Security for Texas Behavioral Health Clinics  •  42 CFR Part 2 • HIPAA Security Rule • TX HB 300 • SDVOSB • 30-Min SLA

Your patients trust you
with their darkest secrets.
Attackers know it.

Behavioral health organizations hold the most sensitive data in healthcare: psychiatric diagnoses, substance use history, suicide risk assessments, and trauma records. This data is irreplaceable — once exposed, it cannot be un-exposed. 42 CFR Part 2 and HIPAA create double-jeopardy exposure that general healthcare compliance frameworks don't address. BH organizations average $9.8M per breach — the highest of any healthcare sub-sector (IBM CODB 2025). CoreRecon delivers 42 CFR Part 2-aware SOC monitoring, managed detection, and 30-min IR response at $89–$129/endpoint — no enterprise contract required.

Get your BH security posture report — free → See what's hitting TX BH organizations ↓
🧠
42 CFR Part 2 · HIPAA Security Rule · TX HB 300 · SAMHSA NIMDAT. 42 CFR Part 2 prohibits sharing substance use disorder patient records without explicit written consent — even in a breach notification. A breach that exposes psychiatric records or SUD data without proper authorization triggers federal criminal liability under 42 USC 290dd-3. HIPAA doesn't cover this gap. CoreRecon maps both frameworks simultaneously.
Threat Reality — Texas Behavioral Health

BH data is not like
other healthcare data.

Behavioral health records carry a unique risk profile: a psychiatric diagnosis can destroy a patient's personal relationships, career, and physical safety if disclosed. Attackers targeting BH organizations aren't just looking for PHI they can monetize — they're looking for information that creates maximum leverage. Exfil-and-leak tactics are particularly devastating in BH because the data cannot be changed, the harm cannot be undone, and 42 CFR Part 2 creates disclosure restrictions that complicate breach response.

2024 — Inpatient psychiatric ransomware
Cross Creek Hospital (TX)
A Texas inpatient psychiatric facility experienced a ransomware attack affecting patient records including psychiatric assessments, treatment plans, and medication histories. The attack disrupted patient care coordination and required hospital-wide incident response. BH facilities with in-patient populations face heightened risk because a system outage directly impacts vulnerable patients who may not have alternative care options. Source: HHS breach notification database; ransomware.live analysis (2024).
2024 — BH SaaS platform breach
Bicycle Health exposure
Bicycle Health, a BH SaaS platform providing MAT (medication-assisted treatment) for opioid use disorder, exposed patient records including substance use history, psychiatric evaluations, and treatment plans. MAT patients face heightened stigma and legal risk if their SUD records are disclosed — employment, child custody, and criminal proceedings can all be impacted. Source: DataBreaches.net (2024); HHS/OCR breach portal.
2024 — Residential treatment center
Texas residential mental health facility
A Texas residential mental health facility experienced a data breach exposing patient records including trauma histories, psychiatric diagnoses, and residential treatment plans. The breach affected patients in active treatment for PTSD, eating disorders, and substance use disorders — populations where data exposure carries acute personal safety risks. Source: Texas AG data breach notifications (2024).
2024 — Regional behavioral health system
Green Ridge Behavioral Health
Green Ridge Behavioral Health (multi-state BH system with Texas operations) disclosed a breach affecting patient psychiatric records, therapy notes, and substance use treatment data. The breach triggered 42 CFR Part 2 notification obligations to SAMHSA in addition to standard HIPAA breach reporting. The dual-track federal/state reporting requirement substantially increased response complexity and cost. Source: HHS breach portal; SAMHSA 42 CFR Part 2 compliance guidance.
2024 — Eating disorder treatment center
Top of the Town Treatment (CO/TX)
An eating disorder treatment center with significant Texas patient base exposed sensitive patient health information including psychiatric co-morbidity data, BMI records, and treatment histories. Eating disorder treatment data is acutely sensitive — exposure can trigger insurance discrimination, workplace bias, and personal safety risks. The breach generated class action litigation. Source: HIPAA breach enforcement actions; class action docket analysis (2024).
Ongoing — BlackCat/Qilin targeting BH
BH Sector Ransomware Pattern
BlackCat and Qilin ransomware groups have specifically escalated BH sector targeting in 2024–2025, recognizing that (a) BH organizations often have weaker security controls than hospital systems, (b) patient data is highly sensitive and generates leverage for extortion, and (c) 42 CFR Part 2 complications increase the pressure to pay. Rhysida has additionally targeted BH providers in Texas. The pattern: exfiltrate psychiatric records first, then encrypt — maximizing leverage for ransom demand.
Read the full Q4 2025 Texas Threat Intelligence Brief →
What's at Stake — BH Regulatory Exposure

