Cyber Threat Brief 2026
Executive Summary
Veterinary practices in Texas hold a uniquely attractive combination of personal and operational data: pet owner names, home addresses, emergency contacts, home security codes, financial information, and medical records — all tied to a living creature that may visit the same practice for years, even a decade or more. Unlike credit card data, which can be cancelled and replaced, pet owner data in a veterinary practice management system (PMS) has an exploitation window measured in years, not months. Once breached, that data remains valid for future attacks long after the breach notification letter has been filed.
The National Veterinary Associates (NVA) breach in 2024 confirmed the scale of the threat: 1.1M+ pet records exposed across 1,400+ US veterinary hospitals, including hundreds of Texas locations. The breach wasn't a targeted attack on a single practice — it was a supply chain compromise through NVA's management platform that cascaded to every affiliated location simultaneously. LockBit, BlackCat, and Rhysida ransomware groups have specifically escalated veterinary sector targeting in 2024–2025, recognizing that small practices typically lack dedicated IT security staff and that PMS credentials provide access to a rich dataset of pet owner PII.[1]
NVA confirmed the breach in 2024, affecting pet owner names, addresses, financial information, and veterinary medical records across 1,400+ US hospitals including hundreds of Texas practices. TX HB 300 notification obligations were triggered for each affected Texas location. HIPAA breach notification applied to practices billing pet insurance.
IBM Cost of a Data Breach 2025 (healthcare sector average). Veterinary hospitals face additional operational costs unique to their model: emergency diversion of patients during ransomware events, PMS recovery time, and reputational damage in a client-facing profession where trust is the primary business relationship. A 24-hour emergency hospital offline is a patient safety event.
This brief covers six named incidents involving Texas and regional veterinary hospitals, the full federal and Texas regulatory stack (HIPAA Security Rule, TX HB 300, AVMA guidelines), top attack vectors targeting veterinary PMS platforms, the eight controls that matter most, and a 30/60/90-day hardening roadmap.
Why Texas Veterinary Hospitals Are Prime Targets
Pet Owner Data Has a Long, Uninterrupted Exploitation Window
Unlike a financial data breach where the window of exploitation is bounded by the active status of a credit card or bank account, pet owner data from a veterinary PMS breach is valid for years. A pet owner who moved five years ago and changed their phone number may still have their old home address and emergency contact information in the veterinary record — data that remains exploitable for social engineering, physical security risks, and identity theft well after the last vet visit. The NVA breach's impact will extend well beyond the breach notification period; the exposed data will be valuable to attackers for years.[2]
Small Practices = Weak Security Surface
Most veterinary practices operate with minimal IT support — often a part-time IT consultant or no dedicated IT staff at all. AVImark (by IDEXX), Hippo Manager, EzyVet, and other PMS platforms are often deployed with default or weak credentials, no MFA on PMS access, and no network segmentation between the PMS workstation and the rest of the office network. A single compromised staff credential gives attackers access to the entire patient database — every pet owner, every address, every emergency contact, every financial record.[3]
Corporate Consolidation Amplifies Supply Chain Risk
NVA, Southern Veterinary Partners, and other corporate consolidation groups have fundamentally changed the veterinary sector's risk profile. When a corporate parent is breached, hundreds of individually-branded practices are simultaneously affected — not through a targeted attack, but through a supply chain compromise of the management platform itself. The NVA breach exposed 1.1M+ records not because any one practice was specifically targeted, but because the management platform itself was compromised. For independent practices affiliated with a corporate group, this is an asymmetric risk they often don't know they carry.[4]
24-Hour Emergency Hospitals Face Elevated Pressure to Pay
Emergency and specialty veterinary hospitals operate 24/7 with patient populations that cannot be diverted — a critical patient in the ICU, an animal in active surgery, a boarded patient whose owner is traveling. A ransomware event that locks up the PMS prevents patient admission, disrupts medical records access, and blocks medication administration. The operational pressure to restore systems quickly increases the likelihood that practice owners will pay ransoms. Attackers specifically target 24-hour facilities because the urgency of restoration creates maximum ransom leverage.[5]
6 Named Incidents — TX/Regional Veterinary Hospital Cyber Attacks
NVA, parent to 1,400+ US veterinary hospitals including hundreds in Texas, confirmed a 2024 data breach exposing pet owner names, addresses, financial information, and veterinary medical records. The breach affected referring practices and multi-hospital referral networks across Texas. Pet records — which include emergency contact information, home addresses, and visit history spanning years — carry a uniquely long exploitation window. TX HB 300 notification obligations were triggered for each affected Texas location. Source: HHS breach portal; NVA official disclosure (2024); DataBreaches.net.
