More than a dozen health systems are warning patients this week of a phishing campaign impersonating Epic‘s MyChart patient portal.
The scam emails use the MyChart logo and dangle fake rewards like a “MyChart Medicare Kit” or or “senior health package” to trick patients into handing over their personal details, health records or financial information.
Epic, which licenses MyChart to health systems, said the fraudulent site copies its real login page’s code and directs victims to lookalike domains — such as mychart-epic[.]com — rather than a health system’s actual Epic portal address.
The company has documented two active schemes: one that pushes a fake “critical” lab result to pressure patients into running malicious software, and another that uses a countdown-timer “survey” to harvest personal and payment information before ever shipping anything.
Overall, Epic has characterized this phishing campaign as scammers capitalizing on the MyChart brand’s recognition rather than a sign that Epic’s own systems have been breached.
Jackie Mattingly, senior director of consulting services at cybersecurity firm Clearwater, said providers shouldn’t anticipate that patients will catch these scams on their own.
“We should not expect patients to identify a scam simply because of bad grammar, an unusual logo or an obviously suspicious message. Phishing is becoming much more polished and personalized. A safer habit is simple: if something feels unexpected or concerning, leave the message and access MyChart through the official app or the healthcare provider’s known website, or contact the provider directly to verify it,” she explained.
Mattingly added that hospitals need to treat patient-facing phishing as part of their broader cybersecurity strategy rather than a separate issue, even when their own network hasn’t been breached. To her, that means monitoring for brand impersonation, preparing patient communications in advance and making sure security, communications and clinical teams all understand their roles clearly.
Another healthcare leader — Amy Bucher, chief behavioral officer at patient engagement startup Lirio — said the problem starts before patients ever scrutinize a message’s details.
Legitimate healthcare communications and phishing attempts often arrive through the same channels and look strikingly similar, she noted — and most patients rely on quick mental shortcuts, like whether a message feels familiar or professional rather than carefully verifying each one.
“In many cases, patients aren’t deciding whether a message is authentic. They’re deciding whether it feels authentic,” Bucher said.
To her, that distinction matters. Because when legitimate outreach becomes too generic or impersonal, it becomes harder for patients to tell it apart from spam.
Bucher said trustworthy healthcare messages share a few traits. They’re recognizable, transparent and tied to a relationship the patient already has with a provider or health system. She believes that the more personalized and relevant a message feels, the more likely patients are to trust it — and the easier it becomes to spot an impersonator.
In her eyes, the better hospitals get at building trust, the harder it becomes for scammers to fake it.
Photo: Eoneren, Getty Images
