Share
PATIENT PORTAL IMPERSONATION

Is the MyChart "Medicare Kit" email real? Hospitals across the country say no.

A wave of emails is offering older patients a free Medicare kit or a 2026 senior health package, using the name of the portal they genuinely log in to. The brand is real. The offer never existed.

SafeBrowz Threat Research Security Research · · 8 min read

The short answer

It is phishing. Hospitals that run MyChart have spent the past two weeks telling their own patients the same thing: the message is not from them, and MyChart does not send Medicare kits, senior packages or free wellness bundles. There is one check that settles it without any judgement about wording, because of how MyChart is built: no generic MyChart address holds your chart. Every real one sits on the hospital system that treats you. So a link that lands anywhere other than your own hospital's address is fake by construction. Most people have never memorised that address, which is exactly the gap these emails are built on. So read where the link goes before you open it: hovering shows you the address, and if you cannot tell whether that address belongs to your hospital, a scam checker will judge the destination for you.

SafeBrowz judges the page a link opens by the domain it lives on, which is the one thing a copied logo cannot fake. Add to Chrome, free Get the free Android app or scan a URL now →

What the email says

Health systems have quoted two versions. One arrives with the subject line "Your MyChart Medicare Kit Awaits". The other refers to a 2026 MyChart Senior Health Package. Both dangle something free, both use the MyChart name, and both want a click.

From there the pattern is ordinary. The link leads to a page that wants personal details, and the details it wants are the ones that matter: name, date of birth, address, insurance information and, in the versions hospitals have described, the Medicare number itself. Some variants ask you to confirm a delivery address for the kit, which is a softer opening that reaches the same place.

Expect the wording to drift. Subject lines are the cheapest part of a campaign to change, and by the time a warning circulates, the sender has usually moved on to a new one. The offer is the constant. That is the part to fix in your memory.

Why this one works on people who are usually careful

Most phishing advice tells you to check whether you recognise the sender. That advice quietly assumes the brand will be a stranger, or a company you have a loose relationship with. Here it fails, because MyChart is not a stranger. It is the portal a patient uses to read test results, book appointments and message their doctor. Recognising the name is the wrong test, and recognising it is precisely what makes the email land.

The audience compounds it. These messages target older patients, the group for whom a Medicare-branded envelope or email is a normal thing to receive, and for whom missing a real benefit feels like a genuine cost. University Health, which warned its own patients on 18 August, described the mechanism plainly: the messages invite seniors to click prompts and follow them until personal information is exposed. Nothing about that requires carelessness.

We have written about the same shape before in a different setting. A fake Slack workspace invite works for the identical reason: the product is real, the user has an account, and the brand name is doing no filtering work at all.

The structural giveaway: your MyChart belongs to your hospital

This is the part worth keeping, because it does not depend on spotting bad grammar or a rushed logo.

MyChart is software, made by Epic and licensed to hospitals. Each health system runs its own instance on its own domain, so your records and appointments live at something shaped like mychart.yourhospital.org, or on a page inside your hospital's own website. Epic does run a central site at mychart.org, where the main action offered is "Find your MyChart", and Epic itself is at epic.com. What does not exist anywhere is a generic MyChart address that holds your chart. Your chart sits with the people who treat you.

That matters more than it first sounds. It means a link built around the word mychart on a standalone address, something like mychart-medicare-kit.com or mychart-benefits2026.net (both illustrative examples, not real reported domains), is wrong before you look at anything on the page. A real MyChart cannot live there, because a real MyChart belongs to a hospital.

So the test is not "does this look right". It is "is this my hospital's address". Those are very different questions, and only one of them has an answer you can be sure of.

Who has warned, and when

This is not a single-hospital problem. Warnings have gone out from health systems in different states, on their own patient-facing channels, over the same short window.

  • MetroHealth (Cleveland) told patients the emails referencing a 2026 MyChart Senior Health Package, Medicare wellness benefits or free health kits are fraudulent and not affiliated with MyChart or MetroHealth, and asked patients to mark them as phishing and delete them.
  • University Health (San Antonio) warned on 18 August, describing the threat as occurring nationwide.
  • SGMC Health (Georgia) alerted patients on 19 August, telling them not to click links, open attachments or reply, and to reach MyChart through the official app or the health system's own website instead.
  • Southeast Health (Alabama) reported fraudulent emails telling recipients a MyChart Medicare Kit was waiting for them, and stated plainly that the messages are not from Southeast Health and are a phishing scam built to steal personal information.

Other health systems have published near-identical notices to their own patients over the same window. When unconnected hospitals in different states warn about the same subject line within days of each other, the campaign is being sent broadly rather than aimed at one system's patient list.

