Rise in Deceptive Impersonation Scams Targeting Patient Portals

Criminals are currently targeting users of MyChart, the widely used patient portal, with sophisticated phishing attacks. These bad actors send deceptive emails, text messages, and digital communications that mimic official health system notices. MyChart, licensed by Epic Systems Corporation, clarified that these incidents do not represent a technical security breach of their internal infrastructure. The portal remains safe to use, provided that users follow strict verification habits when receiving unexpected notifications.

Investigations conducted this summer identified two primary methods used to deceive patients. The first scheme involves fake medical result notifications designed to capture login credentials. The second uses fraudulent offers of free health kits to harvest personal, financial, and payment data. While the tactics differ, the goal remains the same: unauthorized access to private information or the direct theft of funds.

Anatomy of the Medical Results Phishing Attack

In one common attack scenario, a target receives an email claiming their lab results are ready for review. The message contains a link that redirects the recipient to a clone of the official MyChart login page. Once the patient inputs their credentials, the attackers gain full access to the account. Some variations of this scheme go further by tricking the user into running malicious code on their local machine.

Specifically, the fake page may instruct users to perform a series of keyboard commands, such as pressing the Windows key and R followed by Ctrl and V. These actions open a command box, paste a script from the user's clipboard, and execute it, which then installs malware directly onto the computer. A legitimate medical institution will never require a patient to execute complex command-line instructions to view a report or unlock a patient account.

Tactics Used in the Medicare Kit Fraud

Another prevalent scam promises a free Medicare health kit as a promotional offer. The email directs victims to a landing page featuring an artificial countdown clock, which creates a false sense of urgency. The site claims that only a few units remain available for distribution, pressuring the recipient to act without verifying the source.

After answering a series of survey questions, the victim is informed they have won a kit valued at $149. The trap closes when the site requests a small shipping fee, which requires the victim to provide a full name, physical address, and credit card number. MyChart maintains no giveaway programs. Any notification that promises a prize in the portal’s name is a fabrication, as any transaction requiring payment to receive a claimed prize is inherently fraudulent.

Best Practices for Patient Data Security

Security experts recommend that all patients prioritize verifying the sender’s actual email address and the full URL of any link before proceeding. Navigating to the official, bookmarked patient portal website or using the dedicated mobile application is the safest way to review medical information. If a patient receives an unexpected or suspicious message, they should mark it as phishing rather than interacting with the embedded links.

Patients who have already clicked a suspicious link should immediately reset their MyChart password and monitor their financial statements for unauthorized activity. If credit card details were provided to a fraudulent site, contact the issuing bank at once to report the theft and request a card replacement. Anyone who executed keyboard shortcuts or downloaded a file should isolate the affected device from the network to prevent the spread of malware and seek professional technical assistance.