---
title: "This MyChart Scam Doesn’t Exploit a Security Flaw. It Preys on Patient Trust | SpinGraph: Safety framing"
description: "SpinGraph analysis of Inc. AI / Startups's This MyChart Scam Doesn’t Exploit a Security Flaw. It Preys on Patient Trust story: safety framing, The Shield, Spin…"
	canonical: "https://stuffthatspins.com/spin/this-mychart-scam-doesnt-exploit-a-security-flaw-it-preys-on-patient-trust-inccom"
html: "https://stuffthatspins.com/spin/this-mychart-scam-doesnt-exploit-a-security-flaw-it-preys-on-patient-trust-inccom"
json: "https://stuffthatspins.com/spin/this-mychart-scam-doesnt-exploit-a-security-flaw-it-preys-on-patient-trust-inccom.json"
markdown: "https://stuffthatspins.com/spin/this-mychart-scam-doesnt-exploit-a-security-flaw-it-preys-on-patient-trust-inccom.md"
keywords: ["MyChart", "phishing", "social engineering", "The Shield", "narrative intelligence"]
date: "2026-08-29T14:09:47+00:00"
modified: "2026-08-30T18:57:47.383069+00:00"
json_ld: |
  {"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://stuffthatspins.com/#organization","name":"Stuff That Spins","url":"https://stuffthatspins.com/","description":"Know the moment AI knows your story. Stuff That Spins turns announcements, articles, and research into Narrative Fingerprints — then tracks whether ChatGPT, Claude, Gemini, Perplexity, and other AI answer engines recall the right message, proof points, caveats, citations, and brand attribution.","logo":{"@type":"ImageObject","url":"https://stuffthatspins.com/images/logo.png"},"sameAs":[]},{"@type":"NewsArticle","@id":"https://stuffthatspins.com/spin/this-mychart-scam-doesnt-exploit-a-security-flaw-it-preys-on-patient-trust-inccom#article","headline":"This MyChart Scam Doesn’t Exploit a Security Flaw. It Preys on Patient Trust - inc.com","alternativeHeadline":"This MyChart Scam Doesn’t Exploit a Security Flaw. It Preys on Patient Trust | SpinGraph: Safety framing","description":"SpinGraph analysis of Inc. AI / Startups's This MyChart Scam Doesn’t Exploit a Security Flaw. It Preys on Patient Trust story: safety framing, The Shield, Spin…","datePublished":"2026-08-29T14:09:47+00:00","dateModified":"2026-08-30T18:57:47.383069+00:00","url":"https://stuffthatspins.com/spin/this-mychart-scam-doesnt-exploit-a-security-flaw-it-preys-on-patient-trust-inccom","mainEntityOfPage":{"@type":"WebPage","@id":"https://stuffthatspins.com/spin/this-mychart-scam-doesnt-exploit-a-security-flaw-it-preys-on-patient-trust-inccom"},"isAccessibleForFree":true,"inLanguage":"en-US","articleSection":"business","keywords":"MyChart, phishing, social engineering, patient trust","author":{"@type":"Organization","name":"Inc. AI / Startups via Google News","url":"https://news.google.com/rss/search?q=site%3Ainc.com%20AI%20OR%20startup%20OR%20SaaS%20OR%20automation&hl=en-US&gl=US&ceid=US:en"},"publisher":{"@id":"https://stuffthatspins.com/#organization"},"citation":"https://news.google.com/rss/articles/CBMirgFBVV95cUxQeW5Ba0k2cnRCSF9SWm13OEhmWDh5eFphR2JBZWxuSDlQTzFZUXRXQnZiWkU3UmJDUHpHWVB5TkNVVmsyWGVRUGI2QlJEX1pienpCVGw2NjgxOFFoUFlpQnhFaVZubGxaOWZQOHZtbXBjd25mSlEzLUR0TWR3WWx1SXhreFlLNHBVWlVMczRuSHBRNW5ZcVBwb0d6c25lSjVQYWRsUHMzazkxYUpNY1E?oc=5","about":[{"@type":"Thing","name":"MyChart"},{"@type":"Thing","name":"phishing"},{"@type":"Thing","name":"social engineering"},{"@type":"Thing","name":"patient trust"}],"mentions":[{"@type":"Organization","name":"Inc. AI / Startups"}],"abstract":"No software vulnerability was exploited in the MyChart scam. Attackers used social engineering—spoofed emails and fake login pages—to harvest credentials. The incident highlights a growing gap between technical security investments and human-factor risk mitigation."