends one promotional-looking message from the portal, you have taught your patients that the fake ones are plausible. This is a governance decision more than a technical one, and it usually needs somebody senior to say no to a campaign.

2. Publish one page that answers “is this real?”

Short URL. Linked from the portal login screen. Updated in place when the next campaign lands rather than replaced with a new address, so the link you gave a patient in August still works in March. Staff should be able to say it out loud on the phone without spelling anything. Almost every organisation on the Becker’s list built one of these last week; the ones who will be glad in six months are the ones who built it at a permanent address.

3. Give the front desk a script, not a policy

Two sentences and one instruction, rehearsed before the volume arrives. There’s a starting version in the next section.

4. Watch the name, not only the network

Look-alike domain monitoring on your organisation’s name and your portal’s subdomain, plus DMARC at p=reject on every domain you own — including the parked ones nobody gets round to. Honestly, the limits here are real: this campaign did not spoof anyone’s domain, and monitoring will not buy fast takedowns when the destination rotates per recipient. It catches the next crew, who will be lazier.

5. Drill the version aimed at your own people

Not a slide deck. An actual email, in the inbox, on a Tuesday, that looks like the thing that is circulating — and a landing page that teaches instead of scolds. The number you want is not the click rate. It is the report rate, and whether it went up after the last round.

Your patients got the email. So did your schedulers.

ScamDrill runs email phishing simulations for organisations, including healthcare-flavoured lures like the one circulating now, so you find out who clicks before somebody with a payload does.

See how organisation drills work

What the front desk should say

Six calls cover most of the volume. Adapt the wording to your own voice, but keep the structure: name the situation, remove the blame, give one action. The right-hand column is there because the wrong answer to a worried patient is usually a hedge.

The patient saysSay thisNot this
“I got an email about a free Medicare kit.” That one is fake and it is going around the whole country. Please delete it without clicking anything, including unsubscribe. Nothing was taken from us and nothing has happened to your chart. “Let me check whether that came from us.” It didn’t, and the hedge tells them it might have.
“I clicked the link but I didn’t type anything.” Then you are most likely fine. Close the page and don’t go back to it. Don’t click unsubscribe — that only confirms your address is real. “You should be OK.” Vague reassurance without the unsubscribe warning invites the second mistake.
“I typed my portal password in.” Change your portal password now, from the app or your own bookmark rather than any link. If you use that password anywhere else, change it there too. I’ll flag your account for our team. “We’ll reset it for you.” Do it if you can, but the reused-password question is the one that matters more.
“I gave them my card details.” Call the number on the back of your card, report it as fraud, and ask for a replacement card — not just a dispute on the one charge. “Dispute the charge.” A small charge that repeats is the actual business model.
“They had me run something on my computer.” Disconnect that computer from the internet and have someone look at it before you use it for banking, email or anything medical. “Run a virus scan.” Not wrong, but it is the wrong first move and it keeps the machine online.
“Is my medical record safe?” Yes. There is no sign our systems or the portal were breached. This is people using our name from the outside, which is why the message came to your personal email and not through the portal. “We’re investigating.” True and useless. Say the specific reassuring thing you can actually stand behind.

Have somewhere to send the patient afterwards, too. Our link checker is free and needs no account, and for the older patients generating most of these calls, the warning signs worth taping next to the phone is a printable page you can hand over at the desk.

The part that lingers

This campaign will burn out. Most do. The pattern behind it will not, because brand impersonation is the cheapest attack available in healthcare: the trust is already built, the audience is already trained, and the attacker does not have to breach anything to spend either one. My read is that the next round wears a payer’s name, or a national lab’s, or yours — and lands on the same patients, who by then have been told twice that free health kits are a scam and once that their results are ready.

Which is the argument for building the page and the script now rather than during the next one. The second time you do this, the only new thing should be the name of the brand being borrowed. For the wider picture, our healthcare overview covers where drills sit alongside the technical controls, and the help-desk vishing playbook covers the version of all this that arrives by phone.

Frequently asked questions

Is a patient portal phishing campaign a HIPAA breach we have to report?

Generally no. A reportable breach under the HIPAA Breach Notification Rule turns on an impermissible acquisition, access, use or disclosure of protected health information held by a covered entity or its business associate. A third party impersonating your brand, using contact data it obtained somewhere else, to phish people who happen to be your patients does not on its own put PHI you held into anyone’s hands. That analysis changes if your systems show signs of being touched, if harvested credentials were used to reach real records, or if the target list plausibly traces to data you hold — and state breach law can reach further than HIPAA does. Confirm the call with counsel, and write the reasoning down at the time.

How did the scammers get our patients’ email addresses?

Nobody has said publicly. The most careful reading available, from the HIPAA Journal, is that the addresses most likely came from an earlier data breach and that the breach was not necessarily at the patient’s own healthcare provider. A great deal of health-sector contact data has been published this year, so assembling a list of Medicare-aged addresses is not difficult. The practical consequence is that the honest answer at the front desk is that the message did not come from your systems and you do not know where the address came from, which is a better answer than a guess.

Should we tell patients the portal was hacked?

No, and the wording matters. Say the thing you can stand behind: there is no sign your systems or the portal were breached, the message came from outside, and that is why it arrived in personal email rather than as a portal notification. Virtua Health’s public notice used almost exactly that construction. Vague phrasing like “we are investigating” is technically safe and practically useless, because a worried patient reads hedging as confirmation that something happened.

What is ClickFix, and why is it turning up in a fake lab result?

ClickFix is the technique of getting victims to run the malware themselves by presenting keyboard instructions as a verification step — usually the Windows key plus R, then Ctrl and V, then Enter, which opens a command box and runs whatever the page has quietly copied to the clipboard. It has circulated behind fake CAPTCHA pages and bogus browser updates for a while. Putting it behind a fake chart is newer and it works better, because a page claiming an urgent problem with your blood work buys compliance a CAPTCHA never could. Epic also documented an August variant that skips the keystrokes and simply serves an executable named Full_Analysis_Report.exe.

Can we get the fake sites taken down?

Slowly, and incompletely. Report the domains to your registrar, to your brand-protection vendor if you have one, and to the hosting provider, and keep a log of what patients reported so you have addresses to submit. Expect it to lag the campaign: Epic notes that the Medicare-kit emails routed each recipient through advertising redirects to a different final address, so there is no single site to remove. Takedown is worth pursuing and it is not a response plan on its own.

Our staff received the same email. What is the real risk to us?

The endpoint, mostly. The credential page is described as a copy of the real sign-in page rather than a live relay, so it harvests a password without defeating MFA on its own; the exposure there is password reuse between a personal portal login and a work account. The larger risk is the executable. A patient who runs it loses a home computer; a staff member who runs it on a domain-joined workstation has given someone a foothold inside a network that holds charts. Blocking newly registered domains at the DNS resolver and alerting on a command shell spawned by a browser closes most of that gap cheaply.