← Back to AI Health Hub

Why Patient Portals Are Failing Security

When patient portals become the perfect disguise for cybercriminals, health systems must realize that warning users to "be careful" is no longer a viable security strategy.

When patient portals become the perfect disguise for cybercriminals, health systems must realize that warning users to “be careful” is no longer a viable security strategy.

For years, healthcare providers pushed patients to manage their medical lives through digital portals. Now, that centralized trust is being weaponized. A massive phishing campaign impersonating Epic’s MyChart has targeted patients across more than 40 health systems, including Penn Medicine and UC Davis Health.

This is not a technical breach of Epic’s servers. It is a brand impersonation attack. Cybercriminals are using fake Medicare reward lures and highly polished login pages to steal credentials.

The Enrollment Trap

The timing is highly calculated. The scam targets older adults just ahead of the Medicare open enrollment period starting October 15. This is when healthcare communication naturally spikes, making fraudulent emails blend in seamlessly.

The American Hospital Association and state attorneys general have issued alerts. Yet, public warnings do not fix the underlying design flaw of modern patient communication.

Shift the Burden

For too long, cybersecurity has treated the patient as the final firewall. Expecting elderly patients to spot sophisticated domain variations is a losing battle.

If security relies on a patient’s ability to analyze a URL, the system is already broken.

Providers must shift from reactive warnings to structural changes. This means actively training patients to bypass email links entirely and access portals only through official apps. When trust is the primary currency of digital health, a compromised interface erodes the clinical relationship itself.

This article is for informational purposes only and is not a substitute for professional medical advice, diagnosis or treatment.