Healthcare Cybersecurity week 33, 2026

A suspected cyberattack forced Fort Worth’s JPS Health Network into more than a week of controlled downtime and ambulance diversions, while the Gentlemen ransomware group hijacked AnMed’s Facebook page to threaten release of HIV, sexual assault, and mental health records.
healthcare
Published

August 15, 2026

Executive Summary

Fort Worth’s JPS Health Network spent nearly two weeks in controlled network downtime after detecting suspicious activity on August 3, diverting trauma, stroke, and heart attack patients to other hospitals before beginning to restore core systems late in the reporting window. South Carolina and Georgia health system AnMed, still recovering from a July 26 malware attack, saw the extortion pressure escalate when the ransomware group calling itself the Gentlemen hijacked its Facebook page to post claims of stolen HIV status, sexual assault, and mental health records directly to patients. A joint federal advisory detailed Gunra, a Conti-derived ransomware operation that has breached at least 51 healthcare, government, and financial organizations by exploiting long-patched Fortinet flaws, and researchers at DEF CON warned that the sector’s cybersecurity failures have become inseparable from patient safety. The Coalition for Health AI also moved to get ahead of a newer risk, convening a work group of health systems to build cyber-risk playbooks for frontier AI models.

This report covers cybersecurity threats to the healthcare sector including hospitals, medical devices, health IT systems, and pharmaceutical supply chains.


Week of August 7 - August 14, 2026

Hospital & Health System Attacks

JPS Health Network, which operates a 582-bed hospital and more than 25 community clinics across Tarrant County, Texas, identified suspicious activity in its technology environment early on August 3 and responded by deliberately taking its network systems offline in what it called a controlled downtime. The outage stretched past the ten-day mark during this reporting window, forcing clinical staff onto paper intake forms, cutting off patient access to MyChart for appointment scheduling and prescription refills, and pushing Fort Worth Fire to place JPS on EMS diversion for trauma, stroke, and STEMI heart attack patients, with ambulances rerouted to other area hospitals. JPS has not disclosed whether the incident involves ransomware or unauthorized data access, describing it only as suspicious activity under investigation, but by August 15 the health system reported major progress toward normal operations, having restored its core electronic health record system and resumed accepting trauma, stroke, and cardiac ambulance traffic, with outpatient pharmacies, registration, labs, and community clinics also back online. The extended timeline underscores a pattern that has become familiar this year: hospitals increasingly choose to isolate their entire network at the first sign of compromise rather than risk a faster-moving encryption event, accepting more than a week of degraded operations as the cost of containment.

AnMed, the nonprofit health system serving upstate South Carolina and northeast Georgia that closed 83 of its 106 facilities after a July 26 malware attack, saw its incident take a more aggressive turn this week when a threat actor hijacked the organization’s Facebook page. Over 100 posts appeared on the page attributed to a ransomware-as-a-service group calling itself the Gentlemen, culminating in an August 11 posting that claimed 6 terabytes of stolen data including records tied to HIV-positive patients, suicide registries, sexual assault and rape victims, mental health treatment, abortion care, genetic data, patient Social Security numbers and dates of birth, and autopsy and police evidence. AnMed said the claims in the unauthorized posts remain unverified and under investigation, and it has not confirmed whether patient information was in fact compromised. The tactic of hijacking a hospital’s own social media presence to post extortion demands directly to patients, rather than relying solely on a dark web leak site, marks an escalation in how ransomware affiliates are trying to maximize psychological pressure on healthcare victims specifically because the threatened data categories carry acute personal and reputational stakes for patients.

Medical Device Vulnerabilities

CISA’s medical device advisory activity this week centered on consumer-grade wearables rather than hospital equipment, a shift worth flagging for healthcare providers who increasingly recommend or integrate such devices into patient care pathways. ICSMA-26-223-02 disclosed a critical flaw in the Pulsetto vagus nerve stimulator, a Bluetooth-connected wellness device, whose firmware accepts undocumented commands over its Bluetooth Low Energy interface with no authentication or encryption, potentially letting a nearby attacker disable the device’s electrical safety mechanisms or alter its stimulation output; Pulsetto has not responded to CISA’s outreach, so no fix exists. A companion advisory, ICSMA-26-223-01, covered the Mira hormone monitor and its Android app, a fertility-tracking device, disclosing flaws that let an unauthenticated attacker within Bluetooth range silently rebind the device to an attacker-controlled account and extract stored hormone measurements in cleartext, alongside hardcoded API keys and third-party analytics SDKs transmitting user data off-device; Mira has shipped fixes across its iOS, Android, and firmware versions. Both devices sit outside the hospital procurement and patching processes that govern traditional medical equipment, and clinicians who direct patients toward Bluetooth-connected wellness or fertility trackers should be aware that these products currently carry weaker security assurances than FDA-regulated hospital devices.

