Particle.news
Download on the App Store

Scammers Impersonate MyChart To Phish Patients' Logins and Payments

Health systems, Epic and the Pennsylvania attorney general warned that the campaign can harvest credentials and push malware so patients should stop clicking unsolicited MyChart links.

Overview

  • Health systems including Penn Medicine, the Pennsylvania Office of Attorney General and Epic publicly warned on Aug. 27–28 that phishing emails and texts posing as MyChart have targeted thousands of patients.
  • The messages use familiar triggers like new test results, appointment or billing notices and a fake 'MyChart Medicare Kit' to persuade recipients to click links and enter personal information.
  • Investigators found fake sign‑in pages that harvest usernames and passwords and scam pages that instruct users to run keyboard shortcuts or download programs that can install clipboard/keystroke malware.
  • Epic says there is no evidence the MyChart platform itself was breached, but officials tell anyone who entered credentials or payment data to reset passwords, contact their provider, and report suspected fraud.
  • Authorities advise accessing MyChart only through the official app or a bookmarked site, checking full sender addresses and URLs before clicking, never sharing passwords or codes, and monitoring medical and insurance accounts for unauthorized activity.