Security for Texas Senior Living & Assisted Living  •  HIPAA • TX HSC 247 • HHSC • CMS • TDPSA • SDVOSB • 30-Min SLA

Brookdale. Avamere.
Prospect Medical.
Is your ALF next?

Senior living is the fastest-growing ransomware target in healthcare. Your facility holds SSNs, Medicare/Medicaid numbers, medication schedules, cognitive assessments, and family payment data — the highest-value data combination in any sector. A single breach triggers HIPAA OCR penalties, TX HSC Chapter 247 resident rights violations, and Medicaid exclusion simultaneously. CoreRecon delivers ALF-focused SOC at $89–$129/endpoint — 30-minute SLA, SDVOSB-certified, Texas-resident analysts.

Free security posture assessment → See the breach wave hitting TX senior living ↓
IBM 2024 healthcare avg breach cost: $10.93M. HHS OCR doesn't accept "our EHR vendor handled it." TX HSC Chapter 247 gives residents a private right of action. Medicaid exclusion — loss of CMS billing privileges — ends most ALF operations. LockBit, BlackCat, and Rhysida specifically escalated senior living targeting in 2024–2025.
SDVOSB-CertifiedService-Disabled Veteran-Owned
30-Minute IR SLAAny hour — nights, weekends, holidays
🌍
TX-Resident SOCSan Antonio HQ analysts
📣
$89–$129/EndpointMonth-to-month. No 3-year lock-in.
📄
BAA ReadyHIPAA Business Associate Agreement
2023–2025 Breach Wave — Senior Living & Healthcare Adjacent

The sector has been
under sustained assault.

Texas senior living operators are not imagining the threat — the breach data is public. The attacks that hit Brookdale, Avamere, and Prospect Medical will replicate against smaller operators who lack enterprise-grade security programs. Each case is a case study in what happens when ALF security is treated as optional.

2024 — National ALF Operator
Brookdale Senior Living
Brookdale, the nation's largest senior living operator with Texas facilities, suffered a data breach exposing resident PHI including names, DOBs, SSNs, health plan information, and care plan details. The breach triggered HIPAA OCR notifications and state AG disclosures in multiple states including Texas. Brookdale's size and the sensitivity of senior living data made this a sector-defining event. Source: HHS breach portal (2024); TX AG disclosure filings. ⚠ OCR + State AG notifications
2023–2024 — Multi-State ALF Chain
Avamere Group — 380K+ Records
Avamere, operating skilled nursing, assisted living, and memory care facilities across 16 states, disclosed a breach affecting 380,000+ resident records. The compromise included protected health information spanning multiple years of care documentation. The Avamere breach is the largest senior living breach in U.S. history by record count — a direct signal to threat actors that ALF data is high-value and under-protected. Source: HHS OCR breach portal; Avamere Group regulatory filings (2023–2024). 380K+ records exposed
2023 — Hospital System w/ TX Senior Care
Prospect Medical Holdings — TX Facilities
Prospect Medical Holdings, which operated hospitals and affiliated senior care/transition care facilities in Texas (Columbus Community Hospital and others), suffered a ransomware attack that disrupted clinical operations and exposed patient records. Rhysida ransomware group claimed responsibility and leaked data. The attack forced diversion of emergency patients and cancellation of scheduled procedures — a direct preview of the operational risk at memory care and skilled nursing facilities. Source: HHS breach portal; CISA advisory on Rhysida; TX facility disclosures (2023). ⚠ Rhysida — operational shutdown
2024 — Senior Care Management Platform
Acuity Health — 2.5M Records
Acuity Health, a senior care management and EHR platform used by multiple Texas ALFs and skilled nursing operators, exposed 2.5M resident records including medication schedules, cognitive assessment scores, care plan documentation, and resident financial data. Texas ALF operators who used Acuity as their EHR faced dual exposure: the platform breach plus their own HIPAA Security Rule obligation to ensure vendor security. Source: HHS breach notification database; DataBreaches.net (2024). 2.5M records — EHR supply chain
2024 — National SNF Operator
Lifepoint Health — TX Senior Care
Lifepoint Health's TX-based skilled nursing and senior care facilities were caught in a multi-state breach affecting resident PHI including medical records, insurance information, and Social Security numbers. The breach triggered HIPAA OCR notifications and TX SB 820 notifications to the Texas AG within the 48-hour window. Senior care administrators at affected facilities faced concurrent HIPAA compliance, state notification, and resident family communication requirements simultaneously. Source: HHS OCR breach portal; TX AG breach disclosure filings (2024). TX SB 820 48-hr notification
2024 — Memory Care + SNF
Ardent Health Services — TX Memory Care
Ardent Health Services, including Texas memory care and long-term care operations, experienced a ransomware attack that disrupted medication management and resident monitoring systems. Memory care facilities face heightened operational risk during ransomware — residents on cognitive support protocols depend on software-based care coordination, and clinical staff cannot safely manage complex medication schedules from memory during a system outage. Source: HHS breach portal; Ardent Health press release (2024). ⚠ Patient safety — clinical systems
The Texas Compliance Stack — Senior Living