EHR, Health IT & Cloud Breaches

No major new health IT vendor breach surfaced during the reporting window, a relative pause following recent disclosures at revenue cycle vendor Unlimited Technology Systems, billing software maker Craneware, and EHR platform CareCloud. Health IT security teams should treat this as a window to work through the backlog rather than a signal that supply chain risk has eased, since forensic investigations into several of those incidents remain open and could still expand in scope, as Unlimited Technology Systems’ revision from 442,000 to 3.8 million affected individuals demonstrated the week prior.

Pharmacy & Supply Chain

No new pharmacy or drug supply chain incident was reported this week following the Anubis ransomware group’s claimed attack on Blackburn’s Physicians Pharmacy the previous week. Industry reporting continued to highlight the underlying fragility of pharmaceutical supply chains more broadly, with active US drug shortages climbing to 227 in the second quarter of 2026, the third consecutive quarterly increase, and nearly half of new shortages traced to medications made by a single manufacturer. That concentration risk compounds the cybersecurity exposure documented throughout the year: a ransomware attack on any single-source manufacturer’s production or quality systems now carries the potential to trigger a shortage directly, rather than merely disrupting billing or records.

Regulatory & Compliance

The Coalition for Health AI announced on August 12 the formation of a Health AI Cybersecurity Work Group, bringing together security leaders from more than eight health systems to build the industry’s first practical playbooks addressing frontier AI model cyber risk, alongside a planned AI cyber risk assessment tool for health systems, payers, and health technology companies. The group will meet biweekly and plans to publish its first deliverables by the end of 2026, with organizers citing the accelerating capability of frontier AI models to identify network vulnerabilities and compress attack timelines from days to seconds as the motivating threat. No new HIPAA settlement was announced during the week, leaving OCR’s Risk Analysis Initiative at six resolved investigations and 1,278,000 dollars in penalties collected in 2026, and the proposed overhaul of the HIPAA Security Rule remains unfinished with the Office of Management and Budget still targeting July 2027 for finalization.

Threat Actor Activity

CISA, the FBI, the Department of Defense Cyber Crime Center, the NSA, the Secret Service, and South Korea’s National Police Agency issued a joint advisory on August 10 detailing Gunra, a double-extortion ransomware-as-a-service operation derived from leaked Conti source code that has breached at least 51 organizations worldwide, with healthcare, government, and financial services among its most concentrated targets. Gunra’s primary access method is exploitation of two Fortinet FortiOS and FortiProxy authentication bypass vulnerabilities, CVE-2024-55591 and CVE-2025-24472, both patched for well over a year, underscoring that unremediated known vulnerabilities rather than novel tradecraft continue to drive successful intrusions against hospitals running exposed VPN infrastructure. The Gentlemen, the group behind AnMed’s ongoing extortion campaign, has emerged as one of the most prolific ransomware-as-a-service operations since surfacing in the second half of 2025 and was Dragos’s third-most-active industrial ransomware group in the second quarter of 2026 with 125 claimed attacks, indicating a healthcare-adjacent group with substantial operational tempo well beyond this single incident.

Speaking at DEF CON on August 8, Christian Dameff, co-director of the University of California San Diego’s Center for Healthcare Cybersecurity, told attendees that cyberattacks have pushed hospitals and clinics to a breaking point, framing the issue in stark terms: “These are patient safety issues, and yet these types of attacks continue to increase.” Dameff pointed to healthcare’s rapid digital transformation, including the transition to electronic health records, as having outpaced the security infrastructure needed to protect it, a theme that continues to run through this year’s ransomware mortality research and the JPS and AnMed incidents playing out concurrently this week.

