Florida Hospitals Issue Alert Over MyChart Phishing Attacks

Scammers are targeting users of MyChart, the widely used patient portal developed by Epic Systems, through a sophisticated phishing campaign. The fraudulent messages impersonate official hospital communications to solicit sensitive personal data and Medicare information. At least 20 hospitals across the United States, including major institutions in Florida such as Tampa General Hospital and Tallahassee Memorial Healthcare, have issued formal warnings to their patients. The scam typically involves claims of wellness programs or the promise of a MyChart Medicare Kit designed to deceive recipients into clicking malicious links.

While health systems in Southwest Florida report no evidence of patient data breaches or direct interference with their operational networks, the scale of the threat is significant. Lee Health and Naples Comprehensive Health are among those actively advising their patients to remain vigilant against unsolicited outreach. The attacks leverage the high visibility of the MyChart brand, which connects to the electronic medical records of roughly 253 million patients. With 190 million registered users, the portal represents a massive target for bad actors looking to exploit the trust patients place in their medical providers.

The Scope of the MyChart Ecosystem

Epic Systems holds approximately 44% of the U.S. hospital market for electronic medical records. This massive footprint makes the MyChart interface a standard part of the patient experience for millions of Americans. Because the platform is integrated into daily care management for chronic conditions and routine appointments, a fake message appearing to originate from the service often carries an inherent sense of legitimacy. The scammers capitalize on this familiarity by mimicking hospital branding and professional language to bypass standard user skepticism.

Trevor Berceau, the director of research and development at Epic Systems, confirmed that the increase in fraudulent activity is not linked to any technical vulnerability within the MyChart infrastructure. Instead, the attackers are exploiting the brand recognition to conduct social engineering campaigns. These bad actors contact users through various channels, including SMS, email, and unsolicited phone calls. Their goal is to capture login credentials, payment details, or personal health identifiers through deceptive websites that mirror legitimate login portals.

Protective Measures and Industry Standards

Medical providers and technical staff are reinforcing clear guidelines to prevent further incidents. Patients are advised to disregard any link sent via email or text message that requests personal or financial information. Instead, users should navigate directly to their provider’s specific website or use the official MyChart application on their smartphone. If a message seems unusual or creates a sense of urgency regarding Medicare benefits or wellness kits, the recommended action is to contact the hospital administrative office by phone.

Security remains a priority for the regional health systems responding to this trend. Andrew Cooper, the chief digital and access officer at Naples Comprehensive Health, stated that his team monitors the threat environment to keep patient information protected. As these phishing tactics evolve, the reliance on verified, direct communication between the hospital and the patient becomes the primary defense. The industry continues to emphasize that while the platform remains secure, individual vigilance acts as the final gatekeeper against unauthorized access to medical records.