Skip to main content
ThreatScams & fraud

Fake telehealth / patient-portal impersonation — email impersonates MyChart, FollowMyHealth, athenaPatient, NextGen, Cerner HealtheLife, Epic Open Scheduling, Teladoc, MDLive, Amwell, or Doxy.me with a health-action hook (new secure message, test results available, refill decision, after-visit summary) + portal-login CTA pointing at an off-allowlist URL. HIPAA Journal Feb 2026: 9.65M PHI records exposed Jan-Feb 2026; Scamicide Apr 2025 personalized MyChart phish; HHS OCR Dec 2024 PIH Health $600K phishing-breach settlement; KnowBe4 2025 flagged healthcare as a priority phishing vertical

fake-telehealth-patient-portal-mychart-lure

What this tier means

High-confidence threat indicator — phishing, impersonation, BEC, or scam pattern. Strong contributor to the trash decision.

How Gorganizer detects this

Email impersonates a patient portal or telehealth brand — MyChart (Epic), FollowMyHealth, athenaPatient, NextGen, Cerner HealtheLife, Epic Open Scheduling, Teladoc, MDLive, Amwell, or Doxy.me — with a health-action hook ("you have a new secure message," "your test results are available," "prescription refill decision ready," "after-visit summary") and a portal-login CTA pointing at an off-allowlist URL. The target enters credentials on a lookalike login page; because the healthcare context creates emotional urgency (lab results, a message from your doctor, a prescription decision) users click faster than they would for other brands. HIPAA Journal reported 9.65M PHI records exposed Jan-Feb 2026 alone — health phishing has hit sustained epidemic volume. Scamicide documented personalized MyChart phish with the target's first name in April 2025; HHS OCR settled PIH Health for $600K in December 2024 over a phishing-enabled breach; KnowBe4 2025 flagged healthcare as a priority phishing vertical because of the high PHI-record resale value on dark markets. Distinct from generic medical-bill / insurance-claim phish because this specifically targets the patient-portal login flow. Warning signs: any patient-portal-branded email that couples a secure-message / test-results / refill hook with a "log in to view" link to a domain that is not your real provider's portal subdomain.

False-positive guard

Every signal in Gorganizer feeds a multi-module score — never a sole verdict. This is a threat-tier signal — it adds a strong contribution to the trash score. The full pipeline still requires convergence across multiple modules + a margin over the safety floor before deletion happens, and Gmail's trash (30-day recovery) is always used — never permanent delete.

About the scoring engine

Gorganizer's scoring engine emits over 1,800 signals across six modules — headers, sender, subject, body, attachments, and structural metadata. Every email is scored by every module independently; the final verdict requires multiple modules to agree and the trash score to beat the safety floor by a margin.

Sacred safety guards — never delete starred emails, replies, calendar invites, receipts/invoices, or attachments — apply unconditionally regardless of any signal.

Ready to clean your inbox?

Gorganizer scans your Gmail with this signal and 1,800+ others, then cleans everything in one click. $4.99 one-time, no subscription.

Get started