Defensive Recommendations

Healthcare organizations running internet-facing Fortinet FortiOS or FortiProxy instances should treat CVE-2024-55591 and CVE-2025-24472 as immediate patching priorities given their continued active exploitation by Gunra affiliates specifically against the sector. Hospitals should review whether their incident response playbooks account for social media account compromise as an extortion vector following AnMed’s Facebook hijacking, including who holds administrative access to official accounts, how quickly that access can be revoked, and what pre-drafted patient communication can counter unverified extortion claims posted under the organization’s own name. JPS Health Network’s extended controlled-downtime response is a useful benchmark for continuity planning: EMS diversion protocols, paper-based clinical workflows, and pharmacy contingency procedures should be tested as standing capabilities rather than improvised during an active incident. Clinicians recommending Bluetooth-connected wellness or fertility tracking devices to patients should be aware that products like Pulsetto and Mira currently fall outside the security assurance framework applied to FDA-regulated hospital equipment, and should weigh that gap when counseling patients on data sensitivity. Finally, health systems evaluating frontier AI deployments should track the Coalition for Health AI’s forthcoming playbooks as a starting point for structuring AI-specific cyber risk assessments, given the near-total absence of sector-specific guidance on this risk category to date.

Sources Referenced

  • Fort Worth Report: JPS experiences fifth day of network outage after hospital detects suspicious activity, August 7, 2026
  • Becker’s Hospital Review: JPS Health Network outage stretches into 8th day in Fort Worth, August 2026
  • Hoodline: JPS Health Network Hits Fifth Day Of Outage, Patients Stuck On Paper Forms, August 2026
  • WFAA: JPS Health Network says it found ‘suspicious activity’ before taking systems down, August 2026
  • CBS Texas: JPS Health Network says it has restored key systems after “suspicious activity” disruption, August 15, 2026
  • International Cyber Digest via X: AnMed’s Facebook page hijacked to post ransomware extortion note, August 11, 2026
  • The Record from Recorded Future News: Ransomware group hijacks hospital system’s Facebook page amid ongoing cyberattack fallout, August 2026
  • HealthExec: ‘The Gentlemen’ ransomware gang takes over hospital Facebook after cyberattack, August 2026
  • Becker’s Hospital Review: AnMed hit with data theft claim after Facebook hack, August 2026
  • HIPAA Journal: AnMed Investigating Ransomware Group’s Data Theft Claims, August 2026
  • CISA: ICSMA-26-223-02 — Pulsetto Vagus Nerve Stimulator, August 11, 2026
  • CISA: ICSMA-26-223-01 — Mira Hormone Monitor, Mira Android App, August 11, 2026
  • HIPAA Journal: Critical Vulnerabilities Identified in Popular Consumer Fertility Device, August 2026
  • Cleverdude: CISA Warns All Pulsetto Vagus Nerve Stimulators Have Unpatched Bluetooth Vulnerability, August 2026
  • CISA: AA26-222A — #StopRansomware: Gunra Ransomware, August 10, 2026
  • HSToday: CISA, FBI Warn Gunra Ransomware Actors Targeting Critical Infrastructure, August 2026
  • HIPAA Journal: Healthcare Orgs Warned About Gunra Ransomware Attacks, August 2026
  • Beckers Hospital Review: Gunra ransomware targets hospitals: CISA, FBI issue new warning, August 2026
  • The Register: Feds warn Gunra ransomware is exploiting known bugs to hit critical infrastructure, August 11, 2026
  • Dragos: Industrial Ransomware Analysis for Q2 2026, August 11, 2026
  • Cybersecurity Dive: Experts say healthcare faces cybersecurity crisis: ‘These are patient safety issues’, August 8, 2026
  • Healthcare Dive: Experts say healthcare faces cybersecurity crisis: ‘These are patient safety issues’, August 2026
  • PYMNTS: Coalition for Health AI Mounts Effort Against Cyberattacks, August 2026
  • HCInnovation Group: Coalition for Health AI (CHAI) Convenes New Health AI Cybersecurity Work Group, August 12, 2026
  • Healthcare IT News: CHAI forms Health AI Cybersecurity Work Group, August 2026
  • Healthcare Dive: CHAI creates work group to counter frontier AI model cybersecurity risks, August 2026
  • USP: 2026 Annual Drug Shortages Report Reveals Rising Discontinuations and Supply Chain Risks, 2026