Local Tech Fix (626) 655-0020
All articles

The "Free MyChart Medicare Kit" Email Is a Scam — and What to Do If You Already Clicked

September 12, 2026

Epic, the company that makes MyChart, ends the argument in five words on its own website: "MyChart does not run giveaways." The harder question is the one every hospital advisory skips — what to do after you clicked.

Since late August 2026, a phishing wave has been running nationwide using the name of MyChart — the patient portal most American health systems use to hold test results, appointments, prescriptions and messages from your doctor. The message arrives by email or text, it carries MyChart branding, and it offers you something free: a "2026 Medicare Health Kit," a "Senior Health Package," a wellness box, a reward for completing a short survey. Virtua Health, warning its own patients on August 26, 2026, published the two subject lines it was seeing verbatim — "Your MyChart Medicare Kit Awaits!" and "Senior Health Package" — and told people to delete the message without opening attachments or clicking links.

The timing is not an accident. Medicare Open Enrollment runs October 15 to December 7, with the coverage you pick starting January 1. That is the one stretch of the year when a Medicare-shaped message in your inbox is genuinely plausible, because a great deal of real Medicare mail, real plan advertising and real "review your coverage" nudges arrive in exactly the same weeks. A fake blends into a crowd. The crowd is about to show up.

Every advisory currently on the internet about this scam is a single hospital telling its own patients to delete one email. That is good advice and it is not enough, because the people who call us are past that point. They clicked. Or their mother clicked, on the iPad, three days ago, and now nobody is sure what she typed. This article is written for that reader — what the fake page actually does, what a stolen portal login is genuinely worth, and the order to do things in afterwards, using the guidance the companies and agencies involved publish themselves.

The rules that settle it, from the company that makes MyChart

MyChart is a product built by Epic, the software company whose medical records system sits behind a large share of US hospitals and clinics. Your health system runs its own copy under its own name and web address, which is exactly the ambiguity a scammer needs — there is no single "MyChart.com login" that everyone recognises, so a made-up MyChart page does not look obviously wrong.

Epic publishes a plain-language page on scams and fraud, and four sentences on it decide most cases without any technical judgement at all. First: "Epic and your healthcare organization will never ask for your password or verification codes." Second: they "will never ask you to change your email address or phone number to one you don't control." Third: "MyChart will never tell you to press keyboard shortcuts or to run a command to 'verify,' 'fix,' or 'unlock' your account." And fourth, the one that ends this particular scam in five words: "MyChart does not run giveaways."

There is no kit. There has never been a kit. No health system is mailing free Medicare wellness boxes through a patient portal, and neither is Medicare. If a message is offering you one, you already know everything you need to know about it.

Epic also names where real MyChart lives: mychart.org, MyChart.com and Epic.com, plus the address your own healthcare organization uses, with its name on it. If you are not sure which one is yours, Epic keeps a "Find your MyChart" directory of participating organizations on mychart.org — which is a much better way to find your portal than a link somebody sent you.

What actually happens if you follow the link

Epic describes the chain on its own page, and it is worth knowing because the shape is designed to feel like a real promotion rather than a login theft. The link often bounces through unrelated advertising sites before it lands, which is why the address bar ends up somewhere that looks nothing like a hospital. What loads is a MyChart-branded survey page. A countdown clock starts, along with a scarcity line — a handful of kits "remaining" — because a person watching a timer does not stop to look at the web address.

Then the pivot. The kit costs nothing, the page says, but there is a small shipping fee. Before it takes the fee, it collects personal information. The last page asks for card details. Nothing ships, because there is nothing to ship, and there never was — the survey, the countdown and the free box exist to make the card form feel like the last inconvenient step of a real transaction rather than the entire point of the exercise.

One detail from Virtua's notice is worth repeating because people get it exactly backwards: do not click "unsubscribe" on one of these messages either. On a legitimate mailing list, unsubscribe works. On a fraudulent one, any interaction confirms that a real person reads that address — which is worth money to the sender, and buys you a place on a better-quality list that gets sold on.

The phone-call version, and the one Medicare rule that ends it

The same campaign has a telephone half, and it is the one older customers are more likely to fall for, because a voice is harder to delete than an email. SSM Health, in a patient advisory posted in August 2026, described callers claiming "that Medicare information needs to be updated" and then asking for "personal information, including Medicare numbers or other sensitive details." Its advice is the correct one: do not give personal, financial or health information over the phone unless you placed the call and you know who answered.

Medicare itself publishes the rule that makes this easy, and it is short enough to keep in your head: "Medicare will never call you to sell you anything or visit you at your home." Medicare.gov lists the narrow exceptions — essentially, a representative returning your call after you joined a plan, reported fraud, or left a message. Nobody from Medicare rings out of the blue to update your details, and nobody from Medicare knocks on your door.