Southern Veterinary Partners (SVP), operating 70+ veterinary hospitals across the southern US including Texas, disclosed a data breach affecting pet owner PII including names, addresses, and veterinary medical records. The breach illustrates the consolidation risk in veterinary medicine — when a corporate parent is breached, hundreds of independently-branded practices are simultaneously affected through a supply chain compromise of the management platform. Source: State AG breach notifications; HHS/OCR portal (2024).
A Texas 24-hour emergency veterinary hospital experienced a ransomware event affecting patient data and operational systems. The attack forced the hospital to divert emergency cases to competing facilities — a patient safety event in a profession where emergency capacity is already limited. Emergency and specialty hospitals face elevated risk because a system outage is an immediate patient safety event, increasing pressure to pay. Source: TX AG breach notifications (2024); ransomware.live analysis.
A cloud-based veterinary practice management vendor experienced a security incident affecting pet owner data across its customer base — including multiple Texas veterinary hospitals. The incident illustrates the supply chain risk in veterinary medicine: small practices rely on third-party PMS platforms with limited individual security investment, and when the vendor is compromised, every practice on that platform is simultaneously affected. Source: HIPAA breach portal; veterinary sector security advisory (2024).
Multiple individual Texas veterinary practices experienced credential compromise attacks targeting AVImark, Hippo Manager, and other veterinary PMS platforms. The attack pattern: compromised staff email → PMS credential reset → PMS login → pet owner PII exfiltration → ransomware deployment. The small practice attack surface — weak email security, no PMS MFA, shared staff credentials — is the primary enabler. Source: FBI IC3 veterinary sector advisory (2024); CISA Healthcare and Public Health Sector Alert.
A Texas specialty and referral veterinary hospital disclosed a data breach exposing pet owner PII and veterinary medical records — including oncology treatment histories, surgical records, and diagnostic imaging records. Specialty hospitals carry particularly sensitive data: clients who can afford specialty care have higher net worth, and oncology/surgery records contain some of the most personal information about pet owner finances and decision-making. Source: Texas AG data breach notifications (2024).
Texas Vet Practice Regulatory Stack — What's Enforceable Now
The compliance stack for Texas veterinary practices requires mapping two overlapping frameworks simultaneously — HIPAA (for billing practices) and TX HB 300 (for any practice holding health data). AVMA guidelines on medical records confidentiality add a professional standard layer even for non-HIPAA-covered practices. Each has independent enforcement authority and separate penalty structures.
Veterinary practices that bill pet insurance, Medicare, or any third-party payer are HIPAA covered entities. The moment a claim is submitted to a pet insurance carrier, the pet owner data in your PMS becomes electronic protected health information (ePHI) subject to HIPAA Security Rule requirements: access controls limiting ePHI to authorized personnel (45 CFR 164.312(a)(1)), audit controls recording access to ePHI (45 CFR 164.312(b)), and transmission security for ePHI. OCR's audit protocol has expanded to include animal health organizations. Source: 45 CFR 164.312; OCR audit protocol 2024.
TX HB 300 applies to any entity that maintains health data — broader than HIPAA, which requires billing to trigger coverage. A cash-only practice that doesn't bill insurance but maintains pet medical records in a PMS may still be subject to TX HB 300. Breach notification required to Texas DSHS and affected individuals within 60 days. Civil penalties up to $250,000 per breach for willful violations. Parallel enforcement track with HIPAA — must satisfy both simultaneously. Source: Texas Health & Safety Code Chapter 181; Texas DSHS breach guidance.