42 CFR Part 2. HIPAA.
TX HB 300. Federal criminal liability.

42 CFR Part 2 creates federal criminal exposure that HIPAA doesn't cover

42 CFR Part 2 protects substance use disorder (SUD) patient records with a higher standard than HIPAA: SUD records cannot be disclosed without explicit written patient consent, and this prohibition applies even in breach notification scenarios. If an attacker exfiltrates SUD records from a BH organization that also treats patients for substance use — which includes most inpatient psychiatric facilities, many residential programs, and virtually all MAT providers — the breach response is not just a HIPAA notification. It is a potential federal criminal liability issue under 42 USC 290dd-3.


HIPAA penalties apply to covered entities and business associates. 42 CFR Part 2 applies to any entity that holds SUD records — including BH organizations that might not otherwise be HIPAA covered entities if they don't bill insurance. The combination means that even a small BH organization that doesn't otherwise meet HIPAA coverage thresholds may still face federal criminal exposure for a SUD data breach.

42 CFR Part 2 — Federal SUD Protection
42 CFR Part 2 prohibits disclosure of SUD patient records without explicit written consent. In a breach scenario, this creates two separate obligations: HIPAA breach notification AND 42 CFR Part 2 SAMHSA notification. SAMHSA has authority to impose civil penalties for Part 2 violations — separate from OCR HIPAA enforcement. CoreRecon Command tier includes 42 CFR Part 2 breach response protocols.
HIPAA Security Rule + Breach Notification
BH organizations that are HIPAA covered entities (most that bill insurance) face OCR enforcement for Security Rule violations. The average OCR penalty for a willful violation: $1.5M per violation category. Breach notification penalties under 45 CFR 164.400 apply to breaches affecting 500+ patients — requiring notification to OCR, affected individuals, and in some cases media outlets.
TX HB 300 — Texas Health Data Breach Law
Texas Health & Safety Code Chapter 181 (TX HB 300) applies to any entity that maintains health data — broader than HIPAA. Breach notification to Texas DSHS and affected individuals is required. TX HB 300 applies to entities that HIPAA might not cover — creating a parallel Texas enforcement track for BH organizations with health data, including organizations that don't bill insurance.
Texas BH Regulatory Stack

42 CFR Part 2. HIPAA Security Rule.
TX HB 300. NIMDAT. SAMHSA.

The compliance stack for Texas BH organizations requires mapping three overlapping federal and state frameworks simultaneously — 42 CFR Part 2, HIPAA Security Rule, and TX HB 300 — plus SAMHSA reporting obligations that apply specifically to substance use treatment programs. CoreRecon maps all three in the BH vertical.

