- Fake patient portal messages are being used to steal logins and spread malware
- Scams are copying MyChart branding and pushing urgent medical claims
- Some fake pages ask Windows users to run dangerous commands
- Another scheme dangles a bogus Medicare health kit to collect personal data
- Simple safety habits can help stop phishing before it turns into a bigger problem
If a medical message suddenly feels urgent, that is exactly the moment to slow down. A growing wave of fake patient portal scams is using trusted names like MyChart to trick people into handing over passwords, personal details, and in some cases even letting malware onto their computers.
Patient portals have become part of normal life for millions of people, which makes them a perfect target. Lab updates, appointment reminders, and test-result alerts now arrive by email and text so often that a fake one can blend right in. Criminals are banking on that routine, and they are leaning hard on fear to get quick clicks.
What makes this scam stand out is how polished it looks. Some versions copy MyChart branding and use a message that says, “Your recent results are ready.” The link sends people to a fake login page that looks close enough to the real thing to catch someone who is rushing.
After that, the pressure ramps up. The fake site may show a made-up medical warning, including claims that an AI review found something serious in blood work. That kind of message is designed to hit fast and hard, because people will often click before they stop to question it.
The most dangerous part comes next. Epic has documented versions of the scam that tell Windows users to open the Run box, paste content from the clipboard, and press Enter. That is not a patient verification step, it is a trap, and following those instructions can install malware on the computer.
Another version takes a different route but aims for the same result. It promises a free “2026 Medicare Health Kit” or a similar giveaway, then drags the victim through fake survey pages, countdown timers, and shipping fees. By the end, the scam has gathered personal details and may also ask for credit card information.
These messages can feel believable because people already expect legitimate communication from doctors, hospitals, and insurance programs. A real test result can arrive at the same time as a fake one, which makes the scam look normal at first glance. That is the whole trick, using familiar health care communication to lower your guard.
The safest move is to ignore the pressure and open the portal yourself. Do not use the button in the message, even if it looks polished or urgent. Go to the MyChart app directly, use a trusted bookmark, or start from your provider’s official website instead.
It also helps to check the sender closely. A display name can say MyChart while the actual address points somewhere else entirely. If the message feels off, contact the office through a phone number or website you already trust and confirm whether the alert is real.
There is one rule that should never be broken: a patient portal should not ask you to run a computer command. If a website tells you to use keyboard shortcuts, bypass a warning, or download a Windows program to view a medical result, that is a huge red flag. Close the page and do not come back to it.
Extra protection matters too. Two-step verification can make account theft harder, especially if a password gets exposed in a phishing attempt. A strong, unique password for MyChart also helps, because reusing the same login across multiple accounts can turn one stolen password into a much bigger mess.
Security software is still worth having in the background, especially when scams try to push downloads or fake alerts. Keeping Windows and your browser updated adds another layer of defense. If a message claims a serious result needs immediate attention, verify it through the real portal or call your provider before taking action.
If a fake link was already clicked, the next step depends on what happened. Close the page if nothing was entered, change the password if login details were typed, and contact the bank if payment information was shared. If a file was downloaded or a Windows command was run, disconnect the device and get it checked before doing anything sensitive on it again.
The broader warning is simple enough. Health care scams work because they sound personal, urgent, and official all at once. That is exactly why patient portal alerts deserve a second look every single time.
