JPS Health Network

JPS Health Network took systems offline after identifying suspicious activity August 3, disrupting technology, communications, records processing and care workflows across its hospital and clinics. Its core electronic health record returned August 14, ending an ambulance diversion and restoring clinics, laboratories, pharmacies and elective procedures; MyChart followed and routine operations resumed August 16. JPS has not disclosed malicious or unauthorized activity, ransomware, data impact or a responsible actor.
The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.
The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.
The incident is cyber-related, but available evidence does not establish whether or how data was affected.
A service, system, platform, or operational capability remained available only in part or with significant limitations.
Internal or external network connectivity was unavailable or materially impaired.
Telephone, voice-over-IP, call-center, or related voice communication services were unavailable or materially impaired.
A public, customer, employee, student, patient, vendor, or partner portal was unavailable or materially impaired.
Internal business, administrative, operational, or staff-facing systems were unavailable.
Appointment, booking, reservation, dispatch, staffing, or other scheduling functions were unavailable or impaired.
Clinical, diagnostic, pharmacy, patient-care, medical-record, or other healthcare operations were materially affected.
Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.
Staff or users had to rely on paper, telephone, in-person, offline, or other manual processes.
The organization redirected users to a different website, office, telephone number, email address, provider, or service channel.
Services continued but with longer processing, response, delivery, or completion times.
DysruptionHub assesses with high confidence that JPS Health Network experienced a material technology disruption after identifying suspicious activity in its environment early August 3, 2026. JPS’s network update said it deliberately took network systems down to isolate and secure the environment. That qualified, cyber-specific victim wording is concrete public evidence of cyber involvement, although it does not establish that the activity was malicious or unauthorized.
JPS has not confirmed ransomware, malware, data access or theft, extortion, a ransom demand or a responsible actor. Confirmed cyber involvement is limited to the existence of concrete cyber evidence and does not resolve those subsidiary questions.
The outage affected technology systems, communications and normal clinical and administrative workflows. Clinicians and staff used downtime procedures, online services and phone lines were affected, some services could be paused, adjusted or moved, and the Tarrant County Hospital District suspended public-information processing.
JPS’s August 14 update disclosed additional clinical impact. Its core electronic health record had been unavailable, elective procedures had been postponed, and the network had temporarily diverted ambulance and emergency medical services arrivals for stroke, trauma and serious heart-attack patients. JPS said the electronic health record was back online, the diversion had ended, outpatient pharmacies, patient registration, laboratories and community clinics had returned to normal, and elective procedures had resumed with postponed procedures being rescheduled. MyChart and some business systems remained unavailable that day.
The public record does not show that emergency treatment, trauma services or inpatient care stopped. The diversion, procedure delays and system downtime nevertheless establish material health care disruption and service delay.
JPS’s public explanation evolved from a general outage notice to an acknowledgement of suspicious activity and an intentional isolation decision. The network page dates the cyber-specific statement August 7; its reference to activity early August 3 describes detection timing, not public disclosure timing. No earlier stable external claim or independently supported public cyber characterization was found.
JPS announced August 16 that MyChart was available and routine operations had resumed. That positive restoration statement supports classifying the incident as resolved and establishes August 16 as the end of material operational impact. The latest preceding impact observation is August 14, when MyChart and some business systems remained unavailable while restoration continued.
The resolved operational status does not mean the underlying investigation, security work or potential data review has concluded. It describes the restoration of routine services.
Confidence is high that a material network and technology outage disrupted normal health care and administrative workflows because JPS and the hospital district documented unavailable systems, downtime procedures, delays, an ambulance diversion, affected patient resources and suspended records processing. Confidence is also high that concrete public cyber evidence exists because JPS directly reported suspicious activity in its technology environment.
The public record does not establish whether the activity was malicious or unauthorized, what triggered the detection or whether an account, device or network segment was accessed. Ransomware involvement and threat-actor attribution remain unresolved, and available evidence does not establish whether or how data was affected.
The public record does not identify the initial access vector, compromised credential or host, vulnerability, malware family, persistence, encryption, exfiltration, affected data categories, record count, ransom demand or responsible actor. It also does not establish the full electronic-health-record impact, affected service volume, patient-safety events, prescription delays, third-party role, restoration sequence or final investigative findings.

The principal hospital and affected health-network operations are based in Fort Worth.
JPS is the Tarrant County Hospital District and operates a countywide public health network.
DysruptionHub reported that JPS technology systems had remained unavailable since at least August 3, with phone and online resources affected, manual procedures in use and public-records processing suspended. It raised cybersecurity as a possibility while emphasizing that JPS had not disclosed the cause or confirmed malicious activity, ransomware, data theft, extortion or a threat actor.
JPS Health Network announced that an outage was affecting several patient resources, including online services and phone lines. The notice acknowledged the operational disruption but did not identify its cause or characterize it as cyber-related.
The Tarrant County Hospital District filed a catastrophe notice stating that its network was down and it was unable to respond to public-information requests. The notice suspended applicable processing from August 6 through August 12, 2026, and did not identify the outage cause.
JPS said its core electronic health record returned August 14, an ambulance and EMS diversion ended, outpatient pharmacies, registration, laboratories and community clinics returned to normal, and elective procedures resumed. MyChart and some business systems remained unavailable that day. On August 16, JPS said MyChart was available and routine operations had resumed.
Signed-in members can report an error, update, or missing source.