Multiple U.S. healthcare systems have notified patients about a phishing campaign sending emails that falsely appear to come through the Epic MyChart patient portal.
The campaign uses the MyChart name and logo in messages that offer purported healthcare benefits, Medicare packages, free gifts, or rewards. Some messages claim that recipients have won a MyChart Medicare Kit. Texas Health Resources reported that some emails offered a “Senior Health Package.”
Health Systems Issue Patient Warnings
Healthcare providers using Epic Systems electronic health records and MyChart portals have posted warnings about the campaign. The organizations identified include Methodist Health System, Metro Health, Sentara Health, Premier Health, and Texas Health Resources.
The phishing emails do not originate from legitimate healthcare provider email addresses or domains. Although the messages display a MyChart logo, Epic Systems did not send them. The campaign appears designed to obtain sensitive information. The information sought may include MyChart credentials, Medicare information, financial account data, or other sensitive information.
The individual or group responsible for the campaign has not been identified. The source of the patient contact information also remains unclear. The information may have been obtained through an earlier data breach, and that breach may have occurred outside the patient’s healthcare provider.
Phishing Messages Use MyChart Branding
The campaign uses the MyChart name and logo to make fraudulent communications appear legitimate. The reported campaign can involve emails, while warnings also address unsolicited text messages and phone calls offering free gifts or rewards. Messages may contain spelling or grammatical errors, unusual requests, or offers of free gifts and rewards. Some communications may also direct recipients to take immediate action. The presence of MyChart branding does not establish that a communication came from Epic Systems or a healthcare provider.
Recommended Patient Response
Patients who receive suspected phishing messages should delete them and avoid clicking links in the communication. This includes an unsubscribe link. Recipients should not reply to suspicious messages or disclose personal or financial information in response to them. Patients should also avoid using links in suspicious messages to log in to their patient portals.
Patients who used a link in one of these communications to log in to their MyChart portal should reset the password immediately and contact their healthcare provider’s MyChart support team.
Recipients should examine the sender information and verify that an email originated from a legitimate email address or domain. Patients who are uncertain about a request should contact the relevant healthcare provider through verified contact information. Contact information provided in a suspicious communication should not be used for verification.
Implications for Healthcare Organizations
Healthcare organizations using Epic Systems and MyChart have posted warnings in response to the campaign. The reported activity involves impersonation of healthcare communications rather than messages sent by Epic Systems.
The campaign also demonstrates that fraudulent communications can use familiar patient portal branding while directing recipients toward requests for credentials or other sensitive information.
Healthcare organizations that have identified the campaign can provide patients with information about the characteristics of the fraudulent communications and the appropriate method for contacting their MyChart support teams.
There is no additional information about confirmed compromises, affected patient accounts, financial losses, or HIPAA violations was provided in relation to this phishing campaign incident.