- Services
- Products
-
-
- Online Training
- Information Security Awareness Training Course
- PCI DSS Compliance Bundle
- GLBA Awareness Training Course
- CMMC Training Course
- HIPAA Awareness Training Course
- Data Privacy Training Course
- Payments Security Training Course
- Phishing Awareness Training Course
- GDPR Training Course
- FERPA Training Course
- FACTA Training Course
- Online Training
-
- Compliance
- Markets
- Insights
- About
If you’ve received an email, text, or phone call promising a free “MyChart Medicare Kit” or “Senior Health Package,” delete and report it. You’re being targeted by scammers, not your doctor’s office. Dozens of health systems across the country, along with Epic Systems, the company behind the widely used MyChart patient portal, have issued warnings about a coordinated phishing campaign exploiting the trusted MyChart name and logo.
The scam shows how even trusted healthcare tools can be exploited as bait, making it essential for patients to stay alert.
Details of the MyChart Scam
More than 30 U.S. health systems, including Texas Health Resources, Methodist Health System, Avera Health, Premier Health, Sentara Health, and Metro Health, have posted alerts warning patients about fraudulent messages that impersonate MyChart, the patient portal built by electronic health records giant Epic. The messages arrive as emails, texts, or even phone calls, using the MyChart name and logo to look legitimate.

The lure is typically a “reward,” a free “MyChart Medicare Kit,” a “2026 MyChart Senior Health Package,” Medicare wellness benefits, or a general health-related gift. Victims are told to “claim their reward” by clicking a link, confirming personal details, or logging in with their MyChart credentials.
From there, the scam most likely aims to harvest MyChart login credentials, Medicare numbers, financial account information, or other sensitive personal data.
Epic’s director of research and development, Trevor Berceau, confirmed the company has seen “an uptick in scammers trying to trick patients by using the MyChart name or logo” across emails, texts, calls, and fake websites. Importantly, Epic and affected health systems note this isn’t the result of a security breach in MyChart itself.
It’s an impersonation campaign exploiting the brand’s popularity and reach, since MyChart is used by hospital systems nationwide, making it a recognizable name in front of millions of patients. Security experts also point to artificial intelligence as an accelerant. AI tools make it easier for scammers to build convincing fake portals, generate polished, personalized phishing messages in multiple languages, and scale attacks faster and more cheaply than before.
Red Flags to Watch For
- Unsolicited “rewards” or gift offers tied to Medicare, wellness kits, or senior health packages
- Sender addresses that don’t match your health system’s official domain
- Spelling mistakes, awkward phrasing, or generic greetings
- Urgent calls to action, such as “claim now,” “limited time,” “confirm your address”
- Requests to log in or enter payment/insurance details through a link in an unsolicited message
- Phone calls or texts claiming to be from MyChart or your provider asking for credentials or personal information
Best Practices to Avoid Becoming a Victim
- Don’t click links in unsolicited messages. Go directly to your health system’s official MyChart website or app instead of clicking through an email or text.
- Verify the sender. Check the actual email address or phone number, not just the display name or logo.
- Never enter your MyChart credentials on a page you reached by clicking a link in an email or text.
- Be skeptical of free offers. Legitimate healthcare communications rarely dangle “rewards” for logging in or sharing personal data.
- Enable multi-factor authentication on your MyChart account if your health system offers it.
- Report and delete suspicious messages. Most health systems recommend marking them as spam rather than replying or unsubscribing.
- If you already clicked a link and entered your password, change your MyChart password immediately, change it anywhere else you reused it, and contact your health system’s support line.
- Watch your statements. If you shared Medicare or insurance information, monitor billing statements and explanation-of-benefits notices for unfamiliar claims, as these can take weeks to appear.
- Check the MyChart Is Epic page for more details on the scam and how to protect yourself from scams and fraud.
Guidance for Healthcare Organizations Supporting MyChart Users
While patients are the primary targets of these scams, healthcare organizations also play a critical role in preventing fraud and protecting trust within the patient-provider relationship. Organizations that utilize Epic and MyChart should consider a proactive education and awareness strategy for both employees and patients.
Develop patient facing security awareness communications reminding patients:
- MyChart passwords should never be shared
- Patients should access MyChart through the official app or healthcare organization’s website
- Healthcare organizations will never ask for passwords through email, text, or unsolicited phone calls
- Patients should verify unexpected communications before taking action
- Suspicious messages should be reported to the organization
Front-line staff, call center representatives, patient access teams, nurses, and providers may be the first to hear about suspicious messages from patients. Employees should understand:
- Current phishing scams targeting MyChart users
- How to identify fraudulent emails, text messages, and phone calls
- Appropriate procedures for responding to patient inquiries
- How and where to report suspected phishing attempts
Consider incorporating MyChart-related phishing examples and other health-care specific examples like insurance verification requests, fraudulent appointment confirmations, etc., into security awareness training and periodic phishing simulation exercises.
Your team may want to review your current security features, including things like multi-factor authentication (MFA) requirements, identify verification procedures, account recovery processes, and login monitoring to help reduce the likelihood of account compromise.
Final Thoughts
This campaign is a useful case study in how trust itself becomes an attack surface. MyChart’s near-universal presence across U.S. hospital systems is exactly what makes it convenient for patients, and exactly what makes it valuable to impersonate.
A single phishing template can work against patients of dozens of unrelated health systems simply because so many of them use the same portal brand. Add AI-generated phishing content into the mix, and these scams are only going to get harder to distinguish from the real thing.
The good news: the fix isn’t complicated. Treat unsolicited “free gift” messages tied to your health portal with the same skepticism you’d apply to a too-good-to-be-true prize notification from your bank, and always navigate to sensitive accounts directly rather than through a link.
If you’re unsure whether a message is real, your health system’s patient support line can confirm it in minutes.
If you’re interested in gauging your employee’s phishing readiness, check out our Phishing Awareness training course and our Phishing Simulation platform. Contact us to learn more or request a demo.