Wireva

Fake MyChart patient portal scams target logins, can install malware

Scammers are impersonating the MyChart patient portal in phishing campaigns that steal login credentials and, in some versions, install malware on Windows computers. Health systems and state officials have issued warnings.

This item was produced with AI assistance under the editorial responsibility of Haydamax OÜ.

Patients who use MyChart, the widely adopted patient portal from Epic, are being targeted by a wave of phishing scams that impersonate the service to steal login credentials and, in some cases, infect Windows computers with malware. The warnings come from multiple credible sources at nearly the same time, including health systems, a state attorney general, and Epic's own security team.

Penn Medicine said it was seeing a nationwide scam involving emails and text messages made to look like they came from MyChart. Pennsylvania Attorney General Dave Sunday separately warned consumers about another impersonation scam involving a bogus Medicare Kit. Epic has detailed two phishing campaigns its security team investigated this summer. The coordinated timing of the warnings suggests patients should be especially careful with unexpected MyChart messages right now.

The tricky part for many patients is that legitimate emails about appointments or new test results are routine. A fake MyChart alert can land right alongside the real ones, and scammers are counting on recipients reacting before taking a closer look. The impersonation does not reflect a breach of the MyChart platform itself; the criminals are copying the MyChart experience to deceive users.

One campaign starts with a message that looks routine. Epic says the email carries MyChart branding and tells the recipient that recent results are ready. The button inside the email leads to a fake sign-in page. According to Epic, scammers copied code from the real MyChart site, which helps the page look convincing. The bogus page asks for an email address and password, and if entered, the scammers capture those credentials.

The attack then becomes more aggressive. After the victim signs in, the fake site displays a made-up medical record. Epic says one version shows a pop-up claiming an AI-powered review found critical patterns in blood work. That is a powerful pressure tactic, since a warning about health can be much harder to ignore than an ordinary phishing message. Epic notes that real critical results come from a care team rather than a website pop-up.

The fake chart then claims the patient needs to complete a human verification step before seeing more information. Epic says the site instructs Windows users to press the Windows key and R, paste content from the clipboard, and press Enter. Those steps open the Windows Run box and execute a command the website placed on the clipboard, which installs malware. Epic also saw an August version with an Unlock Full Report and See Diagnosis button that downloaded a Windows file called Full_Analysis_Report.exe, with the page coaching the victim through bypassing the computer's security warning.

A second campaign uses a different hook. Epic says scammers sent fake emails telling people they had been selected for a 2026 Medicare Health Kit. Penn Medicine has also warned about messages advertising a free MyChart Medicare Kit or Senior Health Package. MyChart does not run giveaways. After someone clicks, the link can pass through unrelated advertising sites before reaching a fake MyChart-branded survey with a countdown clock pushing the victim to move quickly. The site eventually says the kit costs nothing but asks for a shipping fee, collects personal information, and requests credit card details. Epic says no kit ships.

Patients already expect electronic messages from doctors and hospitals, and a real test-result notification may show up on the same day as a fake one. Scammers copy that familiar routine and use fear to shorten the time a recipient spends checking a message. If a fake portal hints at a serious health problem, the first instinct may be to find out what happened. Opening the portal independently by typing the known web address directly into a browser, rather than clicking links in messages, can make a significant difference in avoiding these traps.

Same event, other desks

Story file →