Back to news
Cybersecurity Alert
August 15, 2026 by EmailMeNow IT Consulting

JPS Health Network Took Systems Offline After “Suspicious Activity” — EHR Back, MyChart Still Down

Fort Worth’s JPS Health Network isolated systems Aug 3 after suspicious activity. EHR returned Aug 15; MyChart stayed down. Audits (ideal 100%): jpshealthnet.org 33% (Identity 0%); jpshealth.org 58%. MyChart MFA: SMS/email OTP, passkeys on login, no documented YubiKey.

Source: JPS Health Network · Fort Worth Star-Telegram · Fort Worth Report

NewsHealthcareTexasFort WorthOutageMFAMyChartCybersecurity
Hospital nurses station with paper charts while computer monitors sit dark during a network downtime

JPS Health Network — Tarrant County’s taxpayer-supported hospital district, including John Peter Smith Hospital in Fort Worth — isolated its technology environment after identifying “suspicious activity” on August 3, 2026. The network called the response a controlled network downtime. On August 15, JPS said the core electronic health record was back online and ambulance diversion for trauma, stroke, and STEMI patients had ended. MyChart remained unavailable.

JPS has not called this ransomware, a data breach, or unauthorized access to patient files. Treat the cause as unconfirmed until the hospital district, a regulator, or a court record says otherwise.

We scanned jpshealthnet.org and jpshealth.org, checked MyChart MFA (YubiKey and Google Authenticator), and probed lookalikes that will matter if “your portal is back — log in here” mail starts landing.

Hospital nurses station with paper charts while computer monitors sit dark during a network downtime

Snapshot

FieldDetail
OrganizationJPS Health Network (Tarrant County Hospital District)
Domainsjpshealthnet.org (public site) · jpshealth.org (mail / MyChart parent)
TriggerSuspicious activity — JPS wording, not a named threat actor
IsolationControlled network downtime from Aug 3, 2026
RestorationCore EHR back Aug 15; MyChart still down “soon”
Confirmed theft / ransomNo — do not write “was breached” from this outage alone

What JPS and local press have said

According to the JPS network-update page, Fort Worth Report (Aug 14), CBS Texas, and the Star-Telegram (Aug 15):

  • Aug 3 — JPS identified suspicious activity and took systems down to isolate the environment.
  • Staff used paper charting and downtime procedures. Outpatient pharmacies, labs, and clinics were disrupted; some patients could not refill medications.
  • Trauma / stroke / STEMI ambulances were diverted while the EHR was offline.
  • DysruptionHub reported a Texas AG catastrophe notice pausing public-information requests Aug 6–12 (“Our network is down”) — still not a breach filing.
  • Aug 15 — Core EHR restored; diversion ended; pharmacies, registration, labs, and clinics back to normal; elective procedures resuming. MyChart still offline.

No public ransomware leak-site claim was tied to JPS as of mid-August reporting.

Clinicians using paper charts during an electronic-record outage

MyChart MFA (YubiKey and Google Authenticator)

Public docs and the live login only — not a logged-in mystery shop. Same grades as our MFA directory.

GradeMeaning
FailDocumented second factor is SMS, voice, or email OTP
PartialBetter than SMS, but no open TOTP and no YubiKey/FIDO
Pass (TOTP)Self-serve Google Authenticator-style OATH TOTP
StrongFIDO2 / YubiKey-class security key for sign-in
PortalYubiKey / FIDOGoogle Auth / TOTPGrade
JPS MyChart (2022 handout)NoNot documentedFail
Epic MyChart platform (2-step help)Passkey-on-key onlyYes (authenticator app)Fail

JPS’s own patient handout describes email codes, an optional skip this device checkbox, and the ability to opt out. The live JPS login shows Log in with passkey. Epic’s generic help also documents email or text codes or an authenticator app, and says passkeys can live on a security key.

That is still Fail under our SIM-swap / inbox-OTP rule: SMS and email OTP remain the documented JPS story. Passkeys improve phishing resistance when enrolled; they do not promote the row to Pass or Strong while OTP is the primary path. We do not treat Epic’s generic authenticator-app help as confirmed open TOTP on the JPS tenant.

When MyChart returns, expect “your portal is restored — verify here” phishing. Prefer a passkey (or a hardware key if the browser offers one). Do not type SMS or email codes into a lookalike host.

Hardware security key and authenticator app beside a weak SMS one-time code

Independent cybersecurity audits

EmailMeNow domain audits on August 15, 2026. 100% is the ideal overall score — none of these reach it. Scores are public identity / transport / website posture. They do not prove what caused the downtime.

