Skip to content

JPS Health Network suspicious activity and downtime

Summary

JPS Health Network logo

JPS Health Network took systems offline after identifying suspicious activity August 3, disrupting technology, communications, records processing and care workflows across its hospital and clinics. Its core electronic health record returned August 14, ending an ambulance diversion and restoring clinics, laboratories, pharmacies and elective procedures; MyChart followed and routine operations resumed August 16. JPS has not disclosed malicious or unauthorized activity, ransomware, data impact or a responsible actor.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.
  • Incident end:
    ? Confirmed or defensibly assessed end of material operational disruption or incident activity.

Primary victim organization

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Unknown cyber mechanism

    The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.

Data impacts

  • Unknown data impact

    The incident is cyber-related, but available evidence does not establish whether or how data was affected.

Operational impacts

  • Partial service outage

    A service, system, platform, or operational capability remained available only in part or with significant limitations.

  • Network outage

    Internal or external network connectivity was unavailable or materially impaired.

  • Phone service disruption

    Telephone, voice-over-IP, call-center, or related voice communication services were unavailable or materially impaired.

  • Online portal unavailable

    A public, customer, employee, student, patient, vendor, or partner portal was unavailable or materially impaired.

  • Internal systems unavailable

    Internal business, administrative, operational, or staff-facing systems were unavailable.

  • Scheduling disruption

    Appointment, booking, reservation, dispatch, staffing, or other scheduling functions were unavailable or impaired.

  • Healthcare operations disrupted

    Clinical, diagnostic, pharmacy, patient-care, medical-record, or other healthcare operations were materially affected.

  • Government services disrupted

    Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.

  • Manual workaround required

    Staff or users had to rely on paper, telephone, in-person, offline, or other manual processes.

  • Alternate service channel required

    The organization redirected users to a different website, office, telephone number, email address, provider, or service channel.

  • Service delay

    Services continued but with longer processing, response, delivery, or completion times.

Incident narrative

Analyst assessment

DysruptionHub assesses with high confidence that JPS Health Network experienced a material technology disruption after identifying suspicious activity in its environment early August 3, 2026. JPS’s network update said it deliberately took network systems down to isolate and secure the environment. That qualified, cyber-specific victim wording is concrete public evidence of cyber involvement, although it does not establish that the activity was malicious or unauthorized.

JPS has not confirmed ransomware, malware, data access or theft, extortion, a ransom demand or a responsible actor. Confirmed cyber involvement is limited to the existence of concrete cyber evidence and does not resolve those subsidiary questions.

Operational significance

The outage affected technology systems, communications and normal clinical and administrative workflows. Clinicians and staff used downtime procedures, online services and phone lines were affected, some services could be paused, adjusted or moved, and the Tarrant County Hospital District suspended public-information processing.

JPS’s August 14 update disclosed additional clinical impact. Its core electronic health record had been unavailable, elective procedures had been postponed, and the network had temporarily diverted ambulance and emergency medical services arrivals for stroke, trauma and serious heart-attack patients. JPS said the electronic health record was back online, the diversion had ended, outpatient pharmacies, patient registration, laboratories and community clinics had returned to normal, and elective procedures had resumed with postponed procedures being rescheduled. MyChart and some business systems remained unavailable that day.

The public record does not show that emergency treatment, trauma services or inpatient care stopped. The diversion, procedure delays and system downtime nevertheless establish material health care disruption and service delay.

Disclosure posture

JPS’s public explanation evolved from a general outage notice to an acknowledgement of suspicious activity and an intentional isolation decision. The network page dates the cyber-specific statement August 7; its reference to activity early August 3 describes detection timing, not public disclosure timing. No earlier stable external claim or independently supported public cyber characterization was found.

Current status

JPS announced August 16 that MyChart was available and routine operations had resumed. That positive restoration statement supports classifying the incident as resolved and establishes August 16 as the end of material operational impact. The latest preceding impact observation is August 14, when MyChart and some business systems remained unavailable while restoration continued.

The resolved operational status does not mean the underlying investigation, security work or potential data review has concluded. It describes the restoration of routine services.

Confidence and uncertainty

Confidence is high that a material network and technology outage disrupted normal health care and administrative workflows because JPS and the hospital district documented unavailable systems, downtime procedures, delays, an ambulance diversion, affected patient resources and suspended records processing. Confidence is also high that concrete public cyber evidence exists because JPS directly reported suspicious activity in its technology environment.

The public record does not establish whether the activity was malicious or unauthorized, what triggered the detection or whether an account, device or network segment was accessed. Ransomware involvement and threat-actor attribution remain unresolved, and available evidence does not establish whether or how data was affected.

Analytic gaps

The public record does not identify the initial access vector, compromised credential or host, vulnerability, malware family, persistence, encryption, exfiltration, affected data categories, record count, ransom demand or responsible actor. It also does not establish the full electronic-health-record impact, affected service volume, patient-safety events, prescription delays, third-party role, restoration sequence or final investigative findings.

Organizations involved

Impacted locations

  • Fort Worth, Texas

    The principal hospital and affected health-network operations are based in Fort Worth.

  • Tarrant County, Texas

    JPS is the Tarrant County Hospital District and operates a countywide public health network.

Sources

Possible cyber incident eyed as JPS Health Network in Texas remains in multiday downtime

DysruptionHub reported that JPS technology systems had remained unavailable since at least August 3, with phone and online resources affected, manual procedures in use and public-records processing suspended. It raised cybersecurity as a possibility while emphasizing that JPS had not disclosed the cause or confirmed malicious activity, ransomware, data theft, extortion or a threat actor.

JPS Health Network outage notice

JPS Health Network announced that an outage was affecting several patient resources, including online services and phone lines. The notice acknowledged the operational disruption but did not identify its cause or characterize it as cyber-related.

Tarrant County Hospital District d/b/a JPS Health Network Catastrophe Notice

The Tarrant County Hospital District filed a catastrophe notice stating that its network was down and it was unable to respond to public-information requests. The notice suspended applicable processing from August 6 through August 12, 2026, and did not identify the outage cause.

Network Update

JPS said its core electronic health record returned August 14, an ambulance and EMS diversion ended, outpatient pharmacies, registration, laboratories and community clinics returned to normal, and elective procedures resumed. MyChart and some business systems remained unavailable that day. On August 16, JPS said MyChart was available and routine operations had resumed.

See something that needs correction?

Signed-in members can report an error, update, or missing source.