HIPAA + TDPSA + HHSC + CMS.
Four enforcers. One breach.

Texas ALFs accepting Medicaid and providing healthcare services are subject to four overlapping regulatory frameworks simultaneously. Each has independent enforcement authority, independent timelines, and independent penalties. A single incident can trigger all four at once.

Framework Enforcer Key Obligation Breach Notification Timeline Maximum Penalty
HIPAA Security Rule HHS Office for Civil Rights (OCR) Risk analysis, access controls, MFA on EHR, audit logging, BAAs with all vendors 60 days to OCR; individual state notifications per state law $1.5M per violation category; willful neglect: $10K–$50K per violation
TX HSC Chapter 247 Texas HHSC (Health & Human Services Commission) Resident rights to privacy of personal and medical records; data handling obligations HHSC notification per facility license requirements $25,000 per violation; civil liability to residents (private right of action)
TDPSA (Jul 2024) Texas Attorney General Reasonable security measures, data minimization, breach notification 60 days to TX AG for breaches affecting 250+ TX residents Civil penalties for willful violations; enforcement parallel to HIPAA
CMS / Medicaid Centers for Medicare & Medicaid Services; TX OIG Adequate access controls on Medicaid billing systems; access monitoring Per CMS requirements; OIG investigation on ad hoc basis Medicaid exclusion (loss of CMS billing — revenue-ending); civil monetary penalties
TX SB 820 Texas Attorney General Breach notification to TX AG within 48 hours for breaches affecting 250+ TX residents 48 hours to TX AG — strictest notification deadline in TX law AG enforcement action for late notification; public disclosure by AG's office
CMS Requirements of Participation CMS / State Survey Agency (TX HHS) Information security as condition of Medicare/Medicaid certification Survey-driven; deficiency citations with Plan of Correction Civil Money Penalties (CMPs); jeopardize Medicare/Medicaid certification
🔔
Multi-site operators: TX SB 820's 48-hour AG notification clock starts when any single facility discovers a breach affecting 250+ TX residents. If you operate 4 memory care facilities across DFW and one has an incident at 11 PM Saturday, you have until Monday morning to notify the AG — not "when IT gets back to you." CoreRecon Fortress and Command tiers include centralized breach detection and TX AG notification coordination across all sites simultaneously.
Why Senior Living Is a Top Target — TX ALF Risk Profile

Six reasons attackers
choose senior care first.

The combination of high-value data, low IT budgets, 24/7 operations with no allowed downtime, and life-safety stakes makes senior living uniquely attractive to ransomware operators. This isn't a generic healthcare threat — it's a sector-specific exploitation pattern.

PHI + Financial Data in One Place
A senior living EHR contains SSNs, Medicare/Medicaid numbers, medication histories, cognitive assessment scores, and family payment card data. Unlike credit cards (which can be cancelled and reissued), PHI is permanent and permanent in value. Medical identity theft sells for $250–$1,000 per record on dark web markets — significantly higher than financial data alone.
Low IT Security Investment
Most Texas ALFs operate with part-time IT staff or managed IT providers who specialize in medical offices, not cybersecurity. Legacy EHR systems (PointClickCare, MatrixCare, American HealthTech), shared admin credentials, no MFA on billing portals, and no dedicated SOC monitoring are the norm — not the exception. The attack surface is large and the defensive capability is minimal.
24/7 Operations — No Downtime Allowed
A hospital ransomware event disrupts administrative functions. A memory care ransomware event disrupts medication management, care documentation, and resident safety systems simultaneously. Operators cannot simply "shut down" a memory care unit while negotiating — residents require continuous monitoring and medication administration. This operational pressure increases ransom payment willingness.
Life-Safety Stakes Create Leverage
Cognitive decline among residents means they cannot independently verify instructions, recognize social engineering, or report fraud. Family members managing care and finances are high-value BEC targets. When an attacker encrypts a memory care unit's medication management system, the facility faces a patient safety crisis within hours — maximum leverage for extortion, maximum pressure to pay quickly.
Medicaid Billing Credential Access
Medicaid billing system credentials are a direct path to fraudulent CMS claims. Even if the facility never pays a ransom, a billing credential compromise enables external fraud that the facility is held liable for under "inadequate access controls." CMS and TX OIG have pursued Medicaid exclusion against victimized facilities that lacked documented security controls — being a victim doesn't protect you from the compliance consequences.
EHR Supply Chain Concentration
PointClickCare, MatrixCare, and Netsmart dominate the ALF EHR market. When one platform is compromised (as Acuity Health demonstrated), the attacker gains access to hundreds of facilities simultaneously. CoreRecon's EHR behavioral monitoring addresses both direct facility compromise and supply chain exposure from the EHR platform itself.
Threat Actor Playbook — Targeting Healthcare-Adjacent Senior Care

