Blog · Security

Patient portal phishing: train staff before the fake MyChart mail arrives

Health systems keep warning patients about portal look-alike emails. Clinic staff get the same lures, often on the busiest inbox.

Phishing that looks like a patient portal is effective because the real portal already trains people to click. The lure is urgency: a result is ready, a password expired, a billing hold will cancel care.

What staff should verify

  • Hover the sender domain. Look-alike spellings are the tell.
  • Do not open attachments that "update portal access."
  • Open the portal from a bookmark or the EHR, never from the email button.
  • Report the message to the privacy officer instead of forwarding it to the whole office.

Reduce the blast radius

When PHI and credentials live in the same consumer mailbox as shopping mail, one click exposes both. A dedicated healthcare inbox with logging makes it easier to see who opened what and to disable an account quickly.

HIPAA Companion email gives the practice that named channel. Pair it with a five-minute phishing drill at a staff meeting. Use a fake (internal) example, not a real patient message.