So the move on any such call is always the same, and it costs nothing: hang up, and if you think there might be something in it, call 1-800-MEDICARE (1-800-633-4227) yourself. Not the number the caller gave you, and not the number in the email signature. Caller ID can be forged trivially — a "1-800-MEDICARE" display on your phone screen means nothing at all.

Why a patient-portal login is worth more to a thief than a card number

Most people rank the card details as the serious part of this scam and the login as the annoying part. It is the other way round, and understanding why changes what you do first.

A card number is a rented credential. It is fraud-monitored by someone whose money is at risk, you can have it cancelled in a five-minute phone call, consumer protections limit what you actually pay, and a new card arrives in a few days with a number that makes the stolen one worthless. It is bad. It is also solvable, quickly, by one call.

A patient portal is the opposite: it holds the parts of your identity that cannot be reissued. Full legal name, date of birth, home address, phone, email. Your insurance or Medicare number. Your current medications, allergies and conditions. Visit notes, results and messages with your doctor, in clinical detail. Often the same account reaches your billing history, and sometimes a spouse's or a parent's chart, if proxy access was ever set up. You cannot phone anyone and be issued a new date of birth. That information is durable, and it is precisely the material used to open accounts, pass identity questions and impersonate you convincingly a year from now, long after the card was replaced and forgotten.

A portal login is also a control surface, not just a filing cabinet, which is what Epic's second rule is really about. Anyone who can sign in can change the email address and phone number on the account — and once the notifications go somewhere else, the theft is silent and the real owner is locked out of their own recovery. That is why "will never ask you to change your email address or phone number to one you don't control" is on Epic's list at all: it is the step that converts a stolen password into an owned account.

The downstream shape is what the FTC calls medical identity theft, and its warning signs are worth knowing in advance, because they surface months later: a bill or an Explanation of Benefits for care you never received or medication you do not take, a debt collector chasing a medical debt you do not owe, or a collection notice you do not recognise on your credit report. The version people find hardest is the one that is not about money at all — treatment somebody else received, recorded under your name, in your medical record.

If you already clicked: the order to do things in

Epic tiers this by what you actually did, which is more useful than generic panic. Work down the list and stop when you reach the bottom of what applies to you.

You clicked but typed nothing. In Epic's own words, "close the page. You are most likely fine." Opening a web page is not, by itself, how accounts get taken. Do not spend the evening running scanners over it. Report the message as phishing in your email app before you delete it — Epic asks people to do this specifically because it improves filtering for everyone who gets the next copy.

You typed your MyChart password. Change it now, and change it by going to your health system's real MyChart the long way — open its app, or type the address yourself — never through any link in any message, including the reassuring-looking one that arrives shortly afterwards. Then turn on two-step verification while you are in there: it lives under Account Settings, and Epic describes it as requiring "a code from your email, text message, or authenticator app when you log in." An authenticator app is the stronger of the three. And note the trap in Epic's first rule while you are at it — nobody legitimate will ever ring you and ask you to read that code out.

You used that same password somewhere else. This is the part that turns one bad click into a bad month, and it is the single most common reason a small incident becomes a large one. Every other account sharing that password is now exposed, and email comes first because email is what resets everything else. Change email first, then banking, then the rest.

You typed card details. Call the number on the back of the card, say the number was entered on a fraudulent website, and ask for a replacement — Epic gives the same advice. Watch for a small test charge rather than a large one; a stolen card is usually probed with something trivial before it is used properly.

You ran a program, or pasted something into a box you were told to press keys to open. Take this one seriously: Epic says to disconnect the computer and have it serviced. That instruction exists because a version of this scam does not want your password at all — it wants you to run the software yourself, which sidesteps most of what antivirus is good at. If that is what happened, unplug the network cable or turn off Wi-Fi, leave the machine off, and get it looked at before you sign in to anything else on it.

You gave out your Medicare number. Report it (numbers below), then start checking claims, which is the section after next. A stolen Medicare number does not usually show up as a dramatic event; it shows up as a billing line for equipment you never received.

And one prediction, so it does not catch you twice: expect the second wave. People who have just been scammed are the highest-value list there is, and within weeks somebody will call offering to recover your money or "secure" your medical records for a fee. That is the recovery scam, and it is run by the same industry that got you the first time.

The two checks that catch medical identity theft months later

The reason this scam is worth an hour of your time is that its consequences are slow. Here is how you would actually find out, without paying anyone for monitoring.

First, read your Medicare Summary Notice instead of filing it. Medicare is explicit that the MSN "is not a bill" — it is a statement of what was billed to Medicare on your behalf. If you have Original Medicare you get one at least twice a year, and Medicare's own description is that you will get it "every 6 months if you get any services or medical supplies during that period." You can switch to electronic notices, which is genuinely better for this purpose: with eMSNs you get an email with a link for any month in which a claim was processed, so a fraudulent claim surfaces in weeks rather than at the next six-month mailing. Medicare's instruction is to keep your receipts and bills and compare them against the notice to be sure you actually got everything listed. A line for a service you have never heard of is the whole point of reading it.