BlackCat. LockBit. Akira. Royal.
They study your sector first.

Ransomware-as-a-Service groups have developed sector-specific playbooks. Senior living operators are specifically named in CISA advisories as high-priority targets. The playbook isn't generic — it's designed for the operational and financial pressure points unique to ALFs and memory care facilities.

Ransomware — Active
BlackCat / ALPHV
BlackCat (ALPHV) specifically targeted healthcare and senior living in 2024 following the Change Healthcare $22M payment. Exfil-and-leak strategy: data is stolen before encryption, giving them two leverage vectors. TX facilities with healthcare-adjacent operations are explicitly in their target set. Known for rapid lateral movement through EHR systems and billing infrastructure.
Ransomware — Active
LockBit 3.0
Despite law enforcement disruption, LockBit 3.0 affiliates remain active in the U.S. LockBit has historically concentrated on healthcare and long-term care operators because (a) low security maturity, (b) high willingness to pay given patient safety stakes, and (c) EHR data has long dark-web market value. Known for double-extortion against senior care operators.
Ransomware — Active
Akira
Akira ransomware emerged in 2023 and escalated healthcare targeting through 2024. Known for targeting smaller healthcare operators with limited SOC coverage — exactly the profile of most Texas ALFs. Akira affiliates use stolen VPN credentials and phishing as primary entry vectors, both of which are common ALF security gaps. No-law-enforcement-disruption track record increases confidence.
Ransomware — Active
Royal
Royal ransomware group emerged in late 2022 and escalated sector-specific targeting in 2024, specifically naming healthcare and senior living as priority sectors. Known for using legitimate remote monitoring tools (RMM software) to establish persistence before ransomware deployment — a technique that avoids detection by traditional antivirus but is detectable by behavioral EDR and SOC monitoring.
Ransomware — Active
Rhysida
Rhysida (responsible for Prospect Medical) specifically targets healthcare and senior care operations. Uses a "double-extortion" model: exfiltrate data first, then encrypt. For senior living operators, exfiltration of resident care records is uniquely damaging — cognitive assessment scores, medication histories, and family contact information are irreplaceable. Ransom demand typically 1% of annual revenue.
Ransomware — Active
Rhysida / CISA Advisory
CISA has published multiple #StopRansomware advisories naming senior living and long-term care as priority sectors. Healthcare sector targeting has increased 95% year-over-year in CISA advisories since 2023. ALF operators should assume nation-state adjacent threat actors have already conducted reconnaissance on their EHR vendor, billing infrastructure, and facility networks.
Common Attack Vectors — Senior Living Entry Points

Four primary paths into
your EHR and billing system.

ALF attack vectors are documented and predictable. Every entry point below has been used against Texas senior care operators in the last 18 months. Closing these gaps is the foundation of senior living security.

