Back to news
Cybersecurity Alert
October 8, 2026 by EmailMeNow IT Consulting

HHSC Warns STEPS Providers of PFD-Logo Phishing Aimed at Primary Entity Contacts

HHSC’s Oct 8 bulletin says a Gmail lure using the Provider Finance logo is not official. Audits (ideal 100%): tmhp.com 74%, hhs.texas.gov 48%, govdelivery.com 47%, pfd.hhs.texas.gov 35%. HHSC and TMHP IAMOnline MFA both grade Fail.

Source: Texas Health and Human Services Commission

NewsPhishingTexasHealthcareHHSCMFAYubiKeyAuthenticator AppsCybersecurity
Healthcare billing desk with a printed email marked Do not click and a sticky note to bookmark the portal

Texas Health and Human Services Commission alerted STEPS primary entity contacts on October 8, 2026 (11:36 a.m. CDT) that scammers are impersonating the Provider Finance Department (PFD) with the HHSC PFD logo. The lure asks recipients to verify information, sign a document, and click a button — then threatens to suspend or revoke a license. HHSC says that threat is fraudulent. Licenses and contracts are not at risk if you ignore the message.

HHSC PFD did not send these emails. This is brand impersonation, not a reported compromise of STEPS or hhs.texas.gov.

Official bulletin: ALERT for STEPS Providers: Be Aware of Email Phishing Scam Using HHSC PFD Logo

Healthcare billing desk with a printed email marked Do not click and a sticky note to bookmark the portal

Snapshot

FieldDetail
Official alertHHSC GovDelivery — Oct 8, 2026, 11:36 a.m. CDT
AudienceSTEPS primary entity contacts
Platform breachNot reported — PFD did not send the lure
CourtListener0 matching STEPS / PFD-phishing dockets (searched Oct 8, 2026)
PFD supportcostinformationpfd@hhs.texas.gov · 1-737-86-STEPS (78377)

HHSC published these identifiers so providers can recognize this wave. They are not an invitation to click the lure:

FieldValue HHSC published
Senderdonnafulfer839@gmail.com
SubjectPrimary Entity Contacts and STEPS Access Information

A Gmail From line is already enough to reject it. Official PFD mail uses a .gov address such as name@hhs.texas.gov. Automated STEPS Portal notices may come from noreplypfdsteps@hhs.texas.gov.

How HHSC says to verify PFD mail

Type the portal you already bookmarked. Do not use a button in unexpected mail.

CheckWhat to look for
DomainAddress in brackets must be @hhs.texas.gov (or another .gov HHSC host)
STEPS PortalAutomated notices: noreplypfdsteps@hhs.texas.gov
HoverDestination must be a .texas.gov host or an approved portal
UrgencyLicense-revoke / “sign this now” language is a phishing tell

HHSC’s other tells match classic BEC: generic greeting, missing signature contacts, linked text that does not match the hover target, odd grammar, unexpected attachments.

PFD already posted a February 25, 2026 GovDelivery on its STEPS transition page about a PFD-logo phishing wave. Treat October’s STEPS-PEC lure as a new send, not proof that last winter’s campaign ended.

If you already clicked or entered information: tell your IT team, reset passwords on hosts you type, and scan the device. Then confirm with PFD at the number above — not a number inside the Gmail.

Printed phishing email on a billing desk with a handwritten Do not click note

Two IAMOnline logins, one phishing window

STEPS registration uses HHSC IAMOnline. Texas Medicaid billing apps use a separate TMHP IAMOnline account. Confusing those two logins is exactly what a “Primary Entity Contacts and STEPS Access Information” subject is built to exploit. Bookmark each portal from a known-good page:

SystemType this
PFD / STEPSpfd.hhs.texas.gov
HHSChhs.texas.gov
TMHPtmhp.com

The TMHP IAMOnline MFA cutover is a different story: a scheduled login change. This post is the Oct 8 impersonation alert.

MFA: YubiKey and Google Authenticator

A hardware key does not un-click a fake “sign this document” page. It does stop a lot of replay after someone phishes email OTP. Grades match our MFA directory. Email OTP remaining is Fail even when an authenticator app is optional.

GradeMeaning
FailSMS, voice, or email OTP remains a documented factor
PassSelf-serve Google Authenticator-style open TOTP
StrongFIDO2 / YubiKey-class security key for sign-in
LoginGradeYubiKeyGoogle Authenticator
HHSC IAMOnline (STEPS)FailNoNot documented
TMHP IAMOnlineFailNoOptional
Okta (vendor)StrongYesYes
HHS staff VPN / Microsoft 365FailNoApp PDFs exist; SMS / voice remain

HHSC IAMOnline documents password, a security question, email, and optional Okta Verify. Okta Verify is a vendor-locked app (code or push) — that is not open TOTP. Okta Verify setup does not name Google Authenticator or YubiKey.

TMHP IAMOnline auto-enrolls email MFA and offers Okta Verify or Google Authenticator. Email remaining keeps the grade at Fail. Prefer the authenticator on a managed phone.

