Skip to content

Product1 publisher3 min readPublished

A fake MyChart 'Medicare Kit' pulled dozens of hospital systems into scam warnings

The money leaves by card and not by password, which puts this portal impersonation wave in the hands of hospital comms teams that neither wrote the software nor control the sender addresses. Epic's answer is the guidance it already published.

The Product Desk · Product desk

What happened

  • Gizmodo reports that dozens of hospital systems across the United States issued warnings in the past two weeks about a phishing email dressed up to look as though it came from MyChart.
  • MyChart is built by Epic Systems and is the most widely used patient portal in the country, so the impersonated brand appears in front of patients at thousands of unrelated providers.
  • A Gizmodo FOIA request to the Federal Trade Commission returned 166 consumer complaints about MyChart filed over five years, and not every one of them concerns a phishing attempt.
  • The emails arrive with subject lines such as "Your MyChart Medicare Kit Awaits!" or references to a "Senior Health Package", and offer an official-sounding home health kit under annual wellness benefits.
  • Two complainants aged 70 to 79, in Illinois and Minnesota, told the FTC in July 2026 that they took a MyChart survey and then entered card details to cover shipping for the promised kit.

Compiled by The Product DeskSomething wrong?How this is made

Why it matters

  • constraint The provider carries the patient relationship but not the impersonated brand, so the notice has to come from the hospital while sender authentication and in-portal verification sit with Epic.
  • decision Because the loss happens at the card and not at the login page, telling patients to reset their portal password is the wrong first instruction, and the bank call is the one that matters.
  • exposure The people at risk here never touched the portal, so they surface in card disputes and family phone calls rather than in any security signal a health system already watches.
  • precedent With the vendor's contribution being published guidance, the practical response settles into evergreen copy on the login screen, maintained on an ongoing basis instead of drafted as an incident bulletin.

The Minnesota complainant checked her credit card app a few minutes after submitting the form, and the charge had already posted as an animal or pet service [10]. Neither of the two complaints Gizmodo published describes anyone typing a MyChart password; both describe a survey followed by card details entered to cover shipping [13]. A health system watching its own portal for trouble would see none of this. There is no spike in failed logins to find, because the patient never went near the portal.

The federal paper trail is thinner than the response suggests. The five-year FTC file works out to about 33 complaints a year, roughly one every 11 days [12]. Hospital notices went out on a much faster clock than that [1], and Gizmodo dates the acceleration to the past two months [4]. What the complaint count measures is the subset of people who worked out what had happened and then knew which federal agency to tell.

The lure works because it sits next to something real. Medicare does mail a Welcome to Medicare package with a letter, a booklet and a Medicare card when someone signs up, at no cost, and it looks nothing like a kit [7]. The scam adds the pressure a genuine benefits mailing has no reason to apply: limited allocated inventory for your zip code, and 48 hours before the unclaimed package is reassigned to the next member on the waiting list [6].

The person who has to answer for this on Friday is a communications lead at a system that did not write the software and cannot revoke the sender's domain. Epic, asked by Gizmodo, pointed at guidance it already publishes: replace the card if you entered one, and disconnect the computer and have it inspected if you ran a program or typed sensitive details into the page [11]. That is remediation for someone already caught; drafting Monday's patient email still falls to the communications lead.

Two questions sort the traffic: what the message asks for, a credential or a payment, and whether the patient can confirm the ask inside the portal they already have. A payment the portal cannot confirm belongs with the bank and a new card number, which is where both of these complaints sit [8]. A credential the portal cannot confirm belongs with a reset and an MFA review. Anything the message centre does confirm is your own billing department. That is the argument for writing the standing line about location rather than content, because location is the part patients can check without judging a subject line.

The standing line belongs on the login screen, left in place rather than rewritten every time a wave breaks. It costs something real: patients trained to distrust email from you get slower on the messages you need them to open, and appointment reminders take that hit first. The Illinois complainant recognised the scam and then received the identical offer from a fresh address [8]. Sender addresses rotate faster than notices get written, making patient-portal impersonation a recurring comms line, not a single incident.

What to watch

  • Whether the FTC's MyChart complaint count jumps once the recent filings clear the FOIA pipeline, which would tell you how badly the file lags the wave.
  • Whether Epic moves from published guidance to something hospitals can point patients at, such as sender authentication or in-portal verification of benefits messages.
  • Whether the next round swaps the shipping fee for a credential page, which would move remediation from card replacement to account takeover for every system that warned patients.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories