Over the past several weeks, 41 health systems, from Cleveland Clinic and Northwell Health to Mass General Brigham, Penn Medicine, and Sentara Health, have all sent out some version of the same warning. Patients are receiving emails and text messages with subject lines like "Your MyChart Medicare Kit Awaits!," dangling a free senior wellness package in exchange for a click.
The messages don't come from Epic, the company behind MyChart. They don't come from the hospital. They come from scammers who have figured out something simple and effective: patients trust their care team's name more than they trust their own instincts.
That's the real story here, and it's bigger than one phishing campaign.
A trusted name, borrowed without permission
MyChart works as a brand precisely because patients believe messages that carry it. Years of legitimate use (appointment reminders, lab results, billing notices) have trained people to treat that name as safe. Scammers aren't breaching any system to exploit that trust. They're simply putting a familiar name on an envelope and letting years of institutional credibility do the persuading for them.
The tactics are almost beside the point. Sure, the messages have telltale grammatical slips and unsolicited "free package" offers built to appeal to Medicare-age patients. But brand impersonation scams don't need to be sophisticated to work, because they aren't attacking a system. They're attacking a relationship. Every version of this scam that gets caught only means the next one gets a little more polished.
And when patients can no longer tell the difference between a message from their care team and a message from someone impersonating their care team, the damage doesn't stay contained to the individual who got fooled. It spreads to the brand itself. Every patient who deletes a legitimate portal message out of new suspicion, every patient who calls the front desk to ask "is this real?," every patient who quietly stops trusting the portal altogether: that's a health system's own communication channel being eroded by someone else's fraud.
Why "watch for bad grammar" isn't a strategy
The standard advice health systems are giving patients right now (don't click unfamiliar links, check the sender address, be skeptical of free offers) is necessary, but it's also an admission of a structural problem: there is no reliable way for a patient to know, at a glance, whether a message claiming to be from their health system actually is one.
The burden of verification has been placed entirely on the person least equipped to carry it. Patients, particularly older patients who are frequently the explicit target of these campaigns, are being asked to become amateur fraud analysts every time an email lands in their inbox. That's not a sustainable defense. It's a stopgap while the underlying gap (the absence of a real, verifiable link between a communication and the institution it claims to come from) stays wide open.
The same gap exists in reverse, too. When a patient calls in, resets a password, or accesses an account, most health systems still rely on the same brittle building blocks scammers have already learned to exploit: something the patient knows (an address, a date of birth, the last four of a Social Security number), all of which is widely available on the exact same data-broker and breach markets that fuel these phishing campaigns in the first place. Knowledge-based verification was never designed for a world where the "secret" information isn't secret anymore.
Identity has to be the foundation, not an afterthought
Solving this doesn't mean training patients harder or writing sterner warning emails. It means building identity verification into the relationship itself, so that trust isn't something patients have to guess at. It's something the system can actually confirm.
That starts with verifying who a person really is at the moments that matter most: when an account is created, when access is recovered, when a high-risk change is requested. Instead of relying on static, breachable facts, real identity verification checks something a scammer can't simply purchase or guess: government-issued credentials, biometric matching, signals that confirm a real, living person is who they claim to be. That single shift closes off the easiest path scammers have into patient accounts, regardless of how convincing their emails get.
It also means giving health systems a way to know, with confidence, who is really on the other end of an interaction, before a password reset happens, before sensitive records move, before a "free Medicare kit" scam has any account to actually compromise even if a patient does click through. Strong identity verification doesn't just block fraud at the door; it removes the payoff that makes these campaigns worth running in the first place. When the account itself is well protected, credential-phishing has nowhere to go.
And critically, this protects something health systems can't easily win back once it's lost: patient confidence in the portal brand itself. A verified, trusted identity layer means patients don't have to become the last line of defense. The institution can stand behind its own name again, because there's a real mechanism (not just a warning banner) ensuring that name can't be casually borrowed by whoever sends the next wave of emails.
The scam will change. The gap won't, unless it's closed.
Most firms already have basic safety rules for their workers and apps. But these old rules do not always work for AI agents. NIST states that identification and authorization controls are needed to lower risks. Firms must adapt their current ways to fit how agents work. This means looking at how agents log in and what files they can touch. It is about making sure the agent has only the access it needs.
Modern fintech stacks are complex and have many parts. Agents often move between different clouds and services. This movement makes it hard to keep track of what they do. By using KYA controls, firms can map out every action an agent takes. This level of detail is needed to stop modern cyber attacks. It also gives the firm peace of mind that their systems are secure.
AI agents can speed up money tasks and cut costs. But these tools also bring new risks. Without the right Know Your Agent KYA security controls, a fintech cannot tell if an agent is safe. The goal is to build trust in every online step.
