Skip to content
MarketScale
‹ Back to IndustriesHealthcare

Epic’s MyChart phishing wave is pushing patient-access teams to treat portal identity as a security perimeter

Hospitals are alerting patients about phishing scams involving Epic’s MyChart, as these scams impersonate the patient portal to deceive users. The concern grows as CMS encourages healthcare innovation and interoperability. As a response, healthcare teams are treating portal identity as a vital security frontier.

This story was produced through MarketScale. See how Healthcare teams put it to work with Executive Thought Leadership.

By MarketScale Newsroom · EpicMychartHealthcare CybersecurityPhishing
Share
Learn this in 60 seconds

Key facts, context, and what it means, in one minute.

:60
0:001:00
Epic’s MyChart phishing wave is pushing patient-access teams to treat portal identity as a security perimeter

Key takeaways

01

Hospitals are experiencing phishing scams that mimic Epic’s MyChart portal.

02

The CMS continues to push for industry-led pledges toward healthcare interoperability.

03

Patient portal identity is being prioritized as a critical aspect of cybersecurity.

Get featured

Want to get featured in MarketScale Healthcare?

Create a free MarketScale workspace and get your company's expertise featured across our Healthcare coverage. No credit card, no demo required.

Request an invite

Hospitals are telling patients to ignore suspicious emails, texts, and calls that claim to be from Epic’s MyChart, a sign that the patient portal has become a frontline security boundary. Modern Healthcare reported Aug. 21 that health systems are issuing public warnings as scammers pose as MyChart to solicit information or payments.

The timing matters. Many health systems are expanding portal use beyond lab results into billing, scheduling, intake, and two-way messaging. As that “digital front door” expands, the easiest attack isn’t always the EHR itself. It’s the communication channel around it.

When the portal becomes the front desk, portal identity becomes a control surface, not a UX detail.

Portal impersonation turns patient communications into an operational risk metric

Modern Healthcare’s reporting describes scammers using the trust of a familiar brand, MyChart, to reach patients by email, SMS, and phone. For operators, that’s a reminder that patient identity workflows are now entangled with call-center load and revenue-cycle rework, because confused patients don’t file a ticket, they call the clinic, the billing office, or the nurse line.

That downstream work is measurable. Even when the technical compromise is avoided, a phishing campaign can spike inbound contacts, increase password reset volume, and force staff to handle edge cases around account lockouts and disputed balances. Those are labor costs that rarely appear in a security budget line, but they hit access and service KPIs immediately.

It also changes what “good” looks like for patient engagement. If an organization is pushing for higher portal activation rates, more SMS reminders, or faster self-pay collections, then the same levers increase message volume and create more opportunities for a convincing impersonation. The operational benchmark is no longer just open rates or portal logins, it’s fraud attempts detected per 10,000 outbound messages and the time-to-containment for a patient-facing scam.

CMS’s voluntary pledges raise the stakes for trustworthy identity and data exchange

CMS is trying to accelerate a different, adjacent objective: smoother data flow. STAT reported July 28 that the agency’s Health Tech Ecosystem reviewed a year of progress and announced eight new pledge categories aimed at advancing interoperability through industry commitments rather than federal regulation. The article framed the initiative as a push to move healthcare away from manual, clipboard-style intake and toward more automated data exchange.

Interoperability programs tend to focus on APIs, networks, and standards. But phishing that mimics portal communications exposes a weak link: trust. If patients can’t confidently tell a legitimate portal message from a fake one, adoption of digital intake and self-service features can stall, and contact centers become the de facto safety net.

For CIOs and patient-access leaders, the two storylines connect in contract language. Voluntary pledge frameworks, even when not mandatory, often show up in vendor roadmaps and RFP responses. Meanwhile, impersonation scams force buyers to get more explicit about identity proofing, notification governance, and sender authentication in the same portal and interoperability scope that is being expanded to reduce administrative friction.

What to change in portal operations and vendor governance now

Modern Healthcare’s account of hospitals warning patients about MyChart-themed scams is also a governance test. Patient-facing incidents cross silos fast: IT security detects patterns, communications writes the warning, patient access fields questions, and revenue cycle handles disputed transactions.

Organizations that treat this as a “security awareness” issue alone can end up repeating the same scramble each time a campaign resurfaces. The better posture is to treat portal messaging as a managed channel, with defined owners, controls, and audit trails, much like claims transactions or lab interfaces.

