Online Safety
How to Safely Use Your Doctor's Patient Portal — A Senior's Complete Guide
The short answer: your doctor's patient portal is safe — when you follow a few specific steps. But these websites are also a growing target for identity thieves who specialize in stealing medical information. This guide shows you exactly what to do (and what to avoid) every time you log in.
What Is a Patient Portal?
If your doctor, hospital, or specialist uses a system called MyChart, Epic, Cerner, or something similar, you have access to a patient portal — a private website where you can:
- View test results and visit summaries
- Request prescription refills
- Send messages to your doctor's office
- See upcoming appointments
- Pay medical bills online
More than 80% of U.S. health systems now offer these portals, and since the pandemic, millions of seniors are using them for the first time. They're genuinely useful tools. But because they hold your diagnosis history, medication list, insurance numbers, and sometimes your Social Security number, they're also high-value targets for hackers.
Why Cybercriminals Want Your Medical Records
Here's something most people don't know: stolen medical records sell for 10 to 40 times more than stolen credit card numbers on the dark web.
Why? Because thieves can use your insurance information to file fake claims, obtain prescriptions, or receive medical services in your name — and you may not discover it for months or years. By then, the damage to your insurance coverage, your medical history, and your credit can take years to untangle.
This crime is called medical identity theft, and it's one of the fastest-growing forms of fraud targeting adults over 60. The Federal Trade Commission received over 1.4 million identity theft reports in 2023, with medical identity theft among the hardest categories to recover from.
Step 1: Only Log In From a Secure Network
The single biggest mistake people make with patient portals is accessing them on public Wi-Fi — in the doctor's waiting room, a hospital cafeteria, or a pharmacy.
Public Wi-Fi is convenient, but it is not private. Anyone on the same network can potentially intercept what you're sending and receiving, including your login credentials and the contents of your health records.
What to do instead:
- Use your home Wi-Fi whenever possible
- If you must check your portal away from home, switch off Wi-Fi on your phone and use your cellular data connection instead
- Never access medical records on coffee shop, hotel, or free public Wi-Fi without protection
If you travel frequently or visit the hospital often, a VPN (Virtual Private Network) is worth having. A VPN creates an encrypted tunnel between your device and the internet, making it impossible for someone on the same network to spy on your connection. NordVPN is one of the most trusted options available, and a single subscription covers your phone, tablet, and computer. For a plain-English walkthrough of safe public network habits, see our public Wi-Fi safety guide for seniors.
Affiliate Disclosure: This article may contain affiliate links. If you make a purchase through these links, we may earn a small commission at no extra cost to you. We only recommend products we genuinely believe in. This helps support our work and allows us to continue providing free content.
Step 2: Use a Strong, Unique Password
If your patient portal password is the same one you use for email, online banking, or any other account — change it today.
When hackers steal passwords from one website (which happens regularly to large companies), they immediately try those same passwords on health portals, banks, and government sites. This is called a "credential stuffing" attack, and it's automated — thousands of accounts can be tested in minutes.
A strong patient portal password should:
- Be at least 12 characters long
- Include a mix of uppercase letters, numbers, and symbols
- Not contain your name, birthdate, or common words like "password" or your pet's name
- Not be used on any other website
If keeping track of many different passwords sounds overwhelming, a password manager like 1Password or Bitwarden stores them all securely. You only need to remember one master password — the app remembers everything else.
Step 3: Turn On Two-Factor Authentication
Two-factor authentication (sometimes called 2FA or two-step verification) adds a second check when you log in — usually a short code sent by text message or email that proves it's really you. Even if someone steals your password, they still can't get in without that code.
Most major patient portals now offer this feature. Here's how to find it:
- Log in to your patient portal
- Go to Account Settings or Security Settings
- Look for Two-Factor Authentication, Two-Step Verification, or Login Verification
- Follow the prompts to link your phone number
If you can't find the setting, call the portal's help desk and ask them to walk you through it. It takes about five minutes and dramatically reduces the chance someone else can access your account.
Step 4: Watch Out for Fake Portal Emails
One of the most common scams targeting seniors is a fake email that looks like it's from your doctor's office or hospital, asking you to "log in to view your test results" or "verify your account information."
These emails are designed to steal your login credentials. They often look completely professional — using your health system's real logo, real colors, and a very convincing design — but clicking the link takes you to a fake website that records your username and password the moment you type them.