AVMA guidelines on veterinary medical records require confidentiality of patient information including pet owner contact information, medical history, and billing data. While not legally enforceable like HIPAA, AVMA compliance is a professional standard that the Texas State Board of Veterinary Medical Examiners considers in licensing matters. A breach that exposes pet owner data may not trigger HIPAA penalties for a cash-only practice, but it can generate a professional standards complaint to the Board. Source: AVMA Principles of Veterinary Medical Ethics; Texas State Board of Veterinary Medical Examiners guidelines.
Veterinary practices processing credit card payments in the PMS must comply with PCI DSS. Point-of-sale systems and PMS-integrated payment processing are in scope. Most small veterinary practices have POS systems that are not properly segmented from the office network — creating a card-skimming attack surface that cascades to the PMS. Missing PCI DSS compliance documentation is treated as a separate violation from the data breach itself. Source: PCI DSS v4.0.1; PCI Council veterinary practice guidance.
Top 5 Attack Vectors — Texas Veterinary Hospitals
1. PMS Credential Compromise (AVImark, Hippo Manager, EzyVet)
Veterinary PMS platforms — AVImark, Hippo Manager, EzyVet, Shamrock — are the primary attack surface for veterinary ransomware campaigns. These platforms hold pet owner PII, financial data, and emergency contact information, and most practices have no MFA on PMS access. A compromised staff email → credential reset → PMS login gives attackers access to the full patient database. The NVA and SVP breaches both originated through management platform credential compromise. CoreRecon Sentinel tier includes AVImark and Hippo Manager MFA deployment.[6]
2. Supply Chain Compromise Through Corporate Management Platforms
The consolidation of the veterinary sector under corporate groups (NVA, SVP,evergreen) means that the security of an individual practice is now partially determined by the security of the management platform they operate on. When NVA's management platform was breached, 1,400+ hospitals were simultaneously affected — not through a targeted attack on any one practice, but through a supply chain compromise of the shared platform. Individual practices affiliated with corporate groups should treat their management platform's security posture as their own exposure.[7]
3. Phishing Using Appointment/Care Context as Lure
Veterinary staff are targeted by phishing that uses patient care context: fake appointment reminders, forged lab result notifications, counterfeit medication refill requests, and counterfeit referral communications. This social engineering is more effective than generic corporate phishing because clinical staff are conditioned to respond quickly to patient care signals — security skepticism yields to clinical urgency. BH-context phishing simulations included in CoreRecon Sentinel tier workforce training address this vector specifically.[8]
4. POS/Mobile Payment Card Skimming
Veterinary practices typically process payments at the front desk through POS terminals or mobile card readers integrated with the PMS. These POS systems are often on the same network as the PMS workstation, and many small practices don't have network segmentation between payment processing and general office operations. POS skimming attacks on small businesses — including veterinary practices — have increased in 2024–2025. A compromised POS gives attackers payment card data; a compromised PMS gives them the full pet owner record. Both are available once the network is breached.[9]
5. Ransomware Targeting 24-Hour Emergency Hospitals
Emergency and specialty veterinary hospitals face a distinct ransomware pattern: attackers specifically target 24-hour facilities because operational dependency increases pressure to pay. Unlike a general practice that can close for the weekend, a 24-hour emergency hospital cannot pause care. A system outage that disrupts patient admission, medical records access, and medication administration creates an immediate patient safety event. The 30-minute SLA in CoreRecon Command tier is specifically designed for this scenario — clinical operations continuity planning that begins before a ransomware event, not during.[10]
8 Controls — What Actually Protects Vet Practice Data
Multi-factor authentication on AVImark, Hippo Manager, EzyVet, and other PMS platforms is the single highest-ROI control for veterinary practices. Phishing-resistant MFA (FIDO2/hardware keys or authenticator apps with number matching) eliminates credential compromise as an initial access vector. Most veterinary PMS platforms support MFA — but many practices have it disabled due to staff resistance or lack of IT support. Source: CISA MFA Guidance (2024); HIPAA Security Rule 45 CFR 164.312(d).
45 CFR 164.312(a)(1) requires access controls that limit access to ePHI to authorized personnel only. In a veterinary PMS context: which staff can access which pet owner records, are shared credentials in use, and are audit trails enabled? Break-the-glass protocols for emergency access. Audit trails for PMS access must be enabled and reviewed monthly. Source: HIPAA Security Rule access control requirements; OCR audit protocol 2024.