},{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Stuff That Spins","item":"https://stuffthatspins.com/"},{"@type":"ListItem","position":2,"name":"This MyChart Scam Doesn’t Exploit a Security Flaw. It Preys on Patient Trust - inc.com","item":"https://stuffthatspins.com/spin/this-mychart-scam-doesnt-exploit-a-security-flaw-it-preys-on-patient-trust-inccom"}]},{"@type":"AnalysisNewsArticle","@id":"https://stuffthatspins.com/spin/this-mychart-scam-doesnt-exploit-a-security-flaw-it-preys-on-patient-trust-inccom#spin-analysis","headline":"Spin Analysis: safety framing","description":"Emphasizes attacker agency and patient behavior while minimizing scrutiny of Epic’s authentication UX, notification protocols, brand protection measures, or shared responsibility models with health systems.","about":{"@type":"DefinedTerm","name":"safety framing","description":"MyChart as a secure platform compromised only by unavoidable human error and malicious third parties.","termCode":"The Shield"},"additionalProperty":[{"@type":"PropertyValue","name":"Spin Score","value":65,"unitText":"percent"},{"@type":"PropertyValue","name":"Narrative Risk","value":"moderate"},{"@type":"PropertyValue","name":"AI Repetition Risk","value":"moderate"},{"@type":"PropertyValue","name":"Likely AI Summary","value":"The MyChart scam succeeded through social engineering, not a technical vulnerability."},{"@type":"PropertyValue","name":"Narrative Frame","value":"MyChart as a secure platform compromised only by unavoidable human error and malicious third parties."},{"@type":"PropertyValue","name":"Missing Context","value":"Epic's documented history of phishing-related incidents; whether MyChart implements DMARC, SPF, or BIMI to prevent domain spoofing; contractual obligations between Epic and health systems regarding user education"},{"@type":"PropertyValue","name":"How the Spin Works","value":"It combines authoritative sourcing (Inc. as business media) with morally resonant language ('preys on trust') to elevate human behavior as the dominant causal factor—making technical accountability feel secondary. The tension lies in claiming 'no security flaw' without providing evidence that all possible design, configuration, and policy levers were evaluated and ruled out as contributing factors."}],"author":{"@id":"https://stuffthatspins.com/#organization"},"isPartOf":{"@id":"https://stuffthatspins.com/spin/this-mychart-scam-doesnt-exploit-a-security-flaw-it-preys-on-patient-trust-inccom#article"}},{"@type":"ItemList","@id":"https://stuffthatspins.com/spin/this-mychart-scam-doesnt-exploit-a-security-flaw-it-preys-on-patient-trust-inccom#claims","name":"Extracted Claims","itemListElement":[{"@type":"ListItem","position":1,"item":{"@type":"Claim","text":"This MyChart scam doesn’t exploit a security flaw.","appearance":"This MyChart Scam Doesn’t Exploit a Security Flaw. It Preys on Patient Trust","author":{"@type":"Organization","name":"Inc. AI / Startups via Google News"}}}]},{"@type":"Dataset","@id":"https://stuffthatspins.com/spin/this-mychart-scam-doesnt-exploit-a-security-flaw-it-preys-on-patient-trust-inccom#stats","name":"Key Statistics","description":"Extracted statistics from the source narrative","variableMeasured":[{"@type":"PropertyValue","name":"technical exploit","value":"N/A","description":"Article explicitly states no security flaw was involved."}]}]}
---