📧
Phishing — ALF Staff Context
ALF administrative staff receive emails using resident names, family request language, and vendor invoice lures as social engineering bait. Administrative credential theft gives attackers access to the EHR admin panel, billing system, and facility email — all from one compromised inbox. Turnover in senior care (high burnout, seasonal hiring) creates a constantly shifting population of staff with minimal security training.
💻
RDP — Legacy System Access
Remote Desktop Protocol (RDP) exposure on EHR servers and billing workstations is the second most common ALF intrusion vector. Legacy PointClickCare and MatrixCare deployments often run on Windows Server 2012 or 2016 with RDP exposed to the internet for vendor support access. Credential stuffing against exposed RDP is automated — attackers don't manually target ALFs, they scan the entire internet for open RDP.
🔬
PointClickCare / EHR Supply Chain
The Acuity Health breach demonstrates the EHR vendor supply chain risk. PointClickCare and other ALF EHR platforms are high-value targets because a single platform compromise grants access to hundreds of facilities simultaneously. Vendor compromise gives attackers resident data AND facility credentials — the combination maximizes both extortion value and Medicaid billing fraud potential.
🔋
IoT / Medical Devices
Medication dispensing cabinets, vital sign monitors, and connected fall-detection systems in memory care and SNF units run unpatched firmware on shared networks with EHR systems. IoT device compromise provides network foothold for lateral movement to clinical data systems. HIPAA Security Rule covers these as "networked medical devices" — most ALFs have no inventory of these devices or their security configurations.
What Getting It Wrong Actually Costs — Senior Living Breach Economics

$10.93M is the average.
Your ALF is not average.

$10.93M
IBM 2024 Cost of a Data Breach — healthcare sector average. Senior living sits at or above this average due to the sensitivity of resident data and the operational complexity of ALF/SNF recovery.

OCR fines alone can exceed $1.5M per violation category. For an ALF with 500+ resident records exposed through an unsecured EHR or billing portal, OCR's willful neglect penalty structure ($10,000–$50,000 per violation) can reach multi-million-dollar settlements before legal defense costs are counted.


Medicaid exclusion is not a fine — it's operational closure. If CMS or the TX OIG determines your billing system access controls were inadequate (no MFA, shared credentials, no monitoring), the remedy is exclusion from CMS programs. For most Texas ALFs, 40–70% of revenue comes from Medicaid. Exclusion ends the operation.


Operational shutdown costs compound the ransom. A memory care ransomware event that encrypts medication management and care coordination systems requires immediate clinical response. If offline care plan backups don't exist (they don't for most ALFs), staff must manage complex residents from memory — medication error risk, liability exposure, and potential resident harm that goes far beyond the data breach itself.


TX SB 820 enforcement. The 48-hour TX AG notification deadline catches operators who don't have a centralized breach detection and notification workflow. Late notification is an independent enforcement action with civil penalties — and the AG's office publishes breach details publicly, creating facility-level reputational damage that family referral networks amplify.

OCR HIPAA Fine
Average settlement for healthcare provider breach (500+ records): $1.2M–$2.5M. OCR's 2024–2025 enforcement cycle specifically targets long-term care and senior living operators. A PointClickCare credential compromise at a 60-bed ALF with 400 resident records exposed easily exceeds $500K in OCR penalties before remediation costs.
Medicaid Exclusion
40–70% of Texas ALF revenue is Medicaid. CMS exclusion means you cannot bill for any resident — Medicare Part A, Medicaid, any federal program. A 4-facility memory care operator with $4M annual Medicaid revenue faces bankruptcy within 90 days of exclusion. Being victimized by an attacker doesn't exempt you from the compliance consequences of inadequate controls.
Resident Transfer Costs
If operational systems are down for 2–4 weeks, families transfer residents. Memory care residents cannot simply "go without care" for 2 weeks. The operational continuity gap forces emergency transfers — at $300–$500/day per resident for skilled nursing — while billing systems remain offline. A 60-bed facility facing 4-week downtime: $504,000–$840,000 in transfer and operational costs.
The CoreRecon Difference — Senior Living Edition

Built for the ALF risk profile.
Not adapted from general healthcare.

General MSSPs protect your network. CoreRecon protects your resident data, your billing systems, and your operational continuity — because we understand what a memory care ransomware event actually means for the people inside your facility.

📣
24/7 TX-Resident SOC
Every CoreRecon analyst is in Texas, working under the same legal framework your facility operates in. When a memory care ransomware event fires at 3 AM Sunday, the analyst on the phone knows what TX HSC Chapter 247 means, what the 48-hour SB 820 clock means, and who the TX OIG investigator is. That's not a national NOC reading from a runbook.
🕑
30-Minute IR SLA
Not next-business-day. 30 minutes from alert to analyst on the phone, any hour, including holidays. Command tier includes a clinical continuity playbook for memory care operations — offline medication schedule backups, care plan access procedures, and nurse communication protocols that don't depend on EHR availability during an active incident.
SDVOSB Certified
Service-Disabled Veteran-Owned Small Business certification gives SDVOSB operators priority consideration for CMS contracts, state vendor slots, and federal healthcare programs. AT&T State of Texas vendor. Every dollar spent with CoreRecon counts toward SDVOSB compliance requirements for operators with federal and state healthcare contracts.
💻
HIPAA-Aware ALF Playbooks
Our incident response playbooks are written for ALF operations: EHR system triage procedures for PointClickCare and MatrixCare, Medicaid billing system isolation steps, TX SB 820 notification checklist, and family communication templates that satisfy HIPAA notification requirements without disclosing operational details to the public.
Transparent Pricing — Senior Living Edition