What they are actually after

A Medicare number is not like a password. You cannot rotate it easily, and its value to a fraudster is that it can be used to bill for equipment, tests and services a patient never received. That is why medical identity theft tends to surface late, on a statement, rather than as an immediate loss you notice the same day.

The rest of the harvest is ordinary but useful: date of birth, address and insurance details are the raw material for opening accounts and for the next, more convincing round of contact. Anyone who filled in one of these forms should assume the information is now in circulation, and should read their Medicare Summary Notices with more attention than usual for a while.

The FTC takes reports at ReportFraud.ftc.gov, and Medicare publishes 1-800-MEDICARE (1-800-633-4227) as the line to call if you suspect fraud. Both are worth using, and both share the same property that matters here: you can reach them without touching anything in the message you are checking. Never use a phone number the suspicious message supplied.

Fifteen seconds that settle it

  1. Do not judge it by the name. MyChart is real and you probably do have an account. That tells you nothing about this message.
  2. Read where the link goes, not what it says. On a computer, hover the link and read the address that appears. On a phone, press and hold until the full address shows. The visible text of a link and its destination are unrelated.
  3. Ask one question of that address: is this my hospital? If the domain is not the health system that treats you, stop. No further analysis is needed.
  4. Go there yourself instead. Open your hospital's MyChart app, or type your hospital's address the way you normally reach it. Anything genuinely waiting for you will be there.
  5. If a portal is offering you something free, treat that alone as the tell. Patient portals hold records and appointments. They do not run promotions.

When the brand name is genuine, the address is the only thing left

Almost every consumer phishing tip is a way of asking whether the sender is who they claim. This campaign is a reminder that the question has a floor: once the impersonated brand is one you really use, recognition stops helping, and the only fact the sender cannot borrow is where their page actually lives.

That is the layer SafeBrowz works at. Layer 1 reads the shape of a link in the browser before the page renders, which catches the crude cases early. Layer 2 checks the destination server-side against reputation feeds, a brand database of more than 550 names and our blocklist, which is where the freshly registered lookalikes land. Layer 3 is the AI deep scan, a Premium feature with one free scan a day for everyone else, reading what the page actually serves, so a portal login form wearing hospital branding on a domain registered last week is judged on what it is rather than what it says it is.

Honest scope, and it matters here more than usual. We read links and pages. A MyChart-branded phone call has no link in it, and a fraudulent letter arriving in the post has nothing for us to check until a QR code is opened on a device we are installed on. And because every hospital runs its own MyChart domain, no tool can tell you which one is yours. That single fact has to come from you, once, and then it is the only thing you need.

Got a MyChart email you were not expecting? Test the address before you open it. Test a suspicious link → Get the free Android app
🛡 LIVE CHECK

Not sure if a portal link is your hospital?

Paste it here instead of opening it. Our 3-layer engine (Local + APIs + AI) returns a verdict in about 3 seconds. Free, no signup.

Full scan with deep AI analysis → · No URL is logged to your identity.

Frequently asked questions

Is the MyChart Medicare Kit email real?

No. Hospitals that run MyChart have been telling their own patients the same thing: these messages are not from them and not from MyChart. There is no Medicare kit, no senior health package and no free wellness bundle attached to a patient portal. MyChart is a place to read your chart, book appointments and message your care team. It is not a channel for offers, and a real one has nothing to send you.

How can I tell a fake MyChart link from a real one?

By where it lands. No generic MyChart address holds your chart: every genuine one lives on the hospital system that treats you, at an address like mychart.yourhospital.org. So a link pointing at some other standalone address built around the word mychart is wrong by construction, whatever it looks like. If you do not know your own hospital's MyChart address by heart, which most people do not, check where the link actually goes before you open it rather than after.

What are the scam emails using as subject lines?

Health systems have quoted two: "Your MyChart Medicare Kit Awaits" and wording referring to a 2026 MyChart Senior Health Package. Expect the exact words to drift, because subject lines are the cheapest thing to change. The offer is the constant. A patient portal that suddenly has a free package for you is the part that does not happen.

I clicked the link but did not type anything. Am I at risk?

Opening the page alone is a much smaller problem than filling it in, and if you entered nothing you are probably fine. Do two things anyway. Close the tab without going back, and if the page asked you to log in, sign in to your real MyChart by typing your hospital's address yourself and change the password there. Do not use any link from the email to do it.

I gave them my Medicare number. What now?

Report it to Medicare on 1-800-MEDICARE (1-800-633-4227), the line Medicare publishes for suspected fraud, and to the FTC at ReportFraud.ftc.gov. A Medicare number is valuable because it can be used to bill for equipment and services you never received, so the damage usually shows up later on a statement rather than immediately. Read every Medicare statement that arrives from now on and report anything you do not recognise.

Follow on Google