Epic’s MyChart phishing wave is pushing patient-access teams to treat portal identity as a security perimeter
Hospitals are alerting patients about phishing scams involving Epic’s MyChart, as these scams impersonate the patient portal to deceive users. The concern grows as CMS encourages healthcare innovation and interoperability. As a response, healthcare teams are treating portal identity as a vital security frontier.
This story was produced through MarketScale. See how Healthcare teams put it to work with Executive Thought Leadership.
Key facts, context, and what it means, in one minute.
Key takeaways
Hospitals are experiencing phishing scams that mimic Epic’s MyChart portal.
The CMS continues to push for industry-led pledges toward healthcare interoperability.
Patient portal identity is being prioritized as a critical aspect of cybersecurity.
Get featured
Want to get featured in MarketScale Healthcare?
Create a free MarketScale workspace and get your company's expertise featured across our Healthcare coverage. No credit card, no demo required.
Hospitals are telling patients to ignore suspicious emails, texts, and calls that claim to be from Epic’s MyChart, a sign that the patient portal has become a frontline security boundary. Modern Healthcare reported Aug. 21 that health systems are issuing public warnings as scammers pose as MyChart to solicit information or payments.
The timing matters. Many health systems are expanding portal use beyond lab results into billing, scheduling, intake, and two-way messaging. As that “digital front door” expands, the easiest attack isn’t always the EHR itself. It’s the communication channel around it.
When the portal becomes the front desk, portal identity becomes a control surface, not a UX detail.
Portal impersonation turns patient communications into an operational risk metric
Modern Healthcare’s reporting describes scammers using the trust of a familiar brand, MyChart, to reach patients by email, SMS, and phone. For operators, that’s a reminder that patient identity workflows are now entangled with call-center load and revenue-cycle rework, because confused patients don’t file a ticket, they call the clinic, the billing office, or the nurse line.
That downstream work is measurable. Even when the technical compromise is avoided, a phishing campaign can spike inbound contacts, increase password reset volume, and force staff to handle edge cases around account lockouts and disputed balances. Those are labor costs that rarely appear in a security budget line, but they hit access and service KPIs immediately.
It also changes what “good” looks like for patient engagement. If an organization is pushing for higher portal activation rates, more SMS reminders, or faster self-pay collections, then the same levers increase message volume and create more opportunities for a convincing impersonation. The operational benchmark is no longer just open rates or portal logins, it’s fraud attempts detected per 10,000 outbound messages and the time-to-containment for a patient-facing scam.
CMS’s voluntary pledges raise the stakes for trustworthy identity and data exchange
CMS is trying to accelerate a different, adjacent objective: smoother data flow. STAT reported July 28 that the agency’s Health Tech Ecosystem reviewed a year of progress and announced eight new pledge categories aimed at advancing interoperability through industry commitments rather than federal regulation. The article framed the initiative as a push to move healthcare away from manual, clipboard-style intake and toward more automated data exchange.
Interoperability programs tend to focus on APIs, networks, and standards. But phishing that mimics portal communications exposes a weak link: trust. If patients can’t confidently tell a legitimate portal message from a fake one, adoption of digital intake and self-service features can stall, and contact centers become the de facto safety net.
For CIOs and patient-access leaders, the two storylines connect in contract language. Voluntary pledge frameworks, even when not mandatory, often show up in vendor roadmaps and RFP responses. Meanwhile, impersonation scams force buyers to get more explicit about identity proofing, notification governance, and sender authentication in the same portal and interoperability scope that is being expanded to reduce administrative friction.
What to change in portal operations and vendor governance now
Modern Healthcare’s account of hospitals warning patients about MyChart-themed scams is also a governance test. Patient-facing incidents cross silos fast: IT security detects patterns, communications writes the warning, patient access fields questions, and revenue cycle handles disputed transactions.
Organizations that treat this as a “security awareness” issue alone can end up repeating the same scramble each time a campaign resurfaces. The better posture is to treat portal messaging as a managed channel, with defined owners, controls, and audit trails, much like claims transactions or lab interfaces.
- Confirm who owns outbound sender identity across domains and short links used for portal notifications. That includes DMARC policy, approved sending services, and the change-control process for templates and URLs.
- Ask Epic and any third-party messaging vendors what telemetry is available for patient-facing fraud detection. The decision point is whether the health system can correlate spikes in password resets, failed logins, and call-center contacts to specific campaigns fast enough to publish targeted guidance.
- Recheck portal enrollment and account recovery workflows. If identity proofing is weak at activation or reset, phishing shifts from “annoying” to “account takeover,” and the operational cost moves from contact handling to remediation and patient trust repair.
- If interoperability pledges are influencing roadmap discussions, write specific security and identity requirements into interface and portal statements of work. Voluntary initiatives still have procurement consequences when they change what vendors offer by default.
Sources
- Epic MyChart phishing scam prompts hospital warnings ↗ · Modern Healthcare
- CMS evaluates one year of health tech progress, announces eight new pledge categories ↗ · STAT
- Health Tech ↗ · Modern Healthcare
Featured companies
Your experts belong here
Every story in MarketScale Healthcare starts with a company putting its clinicians, service-line leaders, and field engineers on the record. Buyers are already reading this topic. The only question is whose experts they find.
Service-line buyers vet vendors quietly, and your clinicians become the proof they find while doing it.
About the author
The MarketScale Newsroom reports on the companies, technologies, and trends shaping 16 B2B industries. It turns primary sources and expert commentary into clear, useful coverage for the people doing the work.