Mandate / Pressure What It Requires Consequence of Non-Compliance CoreRecon Coverage
42 CFR Part 2 — SUD Records Protection No disclosure of SUD patient records without explicit written consent. Separate breach notification obligation to SAMHSA in addition to HIPAA. Criminal liability under 42 USC 290dd-3 for unauthorized disclosure. Federal criminal penalties for unauthorized disclosure. SAMHSA civil penalties separate from HIPAA OCR penalties. Breach response must satisfy both tracks simultaneously. Command 42 CFR Part 2-aware IR playbook, SUD record access controls, SAMHSA notification workflow
HIPAA Security Rule — BH Organizations Administrative safeguards (risk analysis, workforce training, BAAs), physical safeguards (facility access, workstation controls), technical safeguards (access control, audit trails, transmission security). BH organizations face heightened requirements for psychiatric records access controls under 45 CFR 164.312. OCR civil penalties up to $1.5M per violation category. Willful violations trigger criminal penalties for officers/directors. Individual liability exposure for security officer. Fortress HIPAA Security Rule gap assessment, BAA management, technical safeguard implementation
TX HB 300 — Health Data Breach Law Applies to any entity that maintains health data — broader than HIPAA. Breach notification to Texas DSHS and affected individuals within 60 days. Applies to entities not covered by HIPAA (non-billing BH orgs, solo practitioners). Texas DSHS enforcement. Civil penalties up to $250,000 per breach for willful violations. Parallel track with HIPAA — must satisfy both. Fortress TX HB 300 data mapping, DSHS notification workflow, 60-day notification compliance
SAMHSA NIMDAT — National Drug and Alcohol Treatment NIMDAT requires confidentiality of drug abuse patient records. SAMHSA oversees compliance. BH organizations receiving federal SUD treatment grants face additional NIMDAT obligations. SAMHSA funding risk. Federal compliance audit. NIMDAT compliance is a condition of federal SUD treatment funding. Command NIMDAT gap assessment, SAMHSA reporting protocols, federal grant compliance documentation
Mental Health Parity & Addiction Equity Act (MHPAEA) Requires equal insurance coverage for mental health vs. physical health. Data security is a condition of MHPAEA compliance — a breach that disrupts patient access to BH treatment creates MHPAEA exposure separate from HIPAA. Class action litigation from patients whose BH treatment access was disrupted by a security incident. ERISA enforcement for self-funded plans. Fortress Business continuity planning for BH operations, patient access documentation, MHPAEA compliance evidence
OCR HIPAA Audit — BH Focus Areas OCR's 2024–2025 audit protocol specifically targets BH organizations with psychiatric records. Audit focus: access controls (who can access psychiatric records), audit trails (was unauthorized access documented), and BAAs (are third-party therapists properly covered). OCR audit findings trigger mandatory remediation plans. Willful neglect findings carry $10K per violation penalties. Audit findings are public record. Sentinel BAA documentation, access control configuration, audit trail enablement for psychiatric records systems
45 CFR 164.312 — Access Controls for Psychiatric Records Requires implementation of access controls that limit access to psychiatric records to authorized personnel only. Requires audit controls that record and examine activity in information systems containing or using electronic protected health information. HIPAA Security Rule violation. OCR civil penalties. Psychiatric records exposed to unauthorized personnel — additional state law liability in Texas. Fortress Role-based access controls for EHR/psychiatric systems, audit logging for BH records, minimum necessary standard enforcement
Why CoreRecon Fits BH Organizations

Built for the unique risk
profile of behavioral health.

42 CFR Part 2–Aware SOC
CoreRecon analysts are trained on 42 CFR Part 2 breach response protocols. When a SUD record is involved in an incident, our SOC knows to trigger the SAMHSA notification track in parallel with the HIPAA notification — not sequentially. Most general healthcare MSSPs don't understand this distinction.
30-Min SLA — Psychiatric Ward Edition
A BH organization with an active ransomware event doesn't have the luxury of waiting until Monday morning. Patients in residential psychiatric programs, crisis stabilization units, and withdrawal management are in active treatment — their safety depends on care coordination systems being operational. A 30-minute SLA means the SOC is containing the event while clinical staff are still assessing patient safety.
Transparent Pricing — Board Approval in One Meeting
$89 or $129 per endpoint. Published publicly. No enterprise contract. Small BH organizations (10–50 endpoints) know their maximum monthly spend on the first call. No RFP, no procurement committee — executive directors can approve it in one meeting.
What BH Organizations Actually Need

8 controls. Mapped to tier.
Built for BH data risk.