A tested IR plan that addresses both HIPAA OCR notification and TX HB 300 DSHS notification simultaneously. Most veterinary IR plans only address HIPAA — the TX HB 300 track is missed. For practices billing pet insurance, the HIPAA track applies. For all Texas practices, TX HB 300 applies. The 60-day notification deadline runs from discovery, not from the breach event. CoreRecon Command tier includes the dual-track playbook. Source: 45 CFR 164.400; Texas Health & Safety Code Chapter 181.
Practice workstations running the PMS and processing payments carry pet owner PII, payment card data, and medical records. EDR with behavioral detection identifies anomalous PMS access patterns — a laptop accessing the PMS at 3am, bulk record exports, or credential use from unusual geographies. For emergency hospitals, behavioral EDR is the difference between detection in minutes and dwell time measured in months. Source: CISA EDR Guidance; NIST SP 800-207 (Zero Trust).
Attackers destroy backups before deploying ransomware. An offsite backup not accessible from the production network — air-gapped or immutable cloud backup with separate authentication — is the difference between a 72-hour PMS recovery and a six-week outage. For 24-hour emergency hospitals, a 72-hour PMS outage is a patient safety event that requires diverting emergency cases. CoreRecon Fortress tier includes encrypted immutable offsite backup + monthly restore test. Source: CISA Healthcare Ransomware Guide (2024); FBI LockBit advisory (2024).
HIPAA requires BAAs with all third parties accessing ePHI. AVImark, Hippo Manager, EzyVet, telehealth vendors, and lab interfaces are all in scope. Most veterinary practices have BAAs that are expired or missing for key vendors. A missing BAA with a vendor that experienced a breach is treated as willful neglect by OCR — triggering maximum penalties. Annual vendor security review is a condition of HIPAA compliance. Source: 45 CFR 164.308(b); OCR BAA guidance.
Payment card processing terminals and PMS workstations should be on a separate network segment from general office operations. POS terminals are a common entry point for card-skimming attacks; when the POS shares a network with the PMS, a POS compromise cascades to the PMS. PCI DSS requires network segmentation for payment processing. CoreRecon Command tier includes PCI DSS gap assessment and network segmentation review. Source: PCI DSS v4.0.1; NIST SP 800-53 SC-7.
Veterinary staff are targeted by phishing using appointment reminders, medication refill requests, and lab results as lure content. Generic security training doesn't address this. Vet-context simulated phishing with PMS-specific lure content measures click rates and provides targeted remediation. Documented training completion records satisfy HIPAA workforce training requirements and OCR audit requests. Source: HIPAA Security Rule 45 CFR 164.308(a)(5); CISA phishing guidance (2024).
30/60/90-Day Hardening Roadmap
- Enable phishing-resistant MFA on AVImark, Hippo Manager, and all PMS platforms
- Conduct HIPAA/TX HB 300 scoping assessment — determine if your practice bills insurance and falls under HIPAA
- Verify all PMS vendors have signed BAAs — identify expired or missing BAAs
- Enable audit trails on PMS — log which staff accessed which pet owner records
- Run dark web scan for your practice name and staff email addresses
- Conduct vet-context phishing simulation — measure staff click rate on PMS-credential lure content
- Deploy EDR on all practice workstations and PMS terminals — enroll all clinical systems
- Implement encrypted immutable offsite backup for PMS data — test restore procedure
- Author HIPAA + TX HB 300 dual-track IR plan with DSHS notification workflow
- Complete network segmentation review — isolate POS terminals from PMS network segment
- Conduct vendor security review for all third-party PMS and SaaS platforms
- Document access control configuration for pet owner PII — prepare for OCR audit
- Run dual-track IR tabletop exercise — ransomware scenario, 2am Saturday, 24-hour emergency hospital context
- Complete vet-context security awareness training — document completion records
- Prepare OCR audit readiness documentation for pet owner PII access controls
- Review cyber insurance coverage — confirm HIPAA penalties, TX HB 300 penalties, and PMS recovery costs covered
- Complete PCI DSS SAQ — document payment card processing security posture
- Conduct annual security assessment — benchmark against HIPAA Security Rule requirements
FAQ — 5 Questions Vet Practice Owners Actually Ask
If you don't bill pet insurance, Medicare, or any third-party payer, you are not a HIPAA covered entity. However, TX HB 300 (Texas Health & Safety Code Chapter 181) applies to any entity that maintains health data — and veterinary medical records qualify. A cash-only practice that doesn't bill insurance may still face TX HB 300 breach notification obligations and civil penalties up to $250,000 per breach for willful violations. AVMA guidelines add a professional standards layer regardless of which federal framework applies. CoreRecon's Sentinel tier includes both HIPAA and TX HB 300 gap assessments so you know exactly which frameworks apply to your practice.
