Dozens of health systems have warned patients about messages promising free benefits, using a portal name that patients associate with their own doctor.

 

What happened

More than 30 health systems using Epic's electronic health records have issued security warnings to patients about phishing messages carrying the MyChart name and logo, BankInfoSecurity reported on August 25, 2026. The messages promise a "2026 MyChart Senior Health Package," a MyChart Medicare Kit, Medicare wellness benefits, or a free health kit, and ask recipients to claim the reward by clicking a link, confirming an address, or supplying further details. Organizations that have posted warnings include Texas Health Resources, Methodist Health System, Premier Health, MetroHealth, Sentara Health, Avera Health, and Cass Health, according to Healthcare Dive. Epic has published its own public warning alongside recommendations for providers and patients.

 

Going deeper

MyChart is used by thousands of provider organizations, so a patient seeing the brand associates it with their own physician's office rather than with a software company, which supplies credibility no lookalike domain could manufacture. The messages do not originate from legitimate healthcare provider addresses or domains, and Epic's systems have not been compromised. Some versions go further than a request for information, linking to a counterfeit MyChart site that displays incorrect medical records, according to the American Hospital Association, a tactic that produces alarm and prompts the recipient to log in and correct what they are seeing. Messages have arrived by email, text, and telephone.

 

What was said

"We've seen an uptick in scammers trying to trick patients by using the MyChart name or logo to make emails, text messages, phone calls, and websites look official," said Trevor Berceau, Director of Research and Development at Epic Systems, in remarks reported by BankInfoSecurity. He attributed the increase to the popularity of the brand rather than to any security problem, and warned that some attempts try to steal login information while others promise gifts in exchange for payment details. Methodist Health System told patients that fraudulent messages titled "Your MyChart Medicare Kit Awaits!" were circulating and did not come from the organization.

 

In the know

A study in PNAS Nexus tested 182 adults aged 18 to 90 using both a laboratory measure of phishing suspicion and a real-world task where participants encountered phishing without knowing it was part of the research, and found that older age predicted greater susceptibility across both. Vulnerability was most pronounced among older participants carrying the APOE4 gene variant associated with Alzheimer's disease who also showed lower working memory. The authors are careful about the wider literature, noting that results across studies have been inconsistent, with some research finding better phishing detection with age and one finding younger adults more vulnerable, which is why they argue for measuring actual behavior rather than laboratory responses alone. What the study does establish is that cognitive factors, rather than inexperience, drive part of the risk.

 

The big picture

Standard email authentication does not address this campaign, which is worth understanding before anyone treats it as a technical failure. DMARC and related controls stop attackers sending messages that appear to come from an organization's own domain, and these messages never claimed to, borrowing a product name and logo instead. Epic has issued recommendations for both healthcare organizations and patients on preventing and limiting the damage from these schemes, published alongside examples of the messages it has observed, including one linking to a counterfeit MyChart site displaying inaccurate medical records. Health systems that have gone public have converged on the same instruction, telling patients not to click links or reply and to reach the portal directly instead, with Cass Health advising recipients to provide no personal, medical, financial, or insurance information in response. The harder operational question is who inside the organization watches for counterfeit sites using its name, since a takedown request depends on someone noticing first.

 

FAQs

Does this campaign mean the patient portal was breached?

No. The messages use the brand rather than the systems, and no compromise of the portal or the underlying records has been reported. A patient who clicked and entered credentials would put their own account at risk, which is a different problem from a platform breach.

 

What can an attacker do with portal login credentials?

Reach the medical records, test results, messages with clinicians, appointment history, and often insurance and billing details held in that account. The information supports medical identity theft and gives an attacker material for more convincing follow-up approaches to the same person.

 

Why would a fake site display incorrect medical records?

Showing a patient something wrong in their own chart creates urgency that a generic request does not, since the natural response is to log in and fix it. The credentials entered at that point go to the attacker rather than to the provider.

 

Should health systems notify patients individually about scams like this?

Most respond with website notices, portal messages, and social media rather than direct notification, since no breach of their systems occurred and no notification obligation applies. Reaching patients who do not visit the website is the practical difficulty, which is why some organizations include warnings in appointment reminders.

 

How can patients report a suspicious message claiming to be from their provider?

Contact the provider through a phone number from a billing statement, insurance card, or the organization's website rather than any number in the message. Reports can also go to the FTC at reportfraud.ftc.gov, which feeds data used to track campaigns across organizations.