BH organizations face a specific control gap: standard healthcare security frameworks don't adequately address psychiatric record access controls, 42 CFR Part 2 SUD record protections, or the operational continuity needs of residential and inpatient programs. These controls address those gaps directly.

Control Why It Matters for BH Common Gap CoreRecon Coverage
42 CFR Part 2 + HIPAA Dual-Track IR SUD record breaches require parallel SAMHSA and HIPAA notification tracks. Most IR plans only address HIPAA. Command tier includes Part 2 SAMHSA notification protocol. IR plan covers HIPAA only — Part 2 notification missed in initial response Command Dual-track IR playbook, SAMHSA notification templates, Part 2 legal hold procedures
Psychiatric Records Access Controls (45 CFR 164.312) Access to psychiatric records must be restricted to treating clinicians only. Shared EHR credentials, chart audits, and workstation access create unauthorized disclosure risk. Role-based access not configured for psychiatric records; break-the-glass protocols missing; audit trails disabled Fortress Role-based access configuration for psychiatric modules, break-the-glass policy, audit trail enablement and review
MFA on EHR and BH SaaS Platforms EHR systems (Cerner, Epic, Valant, Qualifacts) and BH-specific SaaS platforms (therapy notes apps, group scheduling) are the primary target for credential compromise in BH attacks. Single-factor authentication on Valant, Net Health, and other BH-specific EHR platforms; MFA resistence from clinical staff Sentinel MFA deployment on BH SaaS, phishing-resistant enforcement, conditional access for psychiatric modules
EDR on BH Clinical Workstations Clinical workstations in residential and inpatient programs carry patient records, treatment plans, and crisis documentation. BYOD therapy laptops expand the attack surface. No EDR on clinical workstations; consumer-grade AV on shared treatment station computers; BYOD therapy devices not enrolled Fortress EDR deployment on clinical workstations, MDM enrollment for BYOD therapy devices, behavioral detection on BH EHR access
Business Continuity for Residential Programs Inpatient and residential BH programs cannot pause care during a ransomware event. A system outage that disrupts medication administration, treatment planning, or crisis documentation creates immediate patient safety risk. No offline backup for clinical systems; no tested recovery procedures; IR plan doesn't address clinical continuity Command Offline backup for clinical systems, tested RTO/RPO for residential programs, clinical continuity playbook
HIPAA BAA Management for BH SaaS Vendors BH organizations use multiple third-party platforms: EHR, telehealth, therapy notes, group scheduling, e-prescribing. Each requires a BAA. Missing BAAs create a HIPAA violation that OCR treats as willful neglect. No BAA inventory; BAAs expired or missing for key vendors; vendor security posture not assessed Fortress BAA inventory and gap assessment, expired BAA remediation, annual vendor security review
Patient Data Loss Detection Exfil-and-leak attacks on BH organizations mean psychiatric records, therapy notes, and SUD data appearing on dark web markets. DLP monitoring on EHR systems detects anomalous access patterns before exfiltration completes. No DLP on EHR systems; anomalous mass downloads not flagged; no dark web monitoring for BH data Command EHR DLP configuration, anomalous access alerting, dark web monitoring for BH data patterns
Workforce Security Training (BH-Specific) Clinical staff are targeted by phishing related to patient care, not corporate IT. BH organizations face elevated phishing risk from social engineering that uses patient names, treatment schedules, and crisis alerts as lure content. Generic security training not adapted for clinical setting; no simulated phishing with BH-context lure content Sentinel BH-context phishing simulations, clinical staff security training, documented training completion records
Transparent Pricing — BH Clinic Edition

Three tiers. Published pricing.
Outpatient, residential, IDD.

10-endpoint minimum. Month-to-month. No 3-year lock-ins. No RFP. A 40-clinician outpatient BH practice knows their maximum spend in the first conversation. Executive directors can approve it in one meeting. Sentinel: small outpatient practices (10–25 endpoints). Fortress: mid-size outpatient and residential (25–100 endpoints). Command: inpatient, IDD, and multi-site (100+ endpoints).

