JPS Health Network — Tarrant County’s taxpayer-supported hospital district, including John Peter Smith Hospital in Fort Worth — isolated its technology environment after identifying “suspicious activity” on August 3, 2026. The network called the response a controlled network downtime. On August 15, JPS said the core electronic health record was back online and ambulance diversion for trauma, stroke, and STEMI patients had ended. MyChart remained unavailable.
JPS has not called this ransomware, a data breach, or unauthorized access to patient files. Treat the cause as unconfirmed until the hospital district, a regulator, or a court record says otherwise.
We scanned jpshealthnet.org and jpshealth.org, checked MyChart MFA (YubiKey and Google Authenticator), and probed lookalikes that will matter if “your portal is back — log in here” mail starts landing.

Snapshot
| Field | Detail |
|---|---|
| Organization | JPS Health Network (Tarrant County Hospital District) |
| Domains | jpshealthnet.org (public site) · jpshealth.org (mail / MyChart parent) |
| Trigger | Suspicious activity — JPS wording, not a named threat actor |
| Isolation | Controlled network downtime from Aug 3, 2026 |
| Restoration | Core EHR back Aug 15; MyChart still down “soon” |
| Confirmed theft / ransom | No — do not write “was breached” from this outage alone |
What JPS and local press have said
According to the JPS network-update page, Fort Worth Report (Aug 14), CBS Texas, and the Star-Telegram (Aug 15):
- Aug 3 — JPS identified suspicious activity and took systems down to isolate the environment.
- Staff used paper charting and downtime procedures. Outpatient pharmacies, labs, and clinics were disrupted; some patients could not refill medications.
- Trauma / stroke / STEMI ambulances were diverted while the EHR was offline.
- DysruptionHub reported a Texas AG catastrophe notice pausing public-information requests Aug 6–12 (“Our network is down”) — still not a breach filing.
- Aug 15 — Core EHR restored; diversion ended; pharmacies, registration, labs, and clinics back to normal; elective procedures resuming. MyChart still offline.
No public ransomware leak-site claim was tied to JPS as of mid-August reporting.

MyChart MFA (YubiKey and Google Authenticator)
Public docs and the live login only — not a logged-in mystery shop. Same grades as our MFA directory.
| Grade | Meaning |
|---|---|
| Fail | Documented second factor is SMS, voice, or email OTP |
| Partial | Better than SMS, but no open TOTP and no YubiKey/FIDO |
| Pass (TOTP) | Self-serve Google Authenticator-style OATH TOTP |
| Strong | FIDO2 / YubiKey-class security key for sign-in |
| Portal | YubiKey / FIDO | Google Auth / TOTP | Grade |
|---|---|---|---|
| JPS MyChart (2022 handout) | No | Not documented | Fail |
| Epic MyChart platform (2-step help) | Passkey-on-key only | Yes (authenticator app) | Fail |
JPS’s own patient handout describes email codes, an optional skip this device checkbox, and the ability to opt out. The live JPS login shows Log in with passkey. Epic’s generic help also documents email or text codes or an authenticator app, and says passkeys can live on a security key.
That is still Fail under our SIM-swap / inbox-OTP rule: SMS and email OTP remain the documented JPS story. Passkeys improve phishing resistance when enrolled; they do not promote the row to Pass or Strong while OTP is the primary path. We do not treat Epic’s generic authenticator-app help as confirmed open TOTP on the JPS tenant.
When MyChart returns, expect “your portal is restored — verify here” phishing. Prefer a passkey (or a hardware key if the browser offers one). Do not type SMS or email codes into a lookalike host.

Independent cybersecurity audits
EmailMeNow domain audits on August 15, 2026. 100% is the ideal overall score — none of these reach it. Scores are public identity / transport / website posture. They do not prove what caused the downtime.
| Organization | Domain | Overall | Identity | Transport | Website |
|---|---|---|---|---|---|
| JPS Health Network | jpshealthnet.org | 33% | 0% | 15% | 40% |
| JPS mail / MyChart parent | jpshealth.org | 58% | 65% | 15% | 37% |
| Epic MyChart help | mychart.org | 54% | 55% | 15% | 37% |
| Epic (EHR vendor) | epic.com | 69% | 50% | 45% | 89% |
Audit links: jpshealthnet.org · jpshealth.org · mychart.org · epic.com
Pattern: the public brand host sits 67 points under ideal, with Identity 0% and no MX on the apex (mail appears to live on jpshealth.org). Both JPS hosts share 15% Transport (MTA-STS / related). Impersonation of the website brand is the cheap follow-on after a two-week outage — “JPS billing,” “MyChart is back,” “reschedule your diverted appointment.”

