Before you respond
MyChart phishing email: fake results and health kits
A message with a MyChart logo may still be an impersonation. Use your provider's real portal to check result notices and unexpected health-kit offers.
By Olevo · Reviewed September 18, 2026
Quick answer
For a possible MyChart phishing email, open your usual patient app or saved provider portal instead of using the message link. Check there for a real notice. Do not pay shipping for an unexpected MyChart giveaway, install a report-viewing program, or follow instructions to run computer commands.
At a glance
MyChart impersonation borrows the name of a real patient portal. A fake message can ask for credentials, payment information, or a download. The message itself does not establish a medical result or a breach of the real service.
- A result requires a program download or computer command.
- A free kit leads to a payment form.
- A contact asks for your account password or verification code.
Use the provider's portal or independently sourced help desk to verify.
Check the request before the message link
Claim
New lab results are ready
What to question
A separate program is needed to unlock them
Safer route
Check the result in the real provider portal
Claim
A free health kit is reserved
What to question
You must enter card information for shipping
Safer route
Ask your provider independently about the offer
Claim
Verify that you are human
What to question
You must run commands or bypass a device warning
Safer route
Close the page and contact trusted technical help if you followed it
Two MyChart phishing email patterns to separate
Epic documents fake lab-result notices and fake health-kit offers from its summer 2026 security investigations. The first uses a copied portal and can push a download or a supposed human-verification step. The second uses a gift story to collect information and payment. These are different requests under the same familiar name.
GBMC HealthCare also warns about messages impersonating MyChart. Its guidance is to verify with the provider and protect credentials, not to assume that the real portal was hacked. A message with frightening health language is a reason to contact your care team through a trusted route, not a basis for interpreting a diagnosis.
The next step depends on what you shared
Make a short list before seeking help: whether you only opened a page, entered a password, supplied card details, or ran a program. Do not include the password or card number in that list. Contact the real account provider for access concerns and your card issuer for payment exposure. If software ran, use a trusted device for sensitive account checks.
What it may look like
Illustrative example
"Your new health report is ready. Download this viewer to unlock the full analysis."
Signs to slow down
- You are rushed into a login or payment before checking with the provider.
- An unfamiliar page gives computer-command instructions.
- A gift offer asks for more information than you expected.
What to do next
- Open your normal patient portal independently.
- Ask your provider's help desk about the notice if uncertain.
- Do not interpret an emailed claim as a medical finding; contact your care team.
- If information or device access was exposed, explain exactly what happened to the appropriate provider.
How to report it
- Use your email application's phishing or junk report option.
- Tell your healthcare provider about the impersonation through its verified contact route.
- Report financial fraud at ReportFraud.ftc.gov and contact the card issuer if payment details were exposed.
How Olevo can help
Olevo can help review the message's request, urgency, and warning signs.
Remove medical results, patient identifiers, login links, passwords, and codes before sharing a screenshot. Olevo does not access MyChart, interpret test results, or verify a healthcare provider's identity.
Trusted sources
MyChart's investigation of fake results and health-kit offers
Epic / MyChart
Epic documents two impersonation campaigns and an August 2026 fake-report download variant.
Beware of fake MyChart emails and texts
GBMC HealthCare
The healthcare provider explains independent verification and warns against sharing credentials or running commands.
Recognizing and avoiding phishing
Federal Trade Commission
Independent verification, suspicious links, and next steps after sharing information.
Common questions
Are all MyChart result emails phishing?
No. Patient portals can send notifications. Check the notice in your usual app or provider portal, rather than using the unexpected email's link. If you cannot confirm what it refers to, ask your provider's help desk through a contact route you already trust.
Does a fake MyChart message mean MyChart was hacked?
No. Impersonation alone is not evidence of a platform breach. A sender can copy a name or logo without accessing the real service. Check your own account through the provider, and distinguish a suspicious message from independently confirmed changes to your account.
Should I upload my lab results to check the message?
You do not need to share lab values or patient identifiers to ask about a suspicious request. Keep medical information private and contact your care team about actual results. For message review, describe the requested action or use a screenshot with private information removed.