HumanVerified is in beta — free while we build it.Help us make it better →
Small BusinessHealthcare & TelehealthSep 17, 20264 min read

Patient Portal Impersonation Is a Practice Operations Problem Before It Is a Security One

Epic says the portal itself is fine — scammers are copying the brand. For a multi-provider group, the cost shows up as no-shows, delayed care, and administrative time.

Listen to this article
Audio narration
Narrated in a natural voice

A patient gets a text saying there is a new message in her portal. She does not click it, does not log in to check, and does not call, because she was taught not to trust numbers that arrive in texts. Three weeks later she misses a follow-up nobody realized she had never confirmed. Patient portal impersonation did that without stealing a credential.

What Epic Warned MyChart Users About in September

On September 2, 2026, UC Davis Health published a warning that scammers are impersonating the MyChart patient portal — fake emails, texts, phone calls, and counterfeit websites built around the MyChart name and logo. Trevor Berceau of Epic Systems, quoted in the notice, said the company has "seen an uptick in scammers trying to trick patients by using the MyChart name or logo to make emails, text messages, phone calls, and websites look official."

His second remark is the one worth reading twice. Scammers, he said, are "taking advantage of the popularity of the MyChart brand rather than any security concern." The portal is not what failed. What is under attack is the recognizability of the thing patients were told to trust, which hardening your own systems does not touch.

Patient Portal Impersonation Costs You in Appointments, Not Logins

A January 2026 report from Tebra, surveying 500 Americans and 500 healthcare professionals, put numbers to the part administrators feel. The finding that matters operationally is not about scam messages but about real ones: 53% said they had ignored or delayed responding to a legitimate healthcare message because they worried it might be a scam. Among Baby Boomers that figure was 83%.

The staff-side answers line up. In the same survey, 23% of healthcare workers said scams had caused missed appointments and 20% said they had caused delayed care, while 27% estimated that 5% to 10% of administrative staff time goes to sorting out scam-related confusion. That is a practice expense, not a security statistic, and a group that would escalate a breach within the hour will absorb it indefinitely, because it never arrives labeled.

Your Practice Sends Mail From Forty People the Patient Has Never Met

A solo clinician has one identity problem and one answer to it: the patient knows her. A twelve-provider group with a front desk, billing, referral coordination, prior authorization, and an outsourced revenue cycle vendor has a different problem, and it gets worse with every hire.

Patients at a practice that size hear from a scheduler about moving a visit, a prior-auth coordinator about a medication the plan is questioning, a billing specialist about a balance, and a telehealth clinician they will meet once. Every one of those contacts is legitimate. Not one comes from a name the patient can place, and her only way to check is a number she found in the message.

Offboarding runs the problem backward. When a care coordinator leaves in March, her name is still attached to months of messages in patients' inboxes, and nothing tells those patients that mail arriving under her name today should be read differently than mail from February.

Your Security Program Covers the Portal, Not the Patient's Judgment

To the compliance lead or IT manager who maintains it, the practice's security program is a familiar document: risk analysis, access controls, encryption, audit logging, workforce training, business associate agreements with every vendor that touches protected health information.

Reread it with the outbound question in mind and a gap appears. It describes, carefully, how the practice protects data it holds. It says almost nothing about how a patient, covered by none of those controls, decides whether a message claiming to come from the practice is real. That is a category the HIPAA Security Rule was never written to address, and it is where the missed appointments come from.

Verification Is Not Detection

Precision matters here, because overclaiming does real damage. A Human ID does not detect AI. It cannot tell a patient whether a message was drafted by a model or a voice on a call was cloned. HumanVerified confirms that a communication was personally reviewed and authorized by the person shown. It does not certify the accuracy of the content, and it does not claim the message was written without the help of artificial intelligence.

AI can help write the message. Verification tells you who is willing to stand behind it. For a patient holding an unexpected text about a balance or an appointment change, that narrow fact is the useful one: not whether the message is well written, but whether a real person at her practice put their name on it, with somewhere to check that is not the message itself. Our verification policy is explicit about where that line sits.

It carries nothing clinical — a name, a title, and a status, not a chart or a balance. For a compliance lead, that is the point: a way to confirm identity without standing up another system holding protected health information.

What Rollout Looks Like Across a Clinical Staff

Issue IDs at onboarding, in the same checklist that creates the EHR login and the badge. Revoke them at offboarding, so a departed coordinator's name stops carrying the practice's authorization the day she leaves. Put the ID in the standard signature for everyone who contacts patients, not only the physicians — schedulers and billing staff are the names a patient is least equipped to place.

Then decide which messages get a per-message verification code rather than a permanent ID alone. The list is short: anything changing payment or billing instructions, anything requesting documents or card details outside the normal portal flow, and first contact from someone the patient has never dealt with.

Groups rolling this out across a staff rather than one clinician can start at for organizations. None of this stops anyone from sending a convincing text with a practice's name on it. It gives the patient receiving it somewhere to look that is not the text.

Verify your team's communications

Give every person on your team a verifiable identity your clients can check in seconds. Free during beta.

Request organization access

More Commentary