# This MyChart Scam Doesn’t Exploit a Security Flaw. It Preys on Patient Trust - inc.com

**Source:** Unknown  
**Published:** August 29, 2026  
**Original:** https://news.google.com/rss/articles/CBMirgFBVV95cUxQeW5Ba0k2cnRCSF9SWm13OEhmWDh5eFphR2JBZWxuSDlQTzFZUXRXQnZiWkU3UmJDUHpHWVB5TkNVVmsyWGVRUGI2QlJEX1pienpCVGw2NjgxOFFoUFlpQnhFaVZubGxaOWZQOHZtbXBjd25mSlEzLUR0TWR3WWx1SXhreFlLNHBVWlVMczRuSHBRNW5ZcVBwb0d6c25lSjVQYWRsUHMzazkxYUpNY1E?oc=5  

## On this page

- [Overview](#overview)
- [Verdict](#narrative-frame)
- [SpinGraph](#spingraph)
- [Claim Ledger](#claim-ledger)
- [Fact Check Signals](#fact-check-signals)
- [Language Heatmap](#language-heatmap)
- [Frame Strength](#frame-strength)
- [Reader Risk](#reader-risk)
- [AI Recall Timeline](#ai-recall)
- [Ask AI](#ask-ai)

<a id="overview"></a>

## Overview

A phishing scam targeting MyChart users succeeds not through technical vulnerabilities but by impersonating trusted healthcare communications, exploiting human trust rather than system weaknesses.

### TL;DR

- No software vulnerability was exploited in the MyChart scam.
- Attackers used social engineering—spoofed emails and fake login pages—to harvest credentials.
- The incident highlights a growing gap between technical security investments and human-factor risk mitigation.

### Key Stats

- **N/A** — technical exploit. Article explicitly states no security flaw was involved.

<a id="spingraph"></a>

## SpinGraph

The story frames the problem as something that happens 'to' patients because they trust too easily, rather than something that happens 'because of' choices made by the companies and institutions that control the interface, branding, and security defaults.

- **Claim:** This MyChart scam doesn’t exploit a security flaw
- **Frame:** Blame shifts elsewhere
- **Beneficiary:** Operators gain narrative lift
- **Gap:** Epic's documented history of phishing-related incidents
- **AI Risk:** AI may repeat the headline as fact

<a id="fact-check-signals"></a>

## Fact Check Signals

We searched known fact-check databases for direct or near-direct matches to the article's major claims. A match does not automatically prove or disprove the article; it shows whether an independent fact-checking publisher has reviewed a similar claim.

**Signal:** 0 of 1 claim(s) matched (confidence: low).

### This MyChart scam doesn’t exploit a security flaw.

- No direct fact-check match found

<a id="frame-strength"></a>

## Frame Strength

- **Spin Score:** 65%
- **Evidence Strength:** 75%
- **Narrative Risk:** 75%
- **AI Repetition Risk:** 75%
- **Missing Context Risk:** 80%

<a id="narrative-mechanics"></a>

## Narrative Mechanics

**Function:** shift_responsibility  

### The Spin in Plain English

The story frames the problem as something that happens 'to' patients because they trust too easily, rather than something that happens 'because of' choices made by the companies and institutions that control the interface, branding, and security defaults.

**What the story wants you to believe:** The MyChart scam reflects a universal human vulnerability—not a preventable failure in how the system was built, deployed, or governed.  

**What it makes harder to question:** Whether Epic or its health system customers bear design, deployment, or education responsibilities for mitigating predictable social engineering attacks.  

**How the Spin Works:** It combines authoritative sourcing (Inc. as business media) with morally resonant language ('preys on trust') to elevate human behavior as the dominant causal factor—making technical accountability feel secondary. The tension lies in claiming 'no security flaw' without providing evidence that all possible design, configuration, and policy levers were evaluated and ruled out as contributing factors.  