Website stack note
Passive website-tech probes on August 15, 2026 (--deep --fresh):
| Domain | Stack |
|---|---|
jpshealthnet.org | Drupal 8 (outdated — current Drupal is 11.4.5); DigiCert TLS to 2027-01-31; HTTP→HTTPS redirect not confirmed |
jpshealth.org | Stack undetected; HTTP→HTTPS redirect not confirmed |
mychart.org | Next.js; DigiCert TLS to 2026-12-08 (~115 days at probe) |
Drupal 8 is long past vendor support. That is a public CMS signal, not proof of the August isolation path.
Blacklist / deliverability
Mail/domain DNSBL probes August 15, 2026 (public DoH). Shared-MX hits would be low-signal — do not read as “org blacklisted.”
| Domain | Mail/domain status | Note |
|---|---|---|
jpshealthnet.org | No MX | Apex has no mail IPs to score |
jpshealth.org | Clear | 4 MX IPs checked |
mychart.org | Clear | 1 MX IP checked |
Spamhaus ZEN/DBL/ZRD were unavailable via public resolvers — verify on check.spamhaus.org before claiming clean/listed there.
Cybersquat / lookalikes
--bec --registered-only scans August 15, 2026. No BEC staging (NS+MX with no website A/AAAA) on either brand. Several registered lookalikes still have live MX — useful for “MyChart restored” lures.
| Brand | Checked | To review | MX lookalikes |
|---|---|---|---|
jpshealthnet.org | 226 | 3 | pshealthnet.org (omission) |
jpshealth.org | 179 | 11 | joshealth.org, jphealth.org, jshealth.org |
Also registered (site A, no MX in this pass): jpshealthnet.com, jpshealtnhet.org, jpshealth.com, jpshealth.net, jpshealth.biz. Track with Cybersquat Domain Monitoring.
CourtListener
Texas federal RECAP (txsd txed txnd txwd) and a nationwide keyword search found no docket for the August 2026 JPS outage, ransomware, or a patient data-breach class action as of August 15, 2026.
Older Tarrant County Hospital District / JPS filings (employment, opioid MDL, civil rights) are not this incident.
What patients and clinics should do
| Do | Don’t |
|---|---|
| Use official JPS numbers and jpshealthnet.org/network-downtime | Trust “MyChart is back” mail or texts with a new link |
| Enroll a passkey when the portal returns; ask JPS for open TOTP / YubiKey | Type SMS or email OTP into a lookalike host |
| Watch credit / EOBs if JPS later confirms a records incident | Assume paper-chart downtime means data was stolen — or that it wasn’t |
| Run a free domain audit on any clinic you operate | Treat Drupal 8 or a 33% score as the confirmed root cause |
Texas organizations that later determine a breach affected 250 or more residents must notify the attorney general under Business & Commerce Code §521.053. HIPAA-covered providers also report qualifying incidents to HHS OCR. Neither listing is a substitute for JPS’s own statement.
Also in this scan (not this post)
| Lead | Why we did not make it the lead |
|---|---|
| Texas Hearing Institute (~30k patients) | Already a row on our Texas healthcare tracker; March incident, June notices |
| Coryell County “technology disruption” | Unconfirmed cause; smaller than a two-week Level I trauma downtime |
| Midland / Permiacare ~$63,599 BEC arrest | Strong email-fraud follow-up; different fact pattern |
| National ransomware policy / K-12 trend pieces | Not a named Texas hospital incident |
| Fort Bliss phishing tips, lawyer commentary, Michigan NLRB | Irrelevant or out of geo |
Related coverage
- Texas healthcare breaches (HHS / OAG tracker)
- UTSA attempted unauthorized activity
- San Antonio Gentlemen ransomware clinics
- MFA directory — YubiKey, TOTP, passkeys
- Houston City College ShinyHunters (campus MFA FAQ)
- IBM Cost of a Data Breach 2026
Protect your organization.
Run a free Instant Cybersecurity Audit at audit.emailmenow.com — and contact EmailMeNow IT Consulting for healthcare MFA, DMARC, and downtime-comms baselines aimed at the 100% ideal.
Sources: JPS network update · Fort Worth Report, Aug 14, 2026 · CBS Texas · Fort Worth Star-Telegram, Aug 15, 2026 · DysruptionHub (cause unconfirmed) · JPS MyChart 2FA handout (2022) · Epic MyChart two-step verification and passkeys. Independent EmailMeNow audits, website-tech, blacklist, and cybersquat probes August 15, 2026. Domain scores: audit.emailmenow.com only. Do not treat this outage as a confirmed breach unless JPS, Texas OAG, or HHS OCR says so.