Red flags that an email might be fake:
- The sender's email address doesn't exactly match your hospital's official domain (look carefully:
mychart-support.netis not the same asmychart.org) - The message creates urgency ("Your account will be deactivated in 24 hours")
- It asks you to enter your password, Social Security number, or insurance ID in a web form
- The link shown doesn't match the address it goes to when you hover your mouse over it
A safer habit that takes 10 extra seconds: Never click email links to access your portal. Open your browser, type the portal address directly (or use a bookmark you created yourself), and log in from there. If there's a real message waiting for you, it will be there.
Step 5: Set Up Medical Identity Monitoring
Unlike credit monitoring that tracks new loans and accounts, medical identity monitoring watches for suspicious activity in your health records — things like new insurance claims filed in your name, new prescriptions, or providers you've never visited appearing in your files.
For a full overview of identity protection steps — including credit freezes and Social Security monitoring — see our identity theft protection guide for seniors.
Aura includes medical identity monitoring as part of their comprehensive identity protection service. It continuously scans the dark web for your medical insurance information and alerts you immediately if something suspicious appears — giving you the chance to respond before real damage is done.
Affiliate Disclosure: This article may contain affiliate links. If you make a purchase through these links, we may earn a small commission at no extra cost to you. We only recommend products we genuinely believe in. This helps support our work and allows us to continue providing free content.
For seniors on Medicare and those with supplemental insurance, this kind of early warning is especially valuable. Medical identity theft is notoriously difficult to clean up on your own, and Aura's service includes access to U.S.-based fraud resolution specialists who can help you work through the recovery process step by step if something does happen.
Step 6: Know What Your Portal Will Never Ask You
Legitimate patient portals will never:
- Ask for your full Social Security number through a chat window or an email form
- Request your bank account or credit card number just to view your records
- Ask you to "re-verify" your account by clicking a link in an email
- Call you on the phone and ask for your portal password
If anything about your portal experience feels off — an unexpected pop-up asking for unusual information, a login page that looks slightly different than normal, or a phone call claiming to be from your doctor's portal — close the browser and contact your doctor's office directly. Use the phone number printed on your insurance card or from the practice's official website, not any number provided in the suspicious email or pop-up.
Step 7: Log Out When You're Done
This sounds obvious, but many people leave patient portals open in their browser and walk away — especially on tablets or shared computers.
Always click the Log Out or Sign Out button when you're finished, rather than just closing the browser tab. Closing the tab does not end your session on many websites, which means someone else using that device could reopen it and see your records.
If you ever access your portal on a shared computer — at a library, a senior center, or a family member's home — take two extra steps after logging out: clear the browser's history and cookies before you leave.
Bonus: Downloading the Official App Safely
Most major health systems have official apps for their patient portals — MyChart, Epic, and many hospital networks have their own branded versions. These apps are generally a safer option than the web browser because they're harder for scammers to convincingly fake.
To download safely:
- Only use the official Apple App Store or Google Play Store
- Search for the app by your hospital's or health system's full name
- Check the developer name to confirm it matches the official organization
- Read recent reviews before installing
Be cautious of text messages or emails that contain a direct link to download an app. Always search for it yourself rather than following a link from an unknown source.
Your Patient Portal Safety Checklist
Save this checklist or print it out and keep it near your computer:
- [ ] Use home Wi-Fi or cellular data — not public Wi-Fi
- [ ] Create a unique, strong password for the portal
- [ ] Turn on two-factor authentication
- [ ] Never click email links to log in — type the address directly
- [ ] Set up identity monitoring with Aura
- [ ] Use a VPN when accessing from public locations — NordVPN works on all your devices
- [ ] Log out completely after every session
- [ ] Download the official app from the App Store or Google Play, not from a link
Your medical records deserve exactly the same protection as your bank account. With these steps in place, you can use your patient portal with confidence — and catch any problems early, before they become expensive, time-consuming ordeals.
Last updated: 2026-05-27
Get Simple Security Tips Every Week
Join thousands of seniors who receive ClearShield's weekly newsletter — plain English, no tech jargon, and always practical. One email per week, unsubscribe anytime.
Related reading
You Searched for Help. A Scammer Answered First.
You were told never to click links in suspicious emails — so you search for the number yourself. Here's why that 'safe' habit now leads straight to scammers.
Cybersecurity Myths vs. Facts: What Seniors Actually Need to Know
9 common cybersecurity beliefs seniors trust that are quietly wrong — and the facts that actually keep your money and identity safe.
The Security Trap: Why Most Online Protection for Seniors Fixes the Wrong Problem
Antivirus, strong passwords, firewalls — but seniors still lose billions to fraud. Here's the real threat and what actually keeps you safe.