MyChart Phishing Scam Prompts Warnings From Health Systems

Multiple U.S. healthcare systems have notified patients about a phishing campaign sending emails that falsely appear to come through the Epic MyChart patient portal.

The campaign uses the MyChart name and logo in messages that offer purported healthcare benefits, Medicare packages, free gifts, or rewards. Some messages claim that recipients have won a MyChart Medicare Kit. Texas Health Resources reported that some emails offered a “Senior Health Package.”

Health Systems Issue Patient Warnings

Healthcare providers using Epic Systems electronic health records and MyChart portals have posted warnings about the campaign. The organizations identified include Methodist Health System, Metro Health, Sentara Health, Premier Health, and Texas Health Resources.

The phishing emails do not originate from legitimate healthcare provider email addresses or domains. Although the messages display a MyChart logo, Epic Systems did not send them. The campaign appears designed to obtain sensitive information. The information sought may include MyChart credentials, Medicare information, financial account data, or other sensitive information.

The individual or group responsible for the campaign has not been identified. The source of the patient contact information also remains unclear. The information may have been obtained through an earlier data breach, and that breach may have occurred outside the patient’s healthcare provider.

Phishing Messages Use MyChart Branding

The campaign uses the MyChart name and logo to make fraudulent communications appear legitimate. The reported campaign can involve emails, while warnings also address unsolicited text messages and phone calls offering free gifts or rewards. Messages may contain spelling or grammatical errors, unusual requests, or offers of free gifts and rewards. Some communications may also direct recipients to take immediate action. The presence of MyChart branding does not establish that a communication came from Epic Systems or a healthcare provider.

Recommended Patient Response

Patients who receive suspected phishing messages should delete them and avoid clicking links in the communication. This includes an unsubscribe link. Recipients should not reply to suspicious messages or disclose personal or financial information in response to them. Patients should also avoid using links in suspicious messages to log in to their patient portals.

Patients who used a link in one of these communications to log in to their MyChart portal should reset the password immediately and contact their healthcare provider’s MyChart support team.

Recipients should examine the sender information and verify that an email originated from a legitimate email address or domain. Patients who are uncertain about a request should contact the relevant healthcare provider through verified contact information. Contact information provided in a suspicious communication should not be used for verification.

Implications for Healthcare Organizations

Healthcare organizations using Epic Systems and MyChart have posted warnings in response to the campaign. The reported activity involves impersonation of healthcare communications rather than messages sent by Epic Systems.

The campaign also demonstrates that fraudulent communications can use familiar patient portal branding while directing recipients toward requests for credentials or other sensitive information.

Healthcare organizations that have identified the campaign can provide patients with information about the characteristics of the fraudulent communications and the appropriate method for contacting their MyChart support teams.

There is no additional information about confirmed compromises, affected patient accounts, financial losses, or HIPAA violations was provided in relation to this phishing campaign incident.

Tags

Daniel Lopez

Daniel Lopez

Daniel Lopez stands out as an exceptional HIPAA trainer, dedicated to elevating standards in healthcare data protection and privacy. Daniel, recognized as a leading authority on HIPAA compliance, serves as the HIPAA specialist for Healthcare IT Journal. He consistently offers insightful and in-depth perspectives on a wide range of HIPAA-related topics, addressing both typical and complex compliance issues. With his extensive experience, Daniel has made significant contributions to multiple publications such as hipaacoach.com, ComplianceJunction, and The HIPAA Guide, enriching the field with his deep knowledge and practical advice in HIPAA regulations. Daniel offers a comprehensive training program that covers all facets of HIPAA compliance, including privacy, security, and breach notification rules. Daniel's educational background includes a degree in Health Information Management and certifications in data privacy and security. You can contact Daniel via HIPAAcoach.com.

Get the free newsletter

Discover everything you need to become HIPAA compliant
Name

Read Next

Scroll to Top

Get the free newsletter

Discover everything you need to become HIPAA compliant
Name