# Epic’s MyChart phishing wave is pushing patient-access teams to treat portal identity as a security perimeter

By MarketScale Newsroom · Published 2026-08-25 · Healthcare on MarketScale
Canonical: https://www.marketscale.com/industries/healthcare/epics-mychart-phishing-wave-is-pushing-patient-access-teams-to-treat-portal-identity-as-a-security-perimeter

> Hospitals are warning patients about MyChart impersonation scams as CMS keeps pressing industry-led interoperability pledges. Portal identity is becoming an ope

## Key points

- Hospitals are experiencing phishing scams that mimic Epic’s MyChart portal.
- The CMS continues to push for industry-led pledges toward healthcare interoperability.
- Patient portal identity is being prioritized as a critical aspect of cybersecurity.

Hospitals are telling patients to ignore suspicious emails, texts, and calls that claim to be from Epic’s MyChart, a sign that the patient portal has become a frontline security boundary. Modern Healthcare reported Aug. 21 that health systems are issuing public warnings as scammers pose as MyChart to solicit information or payments.

The timing matters. Many health systems are expanding portal use beyond lab results into billing, scheduling, intake, and two-way messaging. As that “digital front door” expands, the easiest attack isn’t always the EHR itself. It’s the communication channel around it.

> When the portal becomes the front desk, portal identity becomes a control surface, not a UX detail.

## Portal impersonation turns patient communications into an operational risk metric

Modern Healthcare’s reporting describes scammers using the trust of a familiar brand, MyChart, to reach patients by email, SMS, and phone. For operators, that’s a reminder that patient identity workflows are now entangled with call-center load and revenue-cycle rework, because confused patients don’t file a ticket, they call the clinic, the billing office, or the nurse line.

That downstream work is measurable. Even when the technical compromise is avoided, a phishing campaign can spike inbound contacts, increase password reset volume, and force staff to handle edge cases around account lockouts and disputed balances. Those are labor costs that rarely appear in a security budget line, but they hit access and service KPIs immediately.

It also changes what “good” looks like for patient engagement. If an organization is pushing for higher portal activation rates, more SMS reminders, or faster self-pay collections, then the same levers increase message volume and create more opportunities for a convincing impersonation. The operational benchmark is no longer just open rates or portal logins, it’s fraud attempts detected per 10,000 outbound messages and the time-to-containment for a patient-facing scam.

## CMS’s voluntary pledges raise the stakes for trustworthy identity and data exchange

CMS is trying to accelerate a different, adjacent objective: smoother data flow. STAT reported July 28 that the agency’s Health Tech Ecosystem reviewed a year of progress and announced eight new pledge categories aimed at advancing interoperability through industry commitments rather than federal regulation. The article framed the initiative as a push to move healthcare away from manual, clipboard-style intake and toward more automated data exchange.

Interoperability programs tend to focus on APIs, networks, and standards. But phishing that mimics portal communications exposes a weak link: trust. If patients can’t confidently tell a legitimate portal message from a fake one, adoption of digital intake and self-service features can stall, and contact centers become the de facto safety net.

For CIOs and patient-access leaders, the two storylines connect in contract language. Voluntary pledge frameworks, even when not mandatory, often show up in vendor roadmaps and RFP responses. Meanwhile, impersonation scams force buyers to get more explicit about identity proofing, notification governance, and sender authentication in the same portal and interoperability scope that is being expanded to reduce administrative friction.

## What to change in portal operations and vendor governance now

Modern Healthcare’s account of hospitals warning patients about MyChart-themed scams is also a governance test. Patient-facing incidents cross silos fast: IT security detects patterns, communications writes the warning, patient access fields questions, and revenue cycle handles disputed transactions.

Organizations that treat this as a “security awareness” issue alone can end up repeating the same scramble each time a campaign resurfaces. The better posture is to treat portal messaging as a managed channel, with defined owners, controls, and audit trails, much like claims transactions or lab interfaces.

- Confirm who owns outbound sender identity across domains and short links used for portal notifications. That includes DMARC policy, approved sending services, and the change-control process for templates and URLs.
- Ask Epic and any third-party messaging vendors what telemetry is available for patient-facing fraud detection. The decision point is whether the health system can correlate spikes in password resets, failed logins, and call-center contacts to specific campaigns fast enough to publish targeted guidance.
- Recheck portal enrollment and account recovery workflows. If identity proofing is weak at activation or reset, phishing shifts from “annoying” to “account takeover,” and the operational cost moves from contact handling to remediation and patient trust repair.
- If interoperability pledges are influencing roadmap discussions, write specific security and identity requirements into interface and portal statements of work. Voluntary initiatives still have procurement consequences when they change what vendors offer by default.

## Sources

- [Epic MyChart phishing scam prompts hospital warnings](https://www.modernhealthcare.com/health-tech/cybersecurity/mh-epic-mychart-phishing-scam-hospitals/) (Modern Healthcare)
- [CMS evaluates one year of health tech progress, announces eight new pledge categories](https://www.statnews.com/2026/07/28/medicare-medicaid-evaluates-health-tech-progress-unveils-eight-pledge-categories/) (STAT)
- [Health Tech](http://www.modernhealthcare.com/health-tech/) (Modern Healthcare)

Tags: [object Object], [object Object], [object Object], [object Object], [object Object], [object Object], [object Object], [object Object], [object Object], [object Object], [object Object], [object Object]

---
Source: MarketScale, https://www.marketscale.com/industries/healthcare/epics-mychart-phishing-wave-is-pushing-patient-access-teams-to-treat-portal-identity-as-a-security-perimeter. Published for AI indexing and citation; cite the canonical URL. Site guide for agents: https://www.marketscale.com/llms.txt