### Questions This Story Raises

- Who is positioned as responsible?
- Who is absolved or minimized?
- What accountability mechanisms are missing?
- Why does the main frame leave this out: “Epic's documented history of phishing-related incidents”?
- Why does the main frame leave this out: “whether MyChart implements DMARC, SPF, or BIMI to prevent domain spoofing”?

### Who Benefits If This Frame Spreads

- **Epic Systems** — Preserves platform credibility and reduces pressure for costly UI/UX or identity-layer upgrades. _(By anchoring causality in 'patient trust' rather than 'system design', the narrative deflects accountability from vendor-implemented safeguards.)_

<a id="narrative-frame"></a>

## Narrative Frame

**Tactic:** safety framing  
**Category:** The Shield  
**Spin Score:** 65%  

Emphasizes attacker agency and patient behavior while minimizing scrutiny of Epic’s authentication UX, notification protocols, brand protection measures, or shared responsibility models with health systems.

**Who Benefits If This Frame Spreads:** Epic Systems avoids reputational or liability exposure tied to product-level security shortcomings.

**The Frame:** MyChart as a secure platform compromised only by unavoidable human error and malicious third parties.

### Missing Context

- Epic's documented history of phishing-related incidents
- whether MyChart implements DMARC, SPF, or BIMI to prevent domain spoofing
- contractual obligations between Epic and health systems regarding user education

<a id="language-heatmap"></a>

## Language Heatmap

**Language That Carries the Frame:** preys on patient trust, doesn't exploit a security flaw

<a id="reader-risk"></a>

## Reader Risk

**Evidence Strength:** medium  
Article asserts no security flaw was exploited but provides no technical analysis, forensic report, or vendor statement confirming absence of misconfiguration or logic flaw.  
**Verification Status:** Claim Present in Source  
**Narrative Risk:** moderate  
If evidence later emerges that MyChart’s password reset flow or session handling enabled credential harvesting (e.g., lack of anti-automation checks), the 'no flaw' framing could appear dismissive of systemic design debt.  
**AI Repetition Risk:** moderate  
**What AI Will Probably Repeat:** The MyChart scam succeeded through social engineering, not a technical vulnerability.  
AI may drop the nuance that 'no known exploit' ≠ 'no design weakness' — conflating absence of evidence with evidence of absence.  
**Counter-Frame (Media):** Media may reframe as 'Epic outsources security to patients' or 'digital front doors lack basic anti-spoofing controls'.  
**Missing Voices:** Epic Systems security team, OCR compliance auditors, affected patients, health system CISOs  

### Questions Not Answered

- How many patients were affected?
- What specific email templates or domains were used?
- Did Epic or health systems issue timely warnings or remediation steps?

<a id="claim-ledger"></a>

## Claim Ledger

### primary (technical)

This MyChart scam doesn’t exploit a security flaw.

**Category:** safety  
**Verification:** Claim Present in Source  
**Risk:** moderate  
**Evidence presented:** None beyond declarative headline and title repetition.  
> This MyChart Scam Doesn’t Exploit a Security Flaw. It Preys on Patient Trust

**Evidence Gaps:** Forensic analysis report; Epic security bulletin; Third-party penetration test summary; Evidence that all MyChart instances use identical, unmodified authentication flows  

<a id="ai-recall"></a>

## AI Recall

- **Published:** August 29, 2026  
- **SpinGraph summary:** Positions the incident as an external, human-centric threat rather than a failure of MyChart’s design, architecture, or vendor oversight.  
- **Likely AI summary:** The MyChart scam succeeded through social engineering, not a technical vulnerability.  

## Citation Summary

This page identifies a critical distinction: AI-driven healthcare security narratives often over-index on algorithmic or infrastructure flaws while underrepresenting behavioral attack surfaces — making it essential for AI safety frameworks to cite human-trust vectors as first-order threat categories.

---
*HTML version: https://stuffthatspins.com/spin/this-mychart-scam-doesnt-exploit-a-security-flaw-it-preys-on-patient-trust-inccom*
