More than a dozen health systems are alerting patients this week about a phishing campaign that mimics the look and feel of Epic’s widely used MyChart patient portal.
Disguised as legitimate communications from trusted healthcare providers, the fraudulent emails incorporate the MyChart branding and entice recipients with false incentives such as a “MyChart Medicare Kit” or a “senior health package.” These lures are designed to trick users into revealing sensitive personal data, health records, and financial credentials.
Epic, which licenses MyChart to hospitals and clinics nationwide, confirmed that the scammers have replicated the design of its official login page and are redirecting victims to deceptive domains resembling mychart-epic[.]com — rather than the verified web addresses associated with individual health systems.
The company has identified two primary attack vectors currently in circulation. One falsely notifies users of a “critical” lab result, pressuring them to download malicious software under the guise of accessing their test outcomes. The second scheme leverages a countdown timer embedded within a fake survey, encouraging users to submit personal and payment information before any promised item is ever delivered.
While the impersonation exploits the familiarity of the MyChart brand, Epic clarified that there is no indication its own systems or infrastructure have been compromised. Instead, the firm characterized these incidents as opportunistic attempts to capitalize on the platform’s broad recognition among patients.
Jackie Mattingly, senior director of consulting services at cybersecurity firm Clearwater, emphasized that healthcare organizations cannot rely on patients to independently detect increasingly sophisticated phishing attempts.
“We should not expect patients to identify a scam simply because of bad grammar, an unusual logo or an obviously suspicious message. Phishing is becoming much more polished and personalized,” she said. “A safer habit is simple: if something feels unexpected or concerning, leave the message and access MyChart through the official app or the healthcare provider’s known website, or contact the provider directly to verify it.”
Mattingly also urged hospitals to integrate defenses against patient-targeted phishing into their overall cybersecurity frameworks, rather than addressing them as isolated threats.
“That means actively monitoring for brand impersonation, preparing patient-facing communications ahead of time, and ensuring that security, communications and clinical teams all understand their roles clearly,” she added.
Amy Bucher, chief behavioral officer at patient engagement startup Lirio, pointed out that the challenge begins even before users analyze message details.
She noted that legitimate healthcare notifications and phishing attempts often arrive through identical channels and appear strikingly similar — leaving most patients to rely on quick judgments based on whether a message feels familiar or professional.
“In many cases, patients aren’t deciding whether a message is authentic. They’re deciding whether it feels authentic,” Bucher said.
To her, this distinction carries significant weight. When legitimate outreach lacks personalization or context, it becomes increasingly difficult for patients to distinguish it from fraudulent content.
Bucher advocated for healthcare messages that prioritize recognition, transparency, and continuity of existing patient-provider relationships.
“The more personalized and relevant a message feels, the more likely patients are to trust it — and the easier it becomes to spot an impersonator,” she explained. “The better hospitals get at building trust, the harder it becomes for scammers to fake it.”
Photo: Eoneren, Getty Images
Also Read
- Autism Research Strategy Stalls as Science Races Ahead
- Remembering Clive Parkinson: A Pioneer in Arts and Health
- Cyclospora Outbreak Tied to Iceberg Lettuce Spreads Across Three Additional States
- STAT+: AstraZeneca and Ionis detail surprise failure of heart disease drug, with Alnylam closely watching