Okta’s own account can be Strong. The HHSC tenant still lets email through. Staff HHS MFA for VPN and Office 365 is a different stack (phone call or text). Do not treat that page as STEPS MFA.

Directory: MFA support directory · Category → Healthcare.

ProductBest forGet it
YubiKey 5C NFCUSB-C laptops + NFC phonesAmazon
YubiKey 5 NFCUSB-A desktops + NFC phonesAmazon
Proton PassPasskeys + authenticator-style TOTPProton Pass

We may earn a commission if you buy a YubiKey or sign up for Proton Pass through the links above.

Hardware security key beside a phone showing a generic authenticator code

Independent cybersecurity audits

We audited the HHSC public site, the PFD host, TMHP, and the GovDelivery bulletin host on October 8, 2026. 100% is the ideal — none reach it. These scores are public email / transport / website posture. They do not mean STEPS was breached.

OrganizationDomainOverallvs 100%
TMHPtmhp.com74%−26
HHSChhs.texas.gov48%−52
GovDeliverygovdelivery.com47%−53
HHSC PFDpfd.hhs.texas.gov35%−65
DomainIdentityTransportWebsite
tmhp.com65%15%90%
hhs.texas.gov0%15%90%
govdelivery.com35%45%37%
pfd.hhs.texas.gov0%45%43%

Audit links: tmhp.com · hhs.texas.gov · govdelivery.com · pfd.hhs.texas.gov

hhs.texas.gov Identity 0% is why a Gmail + stolen PFD logo is plausible in the inbox. Type hhs.texas.gov and the PFD STEPS page. Do not trust a “verify entity contacts” button even when the logo looks right.

tmhp.com still leads this set at 74%, with Email Infrastructure 100%, but Transport stays at 15% — the same recurring gap we flagged on the IAMOnline cutover post.

Printed domain-audit scores well below the 100 percent ideal

Website stack

Passive homepage + Certificate Transparency probes (October 8, 2026). Versions only.

DomainStack note
hhs.texas.govDrupal 11 behind 11.4.8; Sectigo TLS expires 2027-01-06
pfd.hhs.texas.govDrupal 11 behind 11.4.8; Let’s Encrypt TLS expires 2027-01-06
tmhp.comDrupal 10 (latest Drupal is 11.4.8); HTTP→HTTPS redirect not confirmed on probed hosts
govdelivery.comWordPress 7.1.2 (wordpress.org 7.1.3); DigiCert TLS expires 2027-01-05

A Drupal 10 Medicaid portal is not the same as an unsupported CMS, but it is a public signal that tmhp.com is not on the current major line. GovDelivery being one patch behind WordPress core is a bulletin-host note, not proof the Oct 8 alert is fake.

Blacklist and lookalikes

Email blacklist checks (public DoH, October 8, 2026): hhs.texas.gov, pfd.hhs.texas.gov, tmhp.com, and govdelivery.com were clear on mail/domain lists we can query. pfd.hhs.texas.gov has no MX of its own (content host).

Registered lookalikes (BEC profile — not proof this Gmail wave used them):

Brand scannedTo reviewLikely ownedBEC staging
hhs.texas.gov1302
tmhp.com1201
govdelivery.com140
LookalikeTechniqueSignal
texas.cloud / texas.usTLD swap of texas.govNS + MX (BEC staging)
tmshp.comInsertionNS + MX (BEC staging)
govdelivery.coTLD swapRegistered (NS + A + MX)
govdelivery.info / .net / .org / .usTLD swapRedirect to www.govdelivery.com

The hhs.texas.gov pass expands the registrable parent texas.gov. Hosts such as texas.com are ordinary commercial TLD swaps — not evidence they were used in this STEPS lure. Type hhs.texas.gov, pfd.hhs.texas.gov, tmhp.com, and the GovDelivery bulletin. Continuous monitoring: Cybersquat Domain Monitoring.

CourtListener RECAP searches for STEPS, Provider Finance, and this impersonation wave did not return a matching docket. Unrelated HHS / McKesson civil cases are a different story.

What STEPS providers should do

  1. Delete the Gmail. Do not click, sign, or “verify entity contacts” from it.
  2. Open STEPS from a saved bookmark or by typing pfd.hhs.texas.gov.
  3. Keep HHSC IAMOnline and TMHP IAMOnline in separate password-manager entries.
  4. On TMHP IAMOnline, add Google Authenticator on top of email MFA. On HHSC IAMOnline, enroll Okta Verify if your tenant allows it — and treat email codes as phishable.
  5. If you clicked: tell IT, reset passwords on typed hosts, scan the device, then call 1-737-86-STEPS.

Sources: HHSC GovDelivery bulletin 42e7780, Oct 8, 2026 · PFD STEPS transition · HHSC IAMOnline Okta Verify · IAMOnline security methods · HHS staff MFA · TMHP IAMOnline MFA notice · Okta YubiKey. Independent EmailMeNow audits, website-tech, blacklist, cybersquat, and CourtListener searches October 8, 2026. Domain scores: audit.emailmenow.com only. No lure URLs, exploit PoCs, or sample pages in this post.