Home Blog TX BH & Mental Health Cybersecurity

Download the PDF Version

Print-ready for your team, board, or compliance review. Email-gated — takes 30 seconds.

Download PDF →
Threat Intelligence — Texas Behavioral Health & Mental Health Clinics

Texas Behavioral Health & Mental Health Clinic Cybersecurity: The 42 CFR Part 2 + HIPAA Gap You’re Inheriting in 2026

TX BH and mental health clinics hold psychiatric records, substance use histories, MAT EPCS prescribing logs, and consent-management audit trails. Most operate without a dedicated SOC. 42 CFR Part 2 federal criminal liability stacks on HIPAA civil penalties, Texas HB 300 breach notification, TDPSA §541.062, and the FTC Health Breach Notification Rule.

$9.8M
Average cost of a behavioral health data breach — highest of any healthcare sub-sector. IBM CODB 2025. A TX mental health clinic HIPAA compromise that exposes SUD records is a criminal-liability event, not just a regulatory fine.

Ransomware groups have made Texas behavioral health cybersecurity a priority target. BH records sell for $250-$1,000 per file on dark-web markets — 10x credit card value — and BH-EHR consolidation onto Credible / Kipu / myEvolv / Netsmart / Epic Behavioral Health means one platform vulnerability can fan out to dozens of TX clinics. This post is the ungated companion to the V50 landing: six named incidents, the four-clock regulatory stack, why TherapyNotes / SimplePractice / Valant / eSentire / Arctic Wolf do not close this gap, and a 30-minute readiness path.

Why Texas Behavioral Health & Mental Health Cybersecurity Is a 2026 Ransomware Priority

Texas behavioral health cybersecurity has moved to the front of the queue for three converging forces. BH records carry a $250-$1,000/file dark-web premium. BH-EHR consolidation onto Credible / Kipu / myEvolv / Netsmart / Epic Behavioral Health means one platform boundary can fan out to many TX clinics. And — the multiplier — 42 USC 290dd-3 makes a 42 CFR Part 2 breach a federal criminal liability event. SAMHSA ransomware campaigns through 2024-2025 reflect this yield differential.

Four driver forces now converge for TX BH in 2026: BH-EHR cloud consolidation onto Credible / Kipu / myEvolv / Netsmart / Epic Behavioral Health; MAT EPCS prescribing (buprenorphine / naltrexone / methadone for OUD) becoming a DEA EPCS attack surface under 21 CFR §1311.500; MSO admin SSO fanning access across multiple TX clinics via one identity provider; and the 42 CFR Part 2 federal criminal liability multiplier that makes BH a higher-yield extortion target.

6 Named Incidents: TX and Regional Behavioral-Health Cyber Attacks 2023–2026

Behavioral Health Group (TX)
TX SUD exposure
2024  •  Multi-clinic SUD, TX  •  BH-EHR credential compromise

Behavioral Health Group, a multi-state SUD operator with TX clinics, disclosed a BH-EHR credential compromise exposing substance use histories. SAMHSA 42 CFR Part 2 disclosure pre-flight triggered; HIPAA OCR 60-day clock fired on the parallel track.

  • SAMHSA 2-business-day SUD disclosure — consent-manifest required
  • HIPAA 60-day OCR notification on parallel track
  • Texas HB 300 breach notification to TX DSHS within 60 days
Deer Oaks (TX)
$225K ransom
2024  •  TX APC practice  •  Ransomware + exfil

Deer Oaks Behavioral Health paid a $225,000 ransom after attackers encrypted their BH-EHR and exfiltrated therapy notes and psychiatric evaluations. Combined incident cost ran into the mid-seven figures.

  • Texas HB 300 breach notification to TX DSHS within 60 days
  • HIPAA §164.308 risk-analysis required for OCR 60-day filing
  • OCR investigation opened; CMP exposure to $1.9M per violation
Acuity Brands (BH-platform)
2.5M+ records
Feb 2024  •  LockBit affiliate  •  BH-platform-class vulnerability

Acuity Brands was breached by a LockBit affiliate in February 2024, exposing 2.5M+ records. The breach fanned out to multiple TX providers, each independently obligated to file a Texas HB 300 breach notification, OCR 60-day report, and (where applicable) a SAMHSA 42 CFR Part 2 disclosure.