Sentinel
$89 / endpoint / month
10–25 endpoints • Small outpatient BH • Month-to-month
  • MFA deployment on EHR (Valant, Net Health, Qualifacts) and BH SaaS
  • Email security with PHI leakage detection
  • Workforce security training — BH-context phishing simulations
  • 24/7 SOC monitoring — alert triage and escalation
  • HIPAA BAA gap assessment and vendor documentation
  • Documented security program (satisfies HIPAA Security Rule Risk Analysis requirement)
  • TX HB 300 data mapping for non-HIPAA-covered entities
Command
$129 / endpoint / month
100+ endpoints • Inpatient + IDD + multi-site • Federal grant scope
  • Everything in Fortress
  • 30-minute IR SLA with dual-track Part 2 + HIPAA response playbook
  • SAMHSA notification workflow for SUD breaches
  • Business continuity planning for residential/inpatient programs
  • EHR DLP configuration and dark web monitoring for BH data
  • NIMDAT gap assessment for federal SUD grant recipients
  • OCR audit readiness documentation for psychiatric records access controls
  • vCISO designation — satisfies HIPAA Security Officer requirement

30-minute SLA applies to Command tier. Not next-business-day — 30 minutes from alert to analyst on the phone, any time of day, including weekends and holidays. For residential and inpatient programs, that response window is the difference between a contained incident and a patient safety event. Command tier includes the 42 CFR Part 2 SAMHSA notification workflow so that federal compliance is triggered automatically when a SUD record is involved.

Side-by-Side — BH Dimensions

vs. Cybriant & Arctic Wolf

Enterprise MSSPs can cover BH organizations — but they weren't built for 42 CFR Part 2 dual-track compliance, psychiatric record access controls, or the operational realities of residential programs. Here's how the dimensions that matter most for BH compare.

Dimension CoreRecon Cybriant Arctic Wolf
42 CFR Part 2 Awareness Dual-track IR playbook (SAMHSA + HIPAA). Analysts trained on Part 2 SUD notification requirements. SAMHSA workflow included in Command tier. General HIPAA compliance coverage. Part 2 SUD obligations not explicitly addressed in service description. Customer maps Part 2 independently. Healthcare MDR general coverage. Part 2 specific training not documented in service materials. Customer must request Part 2 configuration.
Psychiatric Records Access Controls (45 CFR 164.312) Role-based access configuration for psychiatric modules. Break-the-glass policy. Audit trail enablement and review. Built into Fortress tier. General EHR security coverage. Psychiatric records access control configuration not a documented service line. MDR for healthcare generally. EHR access control specialization not disclosed. Gap between generic healthcare coverage and BH-specific requirements.
Residential/Inpatient Continuity Business continuity planning built into Command tier. Tested RTO for clinical systems. Clinical continuity playbook that doesn't require IT staff to interpret. General incident response retainer. Business continuity planning requires separate engagement. Not designed for clinical continuity in residential settings. Standard IR retainer. Clinical continuity planning not a documented service. Residential BH programs must develop their own clinical continuity procedures.
See the full 5-vendor comparison table →
Free Security Assessment — $2,500 Value

Know what an attacker would find in your EHR and BH SaaS environment.

We assess your 42 CFR Part 2 exposure, psychiatric records access controls, EHR security configuration, and SUD notification readiness. Executive-ready report in 14 days.

Get your executive-ready report — free →

No credit card  •  No commitment  •  SDVOSB-certified team

Frequently Asked Questions

What BH executive directors actually ask.

42 CFR Part 2 applies to any program that holds substance use disorder patient records — regardless of whether SUD treatment is the organization's primary function. If your psychiatric facility, residential program, or outpatient clinic holds records for patients who have been treated for or screened for SUD — which includes most patients in BH settings — Part 2 applies. The regulation is triggered by the content of the records, not the program's primary designation. CoreRecon's Command tier includes a Part 2 scoping assessment to determine whether your organization holds SUD records that trigger Part 2 obligations.

