Cybersecurity Alert Issued as Scammers Target Patient Portal Users

Industry Pulse News Desk · 2026-08-29

Cybersecurity Alert Issued as Scammers Target Patient Portal Users

Fraudulent campaigns are manipulating patient trust in digital health platforms to extract sensitive personal and financial data.

Cybersecurity specialists are issuing alerts over fraudulent schemes targeting patients who rely on digital health portals to communicate with their healthcare providers. Rather than exploiting technical software vulnerabilities, attackers are deploying social engineering tactics designed to abuse patient trust in established medical communication channels.

The fraudulent activity specifically leverages the widespread adoption of digital patient access platforms, including Epic Systems Corporation's MyChart portal, which is utilized by major hospital networks and clinics across the United States. Scammers send deceptive text messages, emails, or direct communications that closely resemble official notifications regarding unpaid bills, prescription updates, or upcoming appointments.

Security analysts note that senior citizens and individuals managing complex medical conditions are particularly susceptible to these deceptive requests. Attackers often instill a false sense of urgency, prompting victims to click on malicious links or disclose sensitive personal identifiers, insurance information, and financial account details.

In response to the rising frequency of these impersonation attempts, healthcare providers are enhancing patient awareness campaigns and advising users to exercise heightened caution. Health administrators stress that legitimate portals rarely demand immediate financial payment or credential confirmation through unverified third-party messaging links.

Medical facilities are encouraging patients to independently verify any suspicious portal notifications by contacting their clinical care teams directly via established telephone lines. Software developers and health systems also continue to review security controls to better detect and prevent external domains from imitating official patient access environments.