OrganizationDomainOverallIdentityTransportWebsite
JPS Health Networkjpshealthnet.org33%0%15%40%
JPS mail / MyChart parentjpshealth.org58%65%15%37%
Epic MyChart helpmychart.org54%55%15%37%
Epic (EHR vendor)epic.com69%50%45%89%

Audit links: jpshealthnet.org · jpshealth.org · mychart.org · epic.com

Pattern: the public brand host sits 67 points under ideal, with Identity 0% and no MX on the apex (mail appears to live on jpshealth.org). Both JPS hosts share 15% Transport (MTA-STS / related). Impersonation of the website brand is the cheap follow-on after a two-week outage — “JPS billing,” “MyChart is back,” “reschedule your diverted appointment.”

Domain-audit shield metaphor for hospital email security scores

Website stack note

Passive website-tech probes on August 15, 2026 (--deep --fresh):

DomainStack
jpshealthnet.orgDrupal 8 (outdated — current Drupal is 11.4.5); DigiCert TLS to 2027-01-31; HTTP→HTTPS redirect not confirmed
jpshealth.orgStack undetected; HTTP→HTTPS redirect not confirmed
mychart.orgNext.js; DigiCert TLS to 2026-12-08 (~115 days at probe)

Drupal 8 is long past vendor support. That is a public CMS signal, not proof of the August isolation path.

Blacklist / deliverability

Mail/domain DNSBL probes August 15, 2026 (public DoH). Shared-MX hits would be low-signal — do not read as “org blacklisted.”

DomainMail/domain statusNote
jpshealthnet.orgNo MXApex has no mail IPs to score
jpshealth.orgClear4 MX IPs checked
mychart.orgClear1 MX IP checked

Spamhaus ZEN/DBL/ZRD were unavailable via public resolvers — verify on check.spamhaus.org before claiming clean/listed there.

Cybersquat / lookalikes

--bec --registered-only scans August 15, 2026. No BEC staging (NS+MX with no website A/AAAA) on either brand. Several registered lookalikes still have live MX — useful for “MyChart restored” lures.

BrandCheckedTo reviewMX lookalikes
jpshealthnet.org2263pshealthnet.org (omission)
jpshealth.org17911joshealth.org, jphealth.org, jshealth.org

Also registered (site A, no MX in this pass): jpshealthnet.com, jpshealtnhet.org, jpshealth.com, jpshealth.net, jpshealth.biz. Track with Cybersquat Domain Monitoring.

CourtListener

Texas federal RECAP (txsd txed txnd txwd) and a nationwide keyword search found no docket for the August 2026 JPS outage, ransomware, or a patient data-breach class action as of August 15, 2026.

Older Tarrant County Hospital District / JPS filings (employment, opioid MDL, civil rights) are not this incident.

What patients and clinics should do

DoDon’t
Use official JPS numbers and jpshealthnet.org/network-downtimeTrust “MyChart is back” mail or texts with a new link
Enroll a passkey when the portal returns; ask JPS for open TOTP / YubiKeyType SMS or email OTP into a lookalike host
Watch credit / EOBs if JPS later confirms a records incidentAssume paper-chart downtime means data was stolen — or that it wasn’t
Run a free domain audit on any clinic you operateTreat Drupal 8 or a 33% score as the confirmed root cause

Texas organizations that later determine a breach affected 250 or more residents must notify the attorney general under Business & Commerce Code §521.053. HIPAA-covered providers also report qualifying incidents to HHS OCR. Neither listing is a substitute for JPS’s own statement.

Also in this scan (not this post)

LeadWhy we did not make it the lead
Texas Hearing Institute (~30k patients)Already a row on our Texas healthcare tracker; March incident, June notices
Coryell County “technology disruption”Unconfirmed cause; smaller than a two-week Level I trauma downtime
Midland / Permiacare ~$63,599 BEC arrestStrong email-fraud follow-up; different fact pattern
National ransomware policy / K-12 trend piecesNot a named Texas hospital incident
Fort Bliss phishing tips, lawyer commentary, Michigan NLRBIrrelevant or out of geo

Protect your organization.

Run a free Instant Cybersecurity Audit at audit.emailmenow.com — and contact EmailMeNow IT Consulting for healthcare MFA, DMARC, and downtime-comms baselines aimed at the 100% ideal.


Sources: JPS network update · Fort Worth Report, Aug 14, 2026 · CBS Texas · Fort Worth Star-Telegram, Aug 15, 2026 · DysruptionHub (cause unconfirmed) · JPS MyChart 2FA handout (2022) · Epic MyChart two-step verification and passkeys. Independent EmailMeNow audits, website-tech, blacklist, and cybersquat probes August 15, 2026. Domain scores: audit.emailmenow.com only. Do not treat this outage as a confirmed breach unless JPS, Texas OAG, or HHS OCR says so.