A Coordinated Warning Rather Than a Breach
American health systems are telling patients the same thing this month: messages arriving with the MyChart name and logo, offering a free Medicare kit or a senior health package, did not come from their doctor's office.
The campaign uses subject lines referencing a MyChart Medicare Kit or a senior wellness package, according to Healthcare Dive, which reported Monday that more than a dozen health systems across the country are warning patients. Messages have arrived by email, text, and phone call. Becker's Hospital Review is maintaining a running tally that has reached thirty health systems that either issued warnings or whose patients reported receiving the messages, up from seven earlier this month. Named systems span Sentara Health in Virginia, Avera Health in South Dakota, Methodist Health System and Texas Health in Texas, Premier Health in Ohio, UMass Memorial Health in Massachusetts, and Cass Health in Iowa.
The most important thing for patients to understand is what this is not. Epic, the company behind MyChart, has attributed the increase to scammers exploiting the brand's familiarity rather than to any security problem with the portal itself. Trevor Berceau, Epic's director of research and development, wrote in a July post that patients can continue using the portal, saying, "You can continue to use MyChart as normal," while advising them to stop and check if something feels off.
That distinction matters because the alternative reading, that a portal holding medical records had been compromised, would call for entirely different action. Nothing reported so far supports it.
The Lure Is Built Around Medicare, and That Is Deliberate
The pitch blends two names people already trust and targets a specific population.
The message typically asks the recipient to click a link to claim an offer, which leads to a page requesting personal information. It may contain spelling mistakes or unusual wording and arrive from an unfamiliar email address, Texas Health said in its notice.
Health systems have been unusually specific about what not to hand over. Becker's reported that organizations are urging patients to delete the messages without clicking any links, verify sender addresses, watch for grammatical errors, and treat unsolicited free offers with skepticism. Sentara advised recipients to delete the email immediately without clicking anything, including the unsubscribe option, and warned against opening attachments from unknown senders.
What a successful attempt yields is worth stating plainly, because it explains why health systems are treating an unglamorous email campaign seriously. A patient portal account can hold diagnoses, medications, laboratory results, home address, insurance details, and message threads with clinicians. Many portals also support bill payment and proxy access for family members. Medicare numbers, separately, are a durable asset for billing fraud in a way a credit card number is not, because they are not routinely reissued.
The Reason This Campaign Slips Past Normal Instincts
Most phishing works by manufacturing an event that did not happen. This one borrows an event that happens constantly.
Patients receive legitimate MyChart notifications all the time: appointment reminders, new test results, billing messages, refill confirmations. A message carrying that name is not inherently surprising, which removes the instinctive pause that a fake package-delivery notice or an unexpected bank alert usually triggers.
The messages also carry healthcare branding that looks plausible at a glance, and text versions often hide the destination behind a shortened link. Epic has cautioned users to be skeptical of free offers sent over email, advising them to check the sender and web address, and has said MyChart will never ask patients to press keyboard shortcuts or to change the email address or phone number associated with an account. That last item is a useful tell because changing the contact details on an account is how an attacker locks out the real owner.
The safest habit requires no judgment about whether a particular message is real. Patients can ignore the link entirely and access the portal as they normally would, through the MyChart app or by typing their health system's web address directly. If a message is legitimate, whatever it describes will be waiting inside the account.
Anyone who clicked and entered credentials should change the portal password immediately, change it anywhere else the same password was used, and contact the health system. Health systems routinely handle phishing, and early notice gives them a better chance to secure the account. People who supplied Medicare or insurance details should watch statements and explanation-of-benefit notices for claims they do not recognize, which may not appear for weeks.
One Brand, Every Hospital, One Template
There is a structural point buried in this episode. MyChart is used by hospitals nationwide, making it a single, recognizable brand in front of an enormous number of patients. That consolidation is convenient for patients and equally convenient for anyone impersonating it, because one template works everywhere.
Individual health systems can post alerts on their own websites, and many have. No single system can reach every person who received the email, since the senders are not working from any one institution's patient list. A patient of a hospital that has not posted a notice is no less likely to receive the message than a patient of one that has, and the absence of a warning from a particular provider says nothing about whether its patients are being targeted. That asymmetry is worth naming because patients reasonably treat silence from their own hospital as reassurance.
Epic pointed Becker's to its public post in response to a request for comment and did not respond to Healthcare Dive by publication time. Phishing remains a common tactic with a high success rate, and healthcare organizations are more susceptible to it than any other major industry. Whether this campaign expands or fades will likely be visible first in additional health system notices rather than in any central tally, because Becker's list is updated only as organizations come forward. Health systems continue to face increasingly damaging intrusions, which is part of why an email campaign draws so much institutional attention.
Key Questions Answered
What is happening? Scammers are sending emails, texts, and calls using the MyChart name and logo, typically offering a free Medicare kit or senior health package, to get recipients to click links or supply personal information.
Was MyChart hacked? No. Epic has said the increase reflects scammers exploiting the brand's popularity rather than a security problem, and has told patients they can continue using the portal normally.
How many health systems have warned patients? Becker's Hospital Review has counted thirty so far, and the list is being updated as more organizations come forward.
What information are they after? Personal, financial, insurance, and Medicare details, and in some versions, portal login credentials. Health systems have specifically warned against providing any of these.
How can someone tell a real message from a fake one? Skip the judgment call. Do not use links in the message. Open the MyChart app or type the health system's address directly, and check whether the notification is there.
What should someone do if they already clicked? Change the portal password right away, change it anywhere else it was reused, and contact the health system. Report the message as phishing and delete it.
What if Medicare or insurance details were shared? Monitor statements and explanation-of-benefit notices for unfamiliar claims, which may take weeks to appear, and report anything unexpected.