Healthcare was the FBI’s most targeted critical infrastructure sector in 2025. The attack chain starts where patients interact with their health system’s brand every day: the login page.
When a patient logs into their health system’s portal to check a biopsy result or review a billing statement, they are not thinking about cybersecurity. They are thinking about their health, their family, or their finances, and they are trusting that the institution on the other side of the screen is who it claims to be. That trust is not optional. It is the foundation of the entire patient-provider relationship, built into the design of every portal, every appointment reminder, every secure message from a care team. It is also the precise thing that attackers exploit when they replicate that portal and send a message that looks exactly like the ones patients receive every week.
Menlo Security’s Q1 2026 healthcare data found that credential phishing accounts for 58% of browser-based attacks in the healthcare sector, one of the highest shares of any vertical. The Department of Health and Human Services documented approximately 276 million patient records compromised in 2024, roughly 758,000 every day, and the FBI reported that healthcare was the most targeted critical infrastructure sector in 2025. For the health systems whose brands appear on the portals being replicated, the phishing attack is an authentication problem and a brand impersonation problem simultaneously, and the patients caught in between are often the last to know.
How healthcare brands get impersonated
The patient portal has become the most visible surface of a health system’s brand, and that visibility makes it the most replicated.
Epic’s MyChart serves millions of patients across hundreds of health systems, and its recognizable interface makes it a natural target for credential harvesting campaigns. In January 2026, Epic filed a federal lawsuit against health data network Health Gorilla, alleging that third parties had gained access to nearly 300,000 patient medical records by posing as legitimate healthcare providers and requesting data through the exchange network. The impersonation operated at the provider level rather than the patient level, borrowing institutional identities to access records that the impersonated organizations never requested.
At the patient-facing layer, the attack chain follows the same playbook documented in phishing-as-a-service campaigns across every other sector. A phishing email or text message arrives claiming to be from the patient’s health system, referencing an appointment, a test result, a billing statement, or an insurance verification requirement. The link directs to a page that replicates the health system’s portal branding, collects login credentials, and in more advanced campaigns relays them through an adversary-in-the-middle proxy to capture the session token after MFA completes. Paubox’s 2026 analysis of healthcare phishing noted that the lures are no longer limited to security alerts and password resets. They mirror the routine communications patients expect: appointment reminders, prescription notifications, billing updates, and benefits enrollment deadlines.
The vendor ecosystem extends the impersonation surface further. When Cognizant’s TriZetto Provider Solutions, a claims clearinghouse used by hospitals and physician practices nationwide, disclosed in early 2026 that unauthorized access dating back to November 2024 had affected more than 3.4 million individuals, the breach illustrated a pattern that is becoming one of the fastest-growing sources of healthcare data exposure: a vendor compromise that cascades into notifications from dozens of providers whose patients had no direct relationship with the breached company. Each notification carries the health system’s name, creating confusion about which organization was responsible and eroding the trust that patients place in their provider’s brand.
Why healthcare's impersonation surface is so large
The characteristics that make healthcare a high-value target for impersonation are structural and unlikely to change.
A health system’s brand carries authority across an unusually wide range of interactions. Patients receive communications about appointments, lab results, prescriptions, billing, insurance, and benefits from what they understand to be a single trusted institution, even when those communications originate from dozens of affiliated entities, contracted vendors, and third-party platforms. Each communication type is a plausible pretext for a social engineering message, and the diversity of legitimate contacts makes it difficult for patients to distinguish authorized communications from fraudulent ones.
The value of the data compounds the targeting incentive. A complete healthcare identity package, including insurance details, medical records, and personal identifiers, sells for approximately $1,000 on criminal marketplaces, compared to roughly $20 for a driver’s license. Healthcare records are worth more because they enable multiple forms of downstream fraud: insurance claims filed under stolen identities, prescriptions obtained fraudulently, and financial accounts opened using the comprehensive personal information that health records contain.
And the workforce operating within this environment faces constraints that amplify phishing effectiveness. KnowBe4’s 2025 benchmarking data ranked healthcare as the most phishing-susceptible industry at 41.9%, ahead of insurance and retail. Clinical staff managing patient care under time pressure, administrative teams processing high volumes of billing and insurance correspondence, and front-desk personnel handling credential resets and portal access requests all represent entry points where a convincing impersonation of the health system’s own communications is likely to succeed.
What healthcare security teams should monitor
The defensive response requires extending visibility beyond the network perimeter to the external surfaces where the health system’s brand is being replicated.
Domain monitoring for newly registered domains incorporating your health system’s name, affiliated clinic names, and portal brand identifiers (particularly MyChart and similar patient-facing platforms) is the earliest detection signal. The registration patterns are consistent with those documented across other sectors: day-old domains, Let’s Encrypt certificates, and brand strings embedded in the hostname. Detecting these registrations before the associated phishing campaign launches provides the window to initiate takedowns before patients receive the messages.
Credential exposure monitoring through dark web surveillance surfaces stolen employee and patient credentials before they are used in credential stuffing or account takeover attacks. IBM’s 2025 data found that healthcare breaches take an average of 279 days to identify and contain, and the Verizon DBIR’s finding that 54% of ransomware victims had credentials exposed in infostealer logs before the attack began underscores why this layer matters: the breach window often opens well before the ransomware deploys, and monitoring for that exposure is the earliest available intervention.
And vendor impersonation monitoring addresses the cascade risk that the TriZetto breach illustrated. When a vendor compromise generates patient notifications bearing your health system’s name, monitoring for domains and communications that exploit the resulting confusion is an extension of the same brand protection discipline applied to your own portal.
The Bottom Line
Healthcare was the FBI’s most targeted critical infrastructure sector in 2025, and the majority of attacks begin with phishing that impersonates the health system’s own patient-facing brand. The login portal that patients use every day is the interface attackers replicate, the communications patients expect are the lures they exploit, and the vendor relationships that extend a health system’s brand across dozens of third parties create an impersonation surface that most monitoring programs are not yet built to cover. For healthcare security teams, defending the authentication layer and monitoring for external impersonation of the institutional brand are not separate priorities. They are two dimensions of the same exposure.
Key Takeaways
The FBI reported 460 ransomware incidents and 182 data breaches targeting healthcare in 2025, making it the most targeted critical infrastructure sector. HHS OCR documented 276 million patient records compromised in 2024.
Attackers replicate patient portal login pages, send phishing messages mimicking appointment reminders, billing updates, and insurance verifications, and in advanced campaigns use adversary-in-the-middle proxies to capture session tokens after MFA. Vendor breaches generate additional impersonation opportunities when patient notifications carry the health system’s name.
Health system brands carry authority across appointment scheduling, lab results, prescriptions, billing, and insurance. The diversity of legitimate communications creates a correspondingly diverse set of lures. Healthcare identity packages sell for approximately $1,000 on criminal marketplaces. KnowBe4 ranks healthcare as the #1 most phishing-susceptible industry at 41.9%.
In January 2026, Epic filed a federal lawsuit alleging third parties accessed nearly 300,000 patient records by posing as legitimate healthcare providers through the Health Gorilla data exchange network. The impersonation operated at the institutional level, borrowing provider identities to access records the impersonated organizations never requested.
Newly registered domains incorporating your health system’s name and portal brands, credential exposure in dark web markets and infostealer logs, and vendor impersonation that exploits the confusion generated by third-party breaches. Domain monitoring provides the earliest detection window before phishing campaigns reach patients.



