An email saying your laboratory results are ready may be legitimate, but the subject line alone cannot establish that. Use a known route to the provider when a message is unexpected or its destination is unclear.
Separate the notification from the sign-in
Open the provider's official app or a website address you already know. Sign in through that route and check for the report or message. Avoid using a search advertisement as a substitute for a previously verified portal address.
If you do inspect a link, read the actual hostname rather than relying on a logo or familiar words in a longer address. A secure connection indicates encryption to that site; it does not prove that the site is your healthcare provider.
Check an unfamiliar service relationship
A test seller and the result portal may have different names. Verify that relationship through the seller's official documentation or a known contact number. Do not assume an unfamiliar portal is fraudulent, but do not supply credentials before establishing why it is involved.
Ask support about the order and access route without sending a complete report or password to a general email address. Legitimate support should not need your password to investigate a notification problem.
Respond to a suspicious message deliberately
CISA recommends recognizing and reporting phishing. Use the reporting tools available in your email service and the provider's appropriate security channel. Do not approve an unexpected authentication request simply to make it disappear.
If you already entered credentials at a suspicious site, use the real service's account-recovery and security guidance promptly. Protect the email account used for recovery as well as the portal itself.
This process verifies access, not the meaning of a medical result. Once you have reached the correct report, use the clinician's follow-up process for health questions. Keep the identity of the website and the interpretation of the result as two separate checks.
Sources and claim boundaries
- CISA: Recognize and report phishing
Use a trusted route to verify unexpected messages rather than following suspicious links or supplying credentials.
- HHS: Personal cell phones and health information
HIPAA applicability depends on entity and relationship; personal consumer apps are often outside its coverage.
- HealthIT.gov: Get it, check it, use it
Obtaining, checking, and using a personal health record.