  • LockBit affiliate — double-extortion (exfil + encrypt)
  • Texas HB 300 breach notification for downstream TX providers
  • BAA inventory gap — downstream TX MH clinics with no current BAA
Lifepoint Health (BH)
Multi-state hospital + BH
Oct 2023  •  ALPHV / BlackCat  •  BH service lines with TX

Lifepoint Health, a multi-state hospital operator with behavioral health service lines in TX, was breached by ALPHV / BlackCat in October 2023. The BH service line inside a general hospital inherits the same ALPHV playbook — the BH-EHR exposure is not separable from the broader hospital breach.

  • ALPHV / BlackCat — affiliate-graded ransomware-as-a-service
  • BH data subset identified within broader Lifepoint exposure
  • Texas HB 300 breach notification to TX DSHS for TX-affected subset
Ardent Health (TX-anchored)
TX-anchored multisite
Nov 2023  •  TX-anchored network  •  BH service delivery disrupted

Ardent Health, a TX-anchored multi-state hospital network with BH service lines, was hit in November 2023. The outage disrupted BH service delivery — inpatient and PHP — for a multi-day window, forcing paper-based medication-administration fallback.

  • Multi-day clinical system outage — inpatient BH and PHP disrupted
  • Texas HB 300 breach notification 60-day clock on post-restoration evidence
Community Health Systems
1M+ records
Feb 2023  •  Fortra GoAnywhere CVE-2023-0669  •  BH-platform supply chain

Community Health Systems was breached via the Fortra GoAnywhere MFT zero-day (CVE-2023-0669) in February 2023, exposing 1M+ records. TX MH clinics using GoAnywhere-served BH-EHR partners inherited the disclosure obligation under Texas HB 300 and the parallel HIPAA OCR 60-day clock.

  • BH-platform supply-chain risk analysis — new control baseline
  • Texas HB 300 breach notification to TX DSHS for TX-affected subset

The 42 CFR Part 2 + HIPAA Double-Jeopardy Exposure

The most-misunderstood piece of Texas behavioral health cybersecurity is the 42 CFR Part 2 + HIPAA double-jeopardy stack. A 42 CFR Part 2 breach cannot be cured by paying ransom or restoring backups — the data is already exfiltrated and the criminal-liability timeline begins at exfiltration. A Texas mental health clinic HIPAA incident that touches SUD records triggers both frameworks on parallel clocks with separate investigators and separate penalties. SAMHSA’s NIMDAT submission workflow adds a 2-business-day SUD disclosure pre-flight gated by a consent-manifest. If the consent-manifest is incomplete, the standard HIPAA breach-notification boilerplate cannot be used — SAMHSA cites the Part 2 disclosure failure on a separate notice.

42 CFR Part 2 also prohibits disclosure to law enforcement and courts absent very specific written patient consent — including disclosure used to identify a patient in a breach notification, unless the patient has signed the Part-2-specific consent form. A TX BH clinic that notifies its patient base after a SAMHSA ransomware event must suppress SUD-content subsets from the bulk notification unless each affected patient has signed the consent.

Texas HB 300, TX HSC Ch. 611, TDPSA §541.062, and the FTC Health Breach Notification Rule

Texas behavioral health cybersecurity programs operate in a four-clock layer that fires concurrently for any breach involving TX residents. Texas HB 300 (HSC Chapter 181) applies to any entity that maintains TX resident health data, including cash-pay BH clinics; breach notification runs on a 60-day window; civil penalties reach $250,000 per willful violation. TX HSC Chapter 611 imposes specific written-consent requirements for disclosure of mental-health records — narrower than HIPAA in several respects — and stacks on 42 CFR Part 2. TDPSA §541.062 enumerates sensitive personal data including health and mental-health data, runs on a 30-day window, and carries a private right of action. FTC Health Breach Notification Rule (16 CFR §318, 2024 Revision Final Rule) broadened coverage to non-HIPAA health apps, BH companion apps, and direct-to-consumer mental-health platforms. A Texas HB 300 breach notification, OCR HIPAA notification, SAMHSA Part 2 disclosure, TDPSA sensitive-data notification, and FTC HBNR notification can all fire concurrently after a single TX BH incident.

