On July 27, 2026, Epic’s MyChart warned that it had observed an increase in scammers using the MyChart name and logo in fraudulent emails, text messages, phone calls, and websites.
What happened
Epic said the activity reflected abuse of the brand’s popularity rather than a security problem with MyChart. The American Hospital Association (AHA) reported on the warning on August 24 after MyChart published examples identified during Epic security investigations in summer 2026. In one campaign, an email stating that recent results were ready directed recipients to a copied MyChart sign-in page.
After collecting login details, the fake portal displayed fabricated medical information and an urgent bloodwork warning. It then instructed users to press Windows+R, paste a command, and press Enter, which Epic said installed malware. An August variation instead offered a downloadable file called Full_Analysis_Report.exe and instructed users to bypass a Windows security warning.
A second campaign promised recipients a free “2026 Medicare Health Kit.” Its links passed through unrelated advertising sites before opening a MyChart-branded survey with a countdown clock. The site subsequently requested personal information, a shipping payment, and complete credit card details. MyChart stated that it does not conduct giveaways, and multiple healthcare organizations issued warnings about the fraudulent messages.
What was said
In the AHA report, it was noted, “Epic’s MyChart has shared examples from potential phishing schemes observed as recently this month that include email messages linking to a fake MyChart website displaying erroneous medical records.”
Why it matters
The MyChart campaign follows the same pattern seen in other healthcare phishing operations. Attackers copy a trusted brand and direct recipients to fraudulent sign-in pages to collect valid credentials. In September 2025, Microsoft disrupted RaccoonO365, a phishing service that had targeted at least 20 US healthcare organizations and stolen at least 5,000 Microsoft credentials worldwide. A practical illustration of the danger comes from the March 2026 HUSKY provider-portal incident.
Connecticut officials said an unauthorized party used compromised Hartford HealthCare employee credentials to access payment accounts and download files containing information about approximately 22,500 people, including names, Medicaid claim identifiers, dates and descriptions of medical services, billing information, payment amounts, and insurance details. The notice did not disclose how the credentials were originally compromised, so the incident cannot be directly attributed to phishing.
However, it demonstrates what an attacker can accomplish after obtaining legitimate healthcare credentials. The MyChart campaign combines credential theft with fabricated urgent medical results, malware-installation instructions, and requests for personal and credit card information. By presenting the messages as genuine health updates, attackers use patients’ trust in a familiar portal to encourage actions that can expose accounts, devices, medical information, and financial data.
See also: HIPAA Compliant Email: The Definitive Guide (2026 Update)
FAQs
How can a phishing message lead to malware?
A phishing email may direct the recipient to open an attachment, download a program, or run a command.
Can a phishing site cause harm if the user does not enter a password?
Simply opening the page does not always compromise an account, especially when the browser and device are updated.
Can a legitimate organization’s logo prove that an email is genuine?
No, attackers can copy logos, colors, wording, and website designs from legitimate organizations. Recipients should verify the sender’s full address and access the organization through its official app or a saved website address.
What is a fake CAPTCHA or ClickFix attack?
It is a social engineering technique that presents harmful computer instructions as a routine human-verification test. A genuine CAPTCHA should not ask someone to open a command window, paste text, disable security settings, or run a program.
