More than 40 health systems across the country have posted alerts about a MyChart phishing scam, from Cleveland Clinic and Mass General Brigham to a small hospital in Keosauqua, Iowa.
The list grew from 30 to 41 systems in three days and now includes Penn Medicine, Mount Sinai Health System, and Virtua Health. The AHA flagged the campaign the same week.
The emails target seniors specifically, offering free Medicare kits or senior wellness packages.
Epic has pointed to a July post from its director of research and development, who attributed the rise in scam attempts to the popularity of the MyChart brand rather than to any security weakness, and told patients they can keep using the portal normally.
Epic's investigation found the destination URL differs for every recipient but identified a fake company sign-off, "MyChart Health Network," as a tell.
Each health system wrote its own warning to its own patients but the alerts converge on the same three instructions: verify the sender address, watch for grammatical errors, and delete without clicking.
So What?
Epic is the leading vendor for EMRs, making it a proven partner but a recognizable target. Although there was no breach at MyChart, the burden still falls on health systems to warn patients against scams, each building its own alert page. As one CIO put at a recent Academy forum, patients see it as the health system losing their data, not the partner.
Scale is often what makes a platform the safer choice, but it also removes the alternative if something goes wrong. A system CIO described having no fallback for a critical clearinghouse partner: if it went down, there is no plan B.
Skepticism about sole-source dependencies has persisted since Change Healthcare, and procurement reviews have lengthened in response as systems tie them to formal risk assessments.
The same impersonation playbook is already aimed at systems and their executives, as C-Suite leaders are high value targets. At past THMA forums, executives have discussed finding their personal information for sale on the dark web and one system described a physician whose paycheck routing was changed by an attacker and went two pay periods before anyone noticed.
The verification methods most systems rely on are the ones these attacks are built to pass. Knowledge questions can be researched, one-time codes confirm a device rather than a person, and turnover at call centers makes consistent human judgment unreliable. Generative AI has compressed the time required to mine stolen records for the details that make an impersonation convincing.
Phishing is now the most frequently reported internet crime among older adults, accounting for roughly a quarter of the complaints adults 60+ filed with the FBI last year. As shown in the chart below, those complaints doubled in a single year. Medicare Annual Enrollment opens October 15, and Medicare-related lures are likely to keep climbing through it, when benefits mail is exactly what seniors expect to receive.
The open question is how much responsibility for protecting an aging patient panel systems should carry alone, and how much belongs in what they ask of platform partners.