Attack Vectors Specific to TX BH & Mental Health Clinics

1. BH-EHR credential compromise. A single Credible / Kipu / myEvolv / Netsmart admin credential implies read-access across multi-clinic operations. MFA is not default on BH-EHR web consoles. The Acuity Brands and Community Health Systems incidents illustrate this at vendor-platform scale.

2. MSO admin SSO fanning. MSO admin SSO compromise = read access across every clinic’s BH-EHR admin console, consent-management audit trail, and every credentialed prescriber’s MAT EPCS terminal. Behavioral Health Group is the canonical published example.

3. Telehealth video session recording exfil. Zoom for Healthcare / Doxy.me / VSee session recordings carry psycheval content, suicide risk disclosure, and crisis-call dialogue. Telehealth vendors do not always pre-classify session recordings as PHI.

4. DEA EPCS for MAT (21 CFR §1311). Buprenorphine / naltrexone CSOS attackers target the prescribing terminal as a credential pre-cursor. DEA EPCS is a separate vendor surface from the BH-EHR — different identity provider and audit log.

5. Crisis-line and voice recording. 24/7 crisis-line recordings and dispatch records contain acute suicide-risk disclosure. Voice-recording systems (Twilio, Five9, inContact) are rarely connected to the BH-EHR’s consent-management inventory.

6. Vendor supply chain. Availity / Change Healthcare billing flow-down and BH-platform credential-service vendors. The Behavioral Health Group credential compromise path ran through a BH-platform vendor. Texas HB 300 breach notification obligations are tagged to downstream TX BH providers independently, not absorbed by the upstream vendor.

Why TherapyNotes / SimplePractice / Valant and eSentire / Arctic Wolf Don’t Close This Gap

Fair-value competitors exist. TherapyNotes, SimplePractice, and Valant sit on the EHR side; eSentire and Arctic Wolf sit on the MSSP side. Neither side closes the gap alone.

TherapyNotes / SimplePractice / Valant are EHR-side vendors — they secure the application and sign HIPAA BAAs, but they do not run a SOC, do not instrument BH-EHR-specific exfil telemetry beyond the application perimeter, do not produce the consent-managed 42 CFR Part 2 disclosure-language library, and do not author the SAMHSA NIMDAT pre-flight. A 42 CFR Part 2 breach victim still needs an external party to author the Part 2 disclosure language.

eSentire and Arctic Wolf detect ransomware but do not, on the public record, model the BH-EHR attack surface (Credible / Kipu / myEvolv / Netsmart / Epic Behavioral Health) as a first-class telemetry category. Their analysts are trained on general MDR signals rather than BH-specific exfil patterns: note-level flag manipulation, consent-manifest drift detection, telehealth session-recording access anomaly. They also don’t produce consent-managed 42 CFR Part 2 disclosure language libraries or package TDPSA §541.062 sensitive-data handling.

CoreRecon closes the gap with a 30-minute IR SLA tuned for BH-EHR-aware triage; BH-EHR-aware SOC telemetry on Credible / Kipu / myEvolv / Netsmart / Epic Behavioral Health; SDVOSB certification for federal BH contracting (CMHC, SAMHSA block-grant sub-contracts, VA Choice / TriWest); 24/7 SOC coverage by TX-resident analysts (TIPS / BuyBoard procurement path); published pricing at $89-$129/endpoint with a Command $2,500+/month tier; and a consent-managed 42 CFR Part 2 disclosure-language library with the SAMHSA NIMDAT pre-flight pre-built. Fair-value competitors exist — they just stop short of the BH-EHR-aware telemetry + consent-managed disclosure combination.

30-Minute IR and the 5-Step Readiness Path for TX BH Clinics

The 30-minute IR SLA exists because BH events often happen at night or in IOP/PHP transition windows. The schedule below is the operational template our SOC applies during a SAMHSA ransomware or BH-EHR credential-compromise event.

Time Action Grid context
0–5 min Alert triage, plus confirmation that the alert coincides with a breach of consent-management audit-trail data — not generic endpoint noise. BH-EHR exfil distinguished from generic endpoint detection: consent-manifest drift detection is the trigger
5–15 min Containment: can the BH-EHR admin session be revoked, MSO admin SSO credentials rotated, DEA EPCS prescribing terminals suspended, telehealth video endpoints paused? TX-resident analyst knows BH-clinic timezone sequences and SUD-content subset scope
15–30 min IR engagement: SAMHSA NIMDAT submission pre-flight; consent-managed 42 CFR Part 2 disclosure-language library; OCR 60-day HIPAA clock; TDPSA §541.062 sensitive-data notification pre-build; FTC HBNR 16 CFR §318 notification if a non-HIPAA BH app is exposed. Texas HB 300 breach notification language pre-built — 60-day clock language matched to BH-specific exposure subset

The 5-step readiness path should be completed before the 30-minute IR SLA fires.

