25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Health Systems Warn Patients About Epic MyChart Patient Portal Phishing Scam

More than a dozen U.S. health care systems have issued warnings to patients about an ongoing phishing campaign involving emails purporting to be legitimate communications sent via their MyChart patient portal. Many of the emails claim that the recipient is a winner of a MyChart Medicare Kit, although other healthcare benefits, Medicare packages, free gifts, or rewards may be offered. Texas Health Resources has warned patients that some email communications offered a “Senior Health Package.”

Healthcare providers that use Epic Systems’ electronic health records and MyChart portals, including Methodist Health System, Premier Health, Sentara Health, Metro Health, and Texas Health Resources, have added scam warnings to their websites about the campaign. The scammer most likely seeks MyChart credentials, Medicare information, financial account information, or other sensitive data.

The emails are not sent from legitimate healthcare provider email addresses or domains, and while they include a MyChart logo, they have not been sent by Epic Systems. The logo is used to make the messages appear legitimate. An example of one of the phishing emails is detailed below, although other messages may also be used in this campaign.

Epic Systems MyChart phishing scam

Example of a phishing email impersonating MyChart

“We’ve seen an uptick in scammers trying to trick patients by using the MyChart name or logo to make emails, text messages, phone calls, and websites look official,” explained Trevor Berceau, Director R&D, Epic Systems. “Some might try to steal your login information or promise free gifts if you enter payment details. The increase in attempts is due to scammers taking advantage of the popularity of the MyChart brand rather than any security concern, so you can continue to use MyChart as normal. If something doesn’t feel right, however, stop and check.”

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The threat actor behind the campaign has yet to be identified, and it is unclear how the cybercriminal or group behind the scam obtained patients’ contact information. It is likely that email addresses were obtained in a previous data breach, although that data breach may not necessarily have occurred at their healthcare provider.

The advice to patients is to delete any such messages immediately and not click on any links, including the “unsubscribe” link. It is important not to reply to the email, and to never disclose personal or financial information in response to one of these communications or attempt to log in to the patient portal using the link in the message. If any action has been taken, such as logging in via the link, patients should immediately reset their MyChart portal password and contact their healthcare provider’s MyChart support team.

Patients should remain vigilant against any unsolicited emails, text messages, or phone calls claiming to offer free gifts or rewards. Recipients of emails or text messages should carefully check the sender’s information to ensure that it has come from a legitimate email address or domain. These messages often include spelling and grammatical errors, unusual requests, free gifts or rewards, and often advise the recipient to take immediate action. If in any doubt about the legitimacy of any request, patients should contact the relevant healthcare provider using verified contact information. Never use any contact information included in the suspicious communication.

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist