An unexpected “your results are ready” message can arrive at a moment when you are especially likely to click. You may be waiting for a report, traveling, or worried about a delay. That urgency is a reason to use a known sign-in route—not evidence that the message itself is genuine.
You do not have to decide whether every feature of the email looks convincing. Separate two tasks: checking your account through the real service, and deciding how to handle the notification. The first task can often be completed without using anything supplied by the message.
Start outside the notification
Open the provider's official app that you already use, or a previously verified website address. Check the account for a new report or message. If you need to call, use contact information from an established record or the provider's known website rather than a number included in the suspicious email.
The FTC recommends contacting a company through a website or phone number you know is real when a message may be a phishing attempt. That principle is more reliable than trying to judge a logo, a polished signature, or a convincing account of why immediate action is required.
For example, a notification might say your access will expire that evening unless you confirm your password. Open the real portal independently. If no corresponding notice appears, you have a reason to ask the provider about it through the known route. Do not test the suspicious form with your real password to find out whether it works.
Treat visual clues as clues
Lookalike sender names, unexpected attachments, urgency, and unfamiliar destinations deserve attention. None of those observations should become a shortcut such as “good spelling means legitimate” or “any unfamiliar company is fraudulent.” Real systems sometimes send poorly formatted notices; deceptive messages can look professional.
When you inspect a web address, focus on the actual hostname. Familiar words in a path or subdomain do not automatically establish ownership. A padlock indicates an encrypted connection to that site; it does not by itself tell you that you reached your healthcare provider.
If reading the address is difficult on a small screen, take the simpler route: leave the message and open the known portal. You do not need to become a forensic email analyst to avoid signing in through an unverified link.
Resolve unfamiliar service names without guessing
A test seller, collection facility, processing laboratory, and result portal may have different names. An unfamiliar portal can be part of a legitimate arrangement. Confirm the relationship through the seller's official documentation or a known support contact before supplying credentials or uploading information.
Frame the support request around access: which organization hosts the report, what official address should you use, and what account is expected? Provide the minimum order or case detail needed for that question. Do not send a complete medical report to a general support mailbox simply to prove that you are a customer.
| What you observe | Useful next step | What remains unresolved |
|---|---|---|
| The known portal shows a new report | Open it through that portal | Whether the original email was genuine |
| A different company hosts results | Verify the relationship through the provider | Whether the particular link you received is correct |
| The account has no corresponding notice | Contact support through a known route | Whether delivery or account matching is delayed |
| A message requests an unexpected code or approval | Pause and inspect the real account's security activity | Whether someone else initiated a sign-in |
If you already interacted, describe what happened precisely
Opening an email, following a link, downloading a file, entering a password, and approving a sign-in are different events. Write down which occurred and when. That helps the provider's support or security team direct you to the relevant recovery process without guessing from “I clicked something.”
If you entered a password on an unverified page, go directly to the real service's account-security guidance. Change a compromised password through the real service, review available sign-in and recovery settings, and address other accounts where the same password was reused. Protect the email account used for recovery as well. Follow the provider's instructions about ending sessions or other account-specific steps.
If you downloaded or opened an unexpected attachment, follow current device-security guidance rather than assuming a password change addresses the whole event. If sensitive personal information was disclosed, the FTC's phishing guidance points to additional reporting and identity-theft resources. The appropriate response depends on what information was actually exposed.
Preserve a useful record without spreading the message
Use the reporting tools in your email service and the provider's published security-reporting route when available. Keep the time, sender address, message subject, and a description of the action you took if they are needed for a case. Avoid forwarding a suspicious attachment widely or posting a screenshot containing account details to a public forum.
After reporting, follow your email service's handling instructions. Keep any legitimate case reference separately so you can follow up through the confirmed channel. An acknowledgement of a report is not the same as confirmation that an account has been secured; complete the recovery steps the real service requires.
Finally, successful sign-in verifies access, not the medical meaning of a result. Use the clinician's normal follow-up process for the report itself. The message's identity, the account's security, and the clinical conversation each need their own check.
Sources and claim boundaries
- CISA: Recognize and report phishing
Use a trusted route to verify unexpected messages rather than following suspicious links or supplying credentials.
- HHS: Personal cell phones and health information
HIPAA applicability depends on entity and relationship; personal consumer apps are often outside its coverage.
- HealthIT.gov: Get it, check it, use it
Obtaining, checking, and using a personal health record.
- FTC: How to recognize and avoid phishing scams
Verify a message using known contact information; response depends on whether credentials, information, or an attachment were involved.