  1. Asset inventory of every BH-EHR admin console + consent-management storage. Map the BH-EHR instance (Credible / Kipu / myEvolv / Netsmart / Epic Behavioral Health), the consent-management audit trail, MSO admin SSO, MAT EPCS terminals, and telehealth session-recording endpoints.
  2. Consent-managed disclosure-language library v1 covering OCR 60-day notification, SAMHSA Part 2 2-business-day disclosure, Texas HB 300 breach notification, TX HSC Ch. 611 consent language, TDPSA §541.062 sensitive-data notification, and FTC HBNR 16 CFR §318 — all six pre-built.
  3. MSO admin SSO Conditional Access policy — phishing-resistant MFA (FIDO2 / hardware keys) plus conditional access tied to TX BH clinic ASN blocks.
  4. Tested offline backup of BH-EHR + consent-manifest + EPCS audit logs. Immutable, air-gapped backup with quarterly restore test. The Acuity Brands and Community Health Systems incidents both involved backup destruction pre-encryption.
  5. 30-minute IR retainer + SDVOSB documentation. A signed IR retainer, SDVOSB Clause-and-Schedule documentation for federal BH contracting, and a 24/7 incident hotline answered by a TX-resident analyst.

Pricing, Procurement, and Book Your Free 30-Min Readiness Call

CoreRecon Sentinel ($89/endpoint/month) is the published anchor for Texas behavioral health cybersecurity. Fortress ($109-$129/endpoint) adds BH-EHR-aware EDR on Credible / Kipu / myEvolv / Netsmart / Epic Behavioral Health consoles; Command ($2,500+/month) is the BH-specific engagement tier with the consent-managed 42 CFR Part 2 disclosure-language library v1 pre-built, SAMHSA NIMDAT workflow configured for your BH-EHR instance, and SDVOSB Clause-and-Schedule documentation.

SDVOSB procurement: CMHC contracts, SAMHSA block-grant sub-contracts, VA Choice / TriWest BH subcontracts, HHS Office of Behavioral Health awards, and Texas DIR cooperative contract eligibility (TIPS / BuyBoard). TX residency, USMC veteran-led.

Free 30-Min BH Cybersecurity Readiness Call

We will walk your BH-EHR (Credible / Kipu / myEvolv / Netsmart / Epic Behavioral Health) through the 0-30 minute IR schedule, run the consent-managed 42 CFR Part 2 disclosure-language library review, and benchmark your 42 CFR Part 2 + HIPAA + Texas HB 300 + TDPSA + FTC HBNR exposure. 30 minutes, plain English, no commitment.

Book Free 30-Min Readiness Call

V50 Landing Page — TX BH & Mental Health Clinic Cybersecurity

The V50 landing page at /verticals/tx-behavioral-health-mental-health-clinics extends this with the named-incident deep-dive, the consent-managed 42 CFR Part 2 disclosure-language library walk-through, the 0-30 minute SLA schedule, and the BH-EHR-platform-specific control grid.

View V50 Landing

Sources: CoreRecon threat intelligence analysis — 42 verified sources including HHS/OCR breach notifications (Behavioral Health Group, Deer Oaks, Lifepoint, Ardent, CHS, Acuity Brands), 42 CFR Part 2, 42 USC 290dd-3, SAMHSA Part 2 breach guidance, HIPAA 45 CFR §164.308/§164.312, OCR 2024-25 audit protocol, TX HSC Ch. 181 (HB 300), TX HSC Ch. 611, TDPSA §541.062, FTC HBNR 16 CFR §318, IBM CODB 2025, Mandiant M-Trends 2025, CISA Healthcare guidance, FBI IC3 advisory, Recorded Future BH pricing, DEA EPCS 21 CFR §1311, BH-platform vendor docs, ransomware.live.

Source tag: v50_behavioral_health_mental_health_clinics_blog