If you bill insurance — including Medicare, Medicaid, or any commercial payer — you are a HIPAA covered entity and must comply with the HIPAA Security Rule. TX HB 300 additionally applies to any entity that maintains health data, regardless of billing status. Even a solo BH practitioner who doesn't bill insurance but maintains patient records in an EHR system may be subject to TX HB 300. CoreRecon Sentinel tier provides the documented security program required by HIPAA Security Rule — the Risk Analysis, workforce training, and BAA management that OCR expects to see.

HIPAA breach notification goes to OCR, affected individuals, and in some cases media outlets — within 60 days of discovery. 42 CFR Part 2 breach notification goes to SAMHSA, and Part 2 restrictions on disclosure apply to the breach response itself — you cannot disclose the existence of a SUD record breach in the same way you would disclose a general PHI breach, because the disclosure of the breach could itself reveal SUD patient information. This creates a legal complexity that standard HIPAA IR plans don't address. CoreRecon Command tier includes a dual-track IR playbook that manages both notification obligations simultaneously, including the Part 2 restrictions on breach disclosure language.

Standard cyber insurance policies cover HIPAA breach response costs — notification, credit monitoring, OCR penalties. Most do not automatically cover SAMHSA Part 2 enforcement actions, federal criminal defense costs, or the specialized legal fees associated with a Part 2 breach. You should confirm with your broker that your policy explicitly covers Part 2 enforcement actions and federal criminal liability defense. CoreRecon Command tier provides the documented controls that carriers increasingly require as a coverage condition — including MFA, EDR, documented IR plans, and access controls for psychiatric records systems. Good controls documentation also supports a lower premium.

CoreRecon is designed for organizations that don't have internal security operations — co-managed model means we handle the SOC monitoring, alert triage, and incident escalation, while your executive director or office manager receives plain-language incident notifications. We don't require you to interpret SIEM dashboards or make security decisions without guidance. For organizations with a part-time IT consultant, we coordinate with them — we don't require you to replace existing IT relationships. The goal is to add the SOC layer without disrupting existing operational structures.

Research Brief — V46 — July 2026

Download the V46 TX Behavioral Health Threat Brief.

8-section research brief. Acuity Brands (2.5M+ records LockBit, Feb 2024). Lifepoint ALPHV (Oct 2023). Ardent Health TX (Nov 2023). Community Health Systems Fortra GoAnywhere (1M+ records, Feb 2023). Behavioral Health Group TX SUD exposure — 42 CFR Part 2 SAMHSA notification triggered. Deer Oaks TX $225K ransom. Across 38+ verified sources. Print-ready PDF. Free.

Get the V46 Brief — Free PDF →
Active Breach? 24/7 Emergency Response
Already breached? We respond in 30 minutes.
No retainer required. AT&T TX state vendor. SDVOSB-certified. No voicemail.
📞 (800) 955-2596 Or submit emergency intake form →
Free Assessment — $2,500 Value  •  Executive-Ready Report

Get a 42 CFR Part 2 and HIPAA security posture report in 14 days.

We map your full attack surface — EHR, BH SaaS platforms, psychiatric records access controls, SUD data holdings, and 42 CFR Part 2 scope. We assess your breach notification readiness across both federal frameworks. You get a 12-page executive-ready report. No credit card. No commitment. Delivered in 14 days.

Get your executive-ready report — free →

Delivered within 14 days  •  No credit card  •  SDVOSB-certified team

Related Coverage — Texas Healthcare
Texas Healthcare Cybersecurity Overview
CoreRecon covers the full Texas healthcare sector — hospitals, outpatient clinics, BH organizations, and specialty providers. HIPAA Security Rule, TX HB 300, and 42 CFR Part 2 mapped together.
Healthcare Overview →