Open House Saturday, Aug 15 | Explore Career Pathways in Technology, Nursing, Healthcare, and More in   Learn More

Fake MyChart Emails Are Stealing Patient Identities. Here's How to Catch Them.

Fake MyChart Emails Are Stealing Patient Identities. Here's How to Catch Them.

Scott Gibson 13News Now In The News Image

A phishing scam spreading across the country is disguising itself as a typical MyChart message, and one wrong click can hand an intruder everything they need to steal your information and your identity.

Scott Gibson, a Computer and Information Science faculty member at ECPI University, spoke with 13News Now about how the scheme works and how patients can protect themselves. 13News Now is the NBC affiliate serving Hampton Roads and southeastern Virginia.

Reporter Derek Lytle covered the threat in a segment on the MyChart phishing scam. Watch the full report to learn how to protect yourself against identity theft.

How does the MyChart phishing scam actually work?

The scam starts with an email built to look exactly like a real MyChart notification. It creates a sense of urgency, pushing you to click a link and log in right away.

That link leads to a counterfeit website that mirrors the real portal. Once you enter your credentials, criminals capture your login and the HIPAA-protected health information tied to your account. From there, Gibson says, they have what they need to impersonate you, open loans and credit cards, finance a car, or otherwise steal your identity.

The tell is often something small and unnoticeable, such as a single altered character in the web address. A domain like MyChartt.com or MyCharto.com reads as legitimate at a glance, and one letter off is exactly what most people miss.

Gibson's recommended defense is simple. Find the organization's real phone number online, call, and ask whether the message came from them. Nearly every time, he says, the answer is that it didn't. He also suggests running security software on home devices that includes firewall protection and can detect a phishing attempt in progress.

How is ECPI University training students to defend against threats like this?

ECPI University trains students to spot and stop threats like phishing through its cybersecurity program. Students learn by doing rather than memorizing, so they graduate having already worked through the kinds of attacks they will see on the job, from fake emails to network break-ins.

Recognizing a scam email is just the entry point. Students also learn to assess risk across entire systems and investigate how breaches happen, building the judgment to defend an organization at every level.

Technology is evolving fast, and the growing role of AI is reshaping cybersecurity along with it. To keep pace, ECPI University integrates AI into its cybersecurity coursework. Students use AI-enhanced tools for tasks like vulnerability detection and network defense, alongside a foundation in machine learning.

With cyber threats and data breaches on the rise, keeping systems and information secure has become a top priority for organizations everywhere.