Why is MyChart becoming a cyber target?

Advertisement

MyChart hasn’t been hacked. Nobody’s data has leaked out of Epic Systems’ platform, and the company says its security is unaffected. And yet dozens of health systems, from academic medical centers to rural critical access hospitals, have spent the past few weeks independently warning patients about the same phishing scam bearing MyChart’s name. The answer to why isn’t a vulnerability in the software. It’s a byproduct of how big, and how trusted, the brand has become.

Becker’s has tracked the number of health systems issuing warnings climb quickly: seven in mid-August, then 21 then over 40 by the beginning of September — and counting. The fraudulent emails, which use subject lines such as “Your MyChart Medicare Kit Awaits!” and dangle a free “Senior Health Package,” direct recipients to a fake website built to harvest login credentials and personal information. Epic has said the site, mychart-epic[.]com, copies the real MyChart website’s code, and some of the fake correspondence even signs off from a “MyChart Health Network” at an address in Verona, Wis. — Epic’s actual headquarters.

That level of detail only pays off because of scale. MyChart is licensed by thousands of hospitals and clinics nationwide, which means a single templated email can plausibly land in the inbox of a huge share of U.S. patients regardless of which health system they actually use. A scammer impersonating a single hospital’s portal reaches that hospital’s patients. A scammer impersonating MyChart reaches almost everyone.

Scale alone doesn’t explain the lure, though. Patients have spent years being trained to expect legitimate correspondence through MyChart: lab results, appointment reminders, billing statements, insurance verification, Medicare enrollment links. That routine familiarity is exactly what a phishing campaign needs to work. A “MyChart Medicare Kit” offer isn’t a wild claim to someone who already receives real Medicare and billing information through that same portal. The scam isn’t inventing trust; it’s borrowing trust patients already extend to the brand for legitimate reasons.

In response to a request for comment, Epic pointed Becker’s to a July 27 post on MyChart.org. In it, Trevor Berceau, director of research and development at Epic, attributed the rise in scam attempts to scammers “taking advantage of the popularity of the MyChart brand,” and said patients can continue using MyChart as normal.

That framing is accurate, but it also draws a line that leaves health systems on the other side of it. Because Epic’s platform itself hasn’t been compromised, there’s no vendor patch and no single incident to report. Each health system has had to discover the campaign on its own, often after patients forwarded the suspicious emails, and post its own warning using its own communications and security staff. More than 40 versions of essentially the same notice now exist because there’s no coordinated alternative.

That pattern isn’t unique to MyChart. Healthcare organizations are more susceptible to phishing than nearly any other major industry, and the sector’s growing reliance on a small number of shared vendors has become its own risk multiplier. The MyChart scam is a lower-stakes version of the same logic: When most hospitals share one vendor, that brand becomes a single point of leverage, whether what’s exploiting it is ransomware — or simply a spoofed email.

At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.

Advertisement

Next Up in Cybersecurity

Advertisement