  • Confirm who owns outbound sender identity across domains and short links used for portal notifications. That includes DMARC policy, approved sending services, and the change-control process for templates and URLs.
  • Ask Epic and any third-party messaging vendors what telemetry is available for patient-facing fraud detection. The decision point is whether the health system can correlate spikes in password resets, failed logins, and call-center contacts to specific campaigns fast enough to publish targeted guidance.
  • Recheck portal enrollment and account recovery workflows. If identity proofing is weak at activation or reset, phishing shifts from “annoying” to “account takeover,” and the operational cost moves from contact handling to remediation and patient trust repair.
  • If interoperability pledges are influencing roadmap discussions, write specific security and identity requirements into interface and portal statements of work. Voluntary initiatives still have procurement consequences when they change what vendors offer by default.

Featured companies

Your experts belong here

Every story in MarketScale Healthcare starts with a company putting its clinicians, service-line leaders, and field engineers on the record. Buyers are already reading this topic. The only question is whose experts they find.

Service-line buyers vet vendors quietly, and your clinicians become the proof they find while doing it.

Get your team featuredSee how it works15 minutes, straight to a calendar.

About the author

MarketScale Newsroom
MarketScale NewsroomEditorial Team, MarketScale

The MarketScale Newsroom reports on the companies, technologies, and trends shaping 16 B2B industries. It turns primary sources and expert commentary into clear, useful coverage for the people doing the work.

Follow Healthcare Insights

Get new expert content in your inbox.

Healthcare: are you visible to AI?

Before they reach out, Healthcare buyers ask AI engines which vendors to trust. See how AI describes your company today, and where competitors show up instead.

Free workspace

You just read one Healthcare expert. Your company is full of them.

This article was produced through MarketScale. The same platform turns your clinicians, service-line leaders, and field engineers into the articles, video, and social content Healthcare buyers are searching for. Create a free workspace and see it with your own people. No credit card, no demo required.

NPS +73 · 1,000+ creators · 38+ countries

What you get, free

Your own MarketScale Studio workspace
One video edit a month, on us
AI writing, editing, and publishing tools
In-platform coaching to learn the system

More Healthcare Insights

Medicare sets $137.53 maximum add-on payment per eligible inpatient case for CT triage AI

Medicare sets $137.53 maximum add-on payment per eligible inpatient case for CT triage AI

Medicare has announced a maximum add-on payment of $137.53 per eligible inpatient case for the use of AI in CT triage, utilizing Aidoc’s CT Body triage technology. This move emphasizes the importance of workflow integration, governance, and coding in hospitals employing radiology AI. The new technology add-on payment (NTAP) signifies a clear investment in AI-driven healthcare solutions.

  • 01Medicare introduces a $137.53 per-case payment for AI in CT triage.
  • 02Hospitals must integrate AI with proper workflow, governance, and coding.
  • 03The NTAP reflects investment in radiology AI solutions.

Aug 30, 2026

Rasonque’s 13.2-month survival result is about to hit hospital formularies

Rasonque’s 13.2-month survival result is about to hit hospital formularies

FDA has cleared Revolution Medicines' drug Rasonque for treating metastatic pancreatic adenocarcinoma. Hospitals are now integrating this drug into their formularies, focusing on operations like pathways, genotyping, and specialty pharmacy flow.

  • 01Rasonque has received FDA clearance for treating metastatic pancreatic adenocarcinoma.
  • 02Hospitals are working on integrating Rasonque into their formularies.
  • 03Operational focus includes pathways, genotyping, and specialty pharmacy flow.

Aug 30, 2026

Real-time radiation dose tracking is moving from badges to live dashboards in procedure rooms

Real-time radiation dose tracking is moving from badges to live dashboards in procedure rooms

Radiation Detection Company has introduced a live radiation dose tracking system called Radiant that updates every 0.2 seconds. GE HealthCare has developed browser-based imaging access for hospitals, transforming how radiation monitoring is managed in procedure rooms. This advancement in live dashboards is enhancing real-time monitoring capabilities in healthcare facilities.

  • 01Radiation Detection Company's Radiant updates radiation dose data every 0.2 seconds.
  • 02GE HealthCare has developed browser-based imaging access for better hospital management.
  • 03Live dashboards are transforming radiation monitoring in procedure rooms.

Aug 30, 2026

Explore More Healthcare Insights

Read more expert perspectives from across Healthcare.

Browse Healthcare Hub

About the Expert

MarketScale Newsroom
MarketScale Newsroom

Editorial Team

MarketScale

The MarketScale Newsroom reports on the companies, technologies, and trends shaping 16 B2B industries. It turns primary sources and expert commentary into clear, useful coverage for the people doing the work.

For B2B teams

Your experts could be publishing here

Stories like this one run on content MarketScale captures from real practitioners. See how your team's expertise becomes coverage in Healthcare and beyond.

Book a 15-minute demo

Or call us. No forms required. We pick up. 214-945-2512