Second, if something does look wrong, the FTC's medical identity theft steps are the ones to follow. Ask each provider involved for copies of your medical records — the FTC notes that "your health care provider must respond to your request within 30 days" — and report errors to them in writing. Get your free credit reports from all three bureaus at AnnualCreditReport.com or by calling 1-877-322-8228, and look for medical collection entries you do not recognise. Then go to IdentityTheft.gov, the FTC's own site, and create a personal recovery plan; it walks you through the disputes in the right order. There is a Spanish-language version at RobodeIdentidad.gov, and phone help in multiple languages at 1-877-438-4338.

Where to report it — and the free California help almost nobody uses

Reporting a scam you did not fall for still matters, because these campaigns are shut down by volume of reports, not by individual heroics. Reporting one you did fall for matters more.

For anything Medicare-related, call 1-800-MEDICARE (1-800-633-4227). If the problem involves a Medicare Advantage plan or a Medicare drug plan specifically, Medicare directs you to the Investigations Medicare Drug Integrity Contractor at 1-877-7SAFERX (1-877-772-3379). Fraud can also be reported online to the Department of Health and Human Services' Office of Inspector General at oig.hhs.gov/fraud/report-fraud.

Then the part that is specific to us here in California, and that we almost never see anyone use. The California Department of Aging runs two free programs that exist for exactly this situation. The Senior Medicare Patrol helps you spot, understand and report Medicare fraud, error and abuse — the state's own page says plainly: "CALL SENIOR MEDICARE PATROL 1(855) 613-7080 TO REPORT FRAUD." Separately, HICAP, the Health Insurance Counseling and Advocacy Program, provides "free, confidential one-on-one counseling, education, and assistance" on Medicare and related insurance questions, statewide, at 1-800-434-0222.

Both are free, and that is the detail worth holding on to during Open Enrollment. If you want a human being to sit with you and go through a plan choice, a confusing notice or a suspicious claim, that human being exists and costs nothing. Anyone who phones you offering the same help for a fee, or offering to recover money you have already lost, is running the next scam.

If you are the family member doing this for a parent

Most of the calls we get about this are not from the person who received the email. They are from an adult child, usually in another city, trying to work out over the phone what mum clicked. A few small changes made once are worth more than any amount of forwarding warnings.

Install the health system's own MyChart app on their phone or tablet and sign in once, so that logging in never requires typing a password into a web page again. From then on the rule is simple enough to actually stick: we open the app, we never follow a link. Real results, real messages and real appointment reminders are all waiting inside the app anyway — the link in the email is never the only way to reach anything.

While you are signed in, turn on two-step verification and check the email address and phone number on the account. They should be contact details your parent genuinely controls, and ideally ones you can reach too. This is Epic's second rule read forwards instead of backwards: the contact details on the account are the account, and quietly changing them is how a takeover is made permanent.

If you need ongoing access to a relative's chart to help them manage care, ask their clinic how to be set up properly for it. Health systems have a formal process for a family member or caregiver to be granted access, and it is far better than the usual arrangement of sharing one password, because it survives password changes and it does not put you in the position of being indistinguishable from an intruder.

Last, set the expectation rather than the rule, because rules get forgotten and expectations stick: no genuine message from a doctor's office, an insurer or Medicare has ever needed a decision in the next ten minutes. Urgency is not a sign of importance. It is the product.

The habit to keep after this particular scam is gone

The Medicare kit will stop working eventually, the way the toll texts and the fake antivirus pop-ups eventually stopped working, and something else will take its place using the same anatomy: a familiar logo, a free thing, a countdown, a login box. The specifics are disposable. One habit is not.

Never reach an account through a message. Not a health portal, not a bank, not a utility, not a delivery company. Open the app you installed, or type the address you know, or call the number printed on the card in your wallet. If the message was real, everything in it is waiting for you when you get there under your own steam — and if it was not, you have just made it irrelevant without having to be clever about spotting it. That single rule beats essentially every phishing message anyone will ever send you, including the ones that are better made than this one.

We're a local computer and network repair shop, and a fair share of our week is the aftermath of messages like this one: cleaning up a machine after somebody ran what a fake page told them to run, getting people back into email and portal accounts, setting up two-step verification so it is not a nuisance, and sitting with people while they change the twelve passwords that shared the one that got typed. If you clicked, or you are not sure whether a parent clicked, that is a perfectly good reason to call — the sooner it is looked at, the smaller the job.

Keep reading

Free calculators

Service areas we cover

Want a second opinion before you buy?

We don't sell hardware or warranties — call and we'll tell you what's worth buying and upgrading.

Call (626) 655-0020

Gear we recommend

All gear →