Person checking a MyChart login screen on a laptop while watching for phishing scams

WASHINGTON, DC Consumers Using Mychart Urged to Watch for Phishing Scams as Lexisnexis Adds New Identity Checks for Patient Portals

WASHINGTON, DC — MyChart is warning patients to stay alert after seeing an increase in phishing attempts aimed at the online medical portal. The company says millions of people use the service to view health records, test results and other information, which makes it an attractive target for scammers.

To respond, LexisNexis Risk Solutions has introduced a new product called Identity Proofing for MyChart. The tool adds extra checks when someone tries to access a patient account, with the goal of making it harder for bad actors to get in while keeping access smooth for legitimate users.

How the fake MyChart email scam works

One common scam starts with an email that appears to come from a medical provider or portal. It may urge patients to click a link to review results, warning that something urgent is waiting inside the account.

Instead of leading to a real login page, the link can send people to a fake site designed to collect usernames, passwords or other personal details. In some cases, the trap may also expose a computer to malware. Kim Brown, vice president of product management for healthcare and insurance at LexisNexis Risk Solutions, said the point is often to gather information that can be reused in other schemes.

Three simple steps patients can use before clicking

Brown offered a few basic habits that can help people avoid handing information to scammers. She said patients should look closely at the sender’s email address, since small spelling changes can be a warning sign that the message is fake.

She also advised people to slow down when a message pushes them to click immediately. If the email sends users to a website they do not recognize, that is another reason to be cautious. The safest move, Brown said, is usually to open a browser and sign in to the portal directly instead of using the email link.

That way, patients can check whether the message is actually waiting in their account and avoid using a suspicious page that may only look legitimate.

Why reusing passwords can make the damage worse

Brown warned that a stolen portal password can become part of a much larger problem when people reuse the same login across different accounts. She said scammers may combine a medical login with other bits of personal data to build a detailed profile of a victim.

That information can then be used in later fraud attempts, including efforts to access bank accounts, obtain a driver’s license number or open credit cards in someone else’s name. Brown said criminals are often looking for username-password combinations that can be tried again elsewhere.

For that reason, patient portals should be treated with the same care as financial accounts. A single weak login choice can create a chain of risk far beyond the original email scam.

New identity proofing adds more friction for suspicious logins

Identity Proofing for MyChart is designed to add more security checks when a login attempt looks risky. Those checks can include a one-time password or biometric verification, both of which make it harder for someone else to pose as the account holder.

The tool is also aimed at helping organizations respond to artificial intelligence-enabled deepfake scams. Brown said the technology is meant to spot suspicious activity and stop it before a fraudulent login can reach sensitive information.

At the same time, the system is intended to keep the process convenient for real patients who simply want to get into their records without extra hassle.

AI is helping scammers move faster, LexisNexis says

Brown said artificial intelligence has made phishing and other fraud schemes easier to scale, allowing scammers to reach more people with less effort. She pointed to LexisNexis Risk Solutions’ 2025 cybercrime report, which found malicious bot attacks rose 59% over the year.

Her message was that defenses need to keep pace with the same technology criminals are using. “We have to fight bad AI with good AI,” Brown said. The company’s view is that stronger detection tools and better user habits both matter if patients are going to keep their online health information safe.

For consumers, that means treating unexpected portal messages carefully, verifying logins directly and using stronger security layers whenever they are available.

More From Author

A doctor discusses medical billing and reimbursement charts in a hospital setting

Chicago Medical Scholars Detail How Medicare Billing Rules Keep Women’s Surgery Undervalued and Shape Care Across the United States

Making Strides Against Breast Cancer walkers gathered at a community event

Mid-Michigan Breast Cancer Walks in Flint and Great Lakes Bay Will Raise Funds for Research, Support Programs and Patient Services This October