Skip to content
MarketScale
‹ Back to IndustriesHealthcare

Epic’s MyChart phishing wave is pushing patient-access teams to treat portal identity as a security perimeter

Hospitals are alerting patients about phishing scams involving Epic’s MyChart, as these scams impersonate the patient portal to deceive users. The concern grows as CMS encourages healthcare innovation and interoperability. As a response, healthcare teams are treating portal identity as a vital security frontier.

This story was produced through MarketScale. See how Healthcare teams put it to work with Executive Thought Leadership.

By MarketScale Newsroom · EpicMychartHealthcare CybersecurityPhishing
Share
Learn this in 60 seconds

Key facts, context, and what it means, in one minute.

:60
0:001:00
Epic’s MyChart phishing wave is pushing patient-access teams to treat portal identity as a security perimeter

Key takeaways

01

Hospitals are experiencing phishing scams that mimic Epic’s MyChart portal.

02

The CMS continues to push for industry-led pledges toward healthcare interoperability.

03

Patient portal identity is being prioritized as a critical aspect of cybersecurity.

Get featured

Want to get featured in MarketScale Healthcare?

Create a free MarketScale workspace and get your company's expertise featured across our Healthcare coverage. No credit card, no demo required.

Request an invite

Hospitals are telling patients to ignore suspicious emails, texts, and calls that claim to be from Epic’s MyChart, a sign that the patient portal has become a frontline security boundary. Modern Healthcare reported Aug. 21 that health systems are issuing public warnings as scammers pose as MyChart to solicit information or payments.

The timing matters. Many health systems are expanding portal use beyond lab results into billing, scheduling, intake, and two-way messaging. As that “digital front door” expands, the easiest attack isn’t always the EHR itself. It’s the communication channel around it.

When the portal becomes the front desk, portal identity becomes a control surface, not a UX detail.

Portal impersonation turns patient communications into an operational risk metric

Modern Healthcare’s reporting describes scammers using the trust of a familiar brand, MyChart, to reach patients by email, SMS, and phone. For operators, that’s a reminder that patient identity workflows are now entangled with call-center load and revenue-cycle rework, because confused patients don’t file a ticket, they call the clinic, the billing office, or the nurse line.

That downstream work is measurable. Even when the technical compromise is avoided, a phishing campaign can spike inbound contacts, increase password reset volume, and force staff to handle edge cases around account lockouts and disputed balances. Those are labor costs that rarely appear in a security budget line, but they hit access and service KPIs immediately.

It also changes what “good” looks like for patient engagement. If an organization is pushing for higher portal activation rates, more SMS reminders, or faster self-pay collections, then the same levers increase message volume and create more opportunities for a convincing impersonation. The operational benchmark is no longer just open rates or portal logins, it’s fraud attempts detected per 10,000 outbound messages and the time-to-containment for a patient-facing scam.

CMS’s voluntary pledges raise the stakes for trustworthy identity and data exchange

CMS is trying to accelerate a different, adjacent objective: smoother data flow. STAT reported July 28 that the agency’s Health Tech Ecosystem reviewed a year of progress and announced eight new pledge categories aimed at advancing interoperability through industry commitments rather than federal regulation. The article framed the initiative as a push to move healthcare away from manual, clipboard-style intake and toward more automated data exchange.

Interoperability programs tend to focus on APIs, networks, and standards. But phishing that mimics portal communications exposes a weak link: trust. If patients can’t confidently tell a legitimate portal message from a fake one, adoption of digital intake and self-service features can stall, and contact centers become the de facto safety net.

For CIOs and patient-access leaders, the two storylines connect in contract language. Voluntary pledge frameworks, even when not mandatory, often show up in vendor roadmaps and RFP responses. Meanwhile, impersonation scams force buyers to get more explicit about identity proofing, notification governance, and sender authentication in the same portal and interoperability scope that is being expanded to reduce administrative friction.

What to change in portal operations and vendor governance now

Modern Healthcare’s account of hospitals warning patients about MyChart-themed scams is also a governance test. Patient-facing incidents cross silos fast: IT security detects patterns, communications writes the warning, patient access fields questions, and revenue cycle handles disputed transactions.

Organizations that treat this as a “security awareness” issue alone can end up repeating the same scramble each time a campaign resurfaces. The better posture is to treat portal messaging as a managed channel, with defined owners, controls, and audit trails, much like claims transactions or lab interfaces.

  • Confirm who owns outbound sender identity across domains and short links used for portal notifications. That includes DMARC policy, approved sending services, and the change-control process for templates and URLs.
  • Ask Epic and any third-party messaging vendors what telemetry is available for patient-facing fraud detection. The decision point is whether the health system can correlate spikes in password resets, failed logins, and call-center contacts to specific campaigns fast enough to publish targeted guidance.
  • Recheck portal enrollment and account recovery workflows. If identity proofing is weak at activation or reset, phishing shifts from “annoying” to “account takeover,” and the operational cost moves from contact handling to remediation and patient trust repair.
  • If interoperability pledges are influencing roadmap discussions, write specific security and identity requirements into interface and portal statements of work. Voluntary initiatives still have procurement consequences when they change what vendors offer by default.

