More than a dozen health systems across the U.S. have issued warnings that patients are being targeted by a wave of phishing attempts impersonating MyChart, Epic’s patient portal. The messages use the MyChart name and logo and promote purported free offers to coax recipients into clicking links and sharing personal information.
The source article cites specific health systems that notified patients about the scam. Notices were posted by Texas Health and also reported from Avera Health in South Dakota, Methodist Health System in Texas, Premier Health in Ohio and Sentara Health in Virginia. The broader report indicates that more than a dozen systems nationwide have raised alerts, though the source does not list every affected organization.
According to the health systems’ notices summarized in the source, the scam messages typically:
These features are consistent with common phishing tactics where attackers leverage a trusted brand to lower recipients’ guard and collect sensitive data via a fraudulent web page.
Epic’s director of research and development, Trevor Berceau, is quoted in the source as saying the recent increase in attempts reflects scammers taking advantage of the popularity of the MyChart brand rather than indicating a security vulnerability in MyChart itself. Per the source, Epic advised users that they can continue to use MyChart normally but should pause and verify if something about a message feels wrong.
Epic has publicly cautioned users to be skeptical of free offers received by email and provided specific checks, including verifying the sender and the web address. The company also stated that MyChart will never ask patients to press keyboard shortcuts or to change the email addresses or phone numbers associated with their accounts.
The article notes Epic did not respond to a request for additional comment by publication time.
The source places this MyChart-branded campaign in the broader context of healthcare cybersecurity. It cites data indicating healthcare organizations are more susceptible to phishing than any other major industry. The article also highlights that artificial intelligence is enabling cybercriminals to produce high volumes of phishing messages that look convincingly legitimate, which elevates the overall threat level for the sector.
The health systems and Epic guidance summarized in the article advise patients to:
These are the specific user-facing checks and cautions reported in the source.
The source reports health system warnings and Epic’s public guidance but does not provide details on the number of patients affected, whether any accounts or personal data were confirmed compromised, or what law enforcement or incident response actions—if any—were taken. The source also notes Epic had been aware of an uptick in scam attempts earlier in July, as reported on MyChart’s public materials, but does not offer additional investigative findings or outcomes.
Health systems are alerting patients to a MyChart-branded phishing campaign that uses free-offer lures and links to collect personal information. Epic frames the surge as brand abuse rather than a MyChart security breach and advises users to verify senders and web addresses and to remember that MyChart will not request certain account changes or keyboard shortcuts. The article underscores the broader vulnerability of healthcare to phishing and the amplifying effect of AI on threat actors’ ability to craft convincing messages.