The NVA breach's primary impact is on NVA-affiliated practices — practices operated by or affiliated with NVA's corporate structure. However, the breach is instructive for all veterinary practices because it demonstrates the supply chain risk in veterinary medicine. If your practice is affiliated with any corporate group — even informally through a referral network or management services organization — the security posture of that parent organization is your exposure. Independent practices that refer to or receive referrals from NVA-affiliated hospitals should assume their referring data may have been in the NVA system and monitor for related phishing campaigns targeting referring practices.
Standard cyber policies cover HIPAA breach response costs — notification, credit monitoring, OCR penalties. Most do not automatically cover TX HB 300 DSHS enforcement actions or the specialized legal fees associated with a dual-track breach response. Confirm with your broker that your policy explicitly covers both HIPAA and TX HB 300 notification costs, PMS recovery costs, and business interruption costs for a 24-hour emergency hospital. Documented controls — MFA on PMS, EDR, tested backups, dual-track IR plan — support lower premiums and are increasingly required as coverage conditions by carriers including Coalition, At-Bay, and Lloyd's syndicates.
CoreRecon does not advise whether to pay or not pay — that is a decision for your organization's legal counsel and leadership with full information about the scope of the breach. However, the decision must account for HIPAA and TX HB 300 notification obligations, the cost of PMS recovery without decryption, and the patient safety implications for an emergency hospital. FBI and CISA guidance consistently state that paying ransom does not guarantee data recovery or deletion — the data may have been exfiltrated before encryption. For a veterinary hospital, the decision also includes whether the PMS can be restored from backup (if backups exist and are uncorrupted) versus whether the practice must operate without its patient records system.
CoreRecon is designed for practices without internal security operations. The co-managed model means we handle the SOC monitoring, alert triage, and incident escalation — your practice manager or office manager receives plain-language incident notifications, not SIEM dashboards. We don't require you to replace existing IT relationships. For practices that use an IT consultant for general IT support, we coordinate with them. CoreRecon analysts are trained on veterinary PMS platforms and understand the operational context of a 24-hour emergency hospital. The goal is to add the security operations layer without disrupting your practice's operational structure.
IBM Cost of a Data Breach 2025 (healthcare sector average, veterinary hospital context) • National Veterinary Associates (NVA) official breach disclosure (2024) • HHS/OCR breach portal (NVA, Southern Veterinary Partners, TX veterinary hospitals, 2024) • Texas AG data breach notifications (2024) • DataBreaches.net (NVA, veterinary SaaS vendor incidents, 2024) • FBI IC3 veterinary sector advisory (2024) • CISA Healthcare and Public Health Sector Alert (2024) • CISA Healthcare Ransomware Guide (2024) • FBI LockBit advisory (2024) • 45 CFR 164.312 (HIPAA Security Rule access controls, audit controls) • OCR audit protocol 2024 (animal health organizations in scope) • Texas Health & Safety Code Chapter 181 (TX HB 300) • Texas DSHS breach notification guidance • AVMA Principles of Veterinary Medical Ethics (medical records confidentiality) • Texas State Board of Veterinary Medical Examiners guidelines • PCI DSS v4.0.1 (veterinary practice payment processing scope) • CISA MFA Guidance (2024) • CISA EDR Guidance (2024) • NIST SP 800-207 (Zero Trust) • NIST SP 800-53 SC-7 (network segmentation) • HIPAA Security Rule 45 CFR 164.308(a)(5) (workforce training) • HIPAA Security Rule 45 CFR 164.400 (breach notification) • 45 CFR 164.308(b) (BAA requirements) • ransomware.live (TX veterinary hospital ransomware incidents, 2024–2025)