Featured companies

Your experts belong here

Every story in MarketScale Healthcare starts with a company putting its clinicians, service-line leaders, and field engineers on the record. Buyers are already reading this topic. The only question is whose experts they find.

Service-line buyers vet vendors quietly, and your clinicians become the proof they find while doing it.

Get your team featuredSee how it works15 minutes, straight to a calendar.

About the author

MarketScale Newsroom
MarketScale NewsroomEditorial Team, MarketScale

The MarketScale Newsroom reports on the companies, technologies, and trends shaping 16 B2B industries. It turns primary sources and expert commentary into clear, useful coverage for the people doing the work.

Follow Healthcare Insights

Get new expert content in your inbox.

Healthcare: are you visible to AI?

Before they reach out, Healthcare buyers ask AI engines which vendors to trust. See how AI describes your company today, and where competitors show up instead.

Free workspace

You just read one Healthcare expert. Your company is full of them.

This article was produced through MarketScale. The same platform turns your clinicians, service-line leaders, and field engineers into the articles, video, and social content Healthcare buyers are searching for. Create a free workspace and see it with your own people. No credit card, no demo required.

NPS +73 · 1,000+ creators · 38+ countries

What you get, free

Your own MarketScale Studio workspace
One video edit a month, on us
AI writing, editing, and publishing tools
In-platform coaching to learn the system

More Healthcare Insights

AAO-HNSF hearing loss guideline moves audiograms and amplification into primary care

AAO-HNSF’s new age-related hearing loss guideline calls for screening adults starting at age 50 and escalating to otoscopy, audiogram, and appropriately fit amplification. It shifts hearing loss from “patient complaint” to a routine primary-care workflow. The pressure shows up in audiology capacity, referral design, and documentation standards.

  • 01Screening at age 50 becomes a repeatable workflow, so capacity planning shifts from episodic ENT referrals to steady primary-care volume, especially where annual wellness visits are a dominant access point.
  • 02The guideline’s escalation sequence, screen, otoscopy, audiogram, amplification, then cochlear implant candidacy evaluation, creates a measurable funnel that health systems can instrument in the EHR and manage like any other pathway.
  • 03Asymmetric loss remains a separate trigger for MRI in many settings, and 2026 pre-proof work using NHANES and SEER highlights why imaging criteria choices can swing scan volume, a budgeting and radiology access issue, not a clinical footnote.

Sep 7, 2026

ADHA shifts My Health Record to multi-supplier ops as Accenture signs new 3-year contract

ADHA shifts My Health Record to multi-supplier ops as Accenture signs new 3-year contract

Accenture will keep supporting Australia’s My Health Record under a new three-year contract. ADHA is moving the platform to a multi-supplier operating model. The shift raises questions about shared integration discipline, tooling, and accountability when changes hit production.

  • 01Multi-supplier delivery is spreading across national-scale health platforms, as ADHA's My Health Record shift shows, moving risk from vendor selection to integration, runbooks, and accountability.
  • 02GenAI model upgrades are arriving with healthcare-specific claims, but the procurement work moves to evidence, safety controls, and monitoring once models sit inside clinical workflows.
  • 03Embedded AI expands the cyber asset inventory problem: if teams cannot discover the AI components across endpoints and devices, they cannot reliably secure or audit them.

Sep 7, 2026

Hospitals need a shortlist as cardiology AI clearances hit 225

Hospitals need a shortlist as cardiology AI clearances hit 225

Cardiology now has 225 FDA-cleared AI algorithms when imaging is included. That volume is the problem. Health systems now need tighter governance, integration checks, and clinical workflow evidence to decide what ships.

  • 01The useful benchmark for governance committees is scale: FDA-cleared AI totals 1,524 overall, with radiology at 1,163 and cardiology at 225 when CV imaging is included, according to Cardiovascular Business.
  • 02Procurement risk is shifting from “is it cleared?” to “where does it run?” because new clearances span cath lab guidance, echo quantification, remote monitoring, and image assessment tools that touch different systems of record.
  • 03AliveCor shows the long game: Healio reported 510(k) clearance for an ECG AI suite in 2020, and Cardiovascular Business listed a new clearance in 2026, a reminder to vet update cadence and post-clearance support.

Sep 7, 2026

Explore More Healthcare Insights

Read more expert perspectives from across Healthcare.

Browse Healthcare Hub

About the Expert

MarketScale Newsroom
MarketScale Newsroom

Editorial Team

MarketScale

The MarketScale Newsroom reports on the companies, technologies, and trends shaping 16 B2B industries. It turns primary sources and expert commentary into clear, useful coverage for the people doing the work.

For B2B teams

Your experts could be publishing here

Stories like this one run on content MarketScale captures from real practitioners. See how your team's expertise becomes coverage in Healthcare and beyond.

Book a 15-minute demo

Or call us. No forms required. We pick up. 214-945-2512