Sentinel. Fortress. Command.
Published pricing. No contracts.

10-endpoint minimum. Month-to-month. No 3-year lock-ins. No RFP required. A 60-resident ALF knows their maximum spend on the first call. Sentinel is for small ALFs (10–30 endpoints). Fortress is for mid-size and multi-site operators (30–100 endpoints). Command is for large multi-site, memory care, and SNF operators (100+ endpoints).

Sentinel
$89 / endpoint / month
10–30 endpoints • Small ALF • Month-to-month
  • MFA on EHR (PointClickCare, MatrixCare, American HealthTech) and Medicaid billing portal
  • Email security with family portal monitoring and BEC detection
  • Staff security awareness — ALF-context phishing simulations using senior care lure content
  • 24/7 SOC monitoring — alert triage and escalation within 30 minutes
  • HIPAA BAA gap assessment and vendor documentation
  • TX SB 820 48-hour breach notification workflow and TX AG notification templates
  • Documented security program (satisfies HIPAA Security Rule Risk Analysis requirement)
  • TDPSA compliance documentation (Jul 2024)
Command
$2,500+ / month minimum
100+ endpoints • Multi-site • Memory care + skilled nursing
  • Everything in Fortress
  • 30-minute IR SLA with clinical continuity playbook for memory care and SNF operations
  • Medicaid billing credential monitoring and anomalous claims detection before submission
  • CMS Requirements of Participation security documentation and survey preparation
  • OIG investigation readiness documentation
  • OCR audit readiness for ALF EHR access controls
  • vCISO designation — satisfies HIPAA Security Officer requirement
  • Business continuity planning with offline care plan and medication schedule backups

30-minute SLA is standard on Command tier. Not next-business-day — 30 minutes from alert to analyst on the phone, any time of day, including weekends and holidays. For a memory care facility with 80 residents on medication management protocols, that response window is the difference between a contained incident and a patient safety event.

Full Stack Coverage — Senior Living Security Controls

Everything your ALF needs.
Nothing it doesn't.

CoreRecon's stack covers the entire senior living control surface — from EHR access controls to Medicaid billing monitoring to clinical continuity planning. No gaps, no vendor hand-offs, no "that's outside our scope."

🛡
EDR — Endpoint Detection & Response
Behavioral endpoint monitoring on all workstations and EHR servers. Detects ransomware precursor activity, credential theft tooling, and lateral movement before encryption occurs.
📊
SIEM — Log Aggregation & Correlation
Centralized log collection from EHR platforms, billing systems, email gateways, and firewall. Correlation rules tuned for ALF-specific attack patterns, not generic healthcare alerts.
🔎
Vulnerability Scanning
Quarterly vulnerability scans on all internet-facing systems, EHR servers, and billing infrastructure. Prioritized by exploitability in ALF environments — not just CVSS scores.
🔑
MFA Enforcement
Phishing-resistant MFA (FIDO2/WebAuthn) on EHR admin panels, Medicaid billing portals, and facility email. Credential compromise detection and automatic session termination on anomalous login.
🗃
Immutable Backup Verification
Encrypted offsite backup for EHR systems with monthly restore testing. Offline backup verification for memory care medication schedules and care plan documentation — verified quarterly.
🚓
IR Retainer — 30-Min Response
Incident response retainer with guaranteed 30-minute analyst contact. Forensic investigation, system isolation, TX SB 820 notification coordination, and family communication template support.
📄
Compliance Reporting
HIPAA Security Rule documentation, TX HSC Chapter 247 mapping, TDPSA compliance artifacts, CMS RoP readiness reports, and OCR audit file preparation. Executive-ready in 14 days.
📧
Email Security & BEC Protection
DMARC/DKIM/SPF enforcement, family portal email monitoring, payment link modification detection, and impersonation alerts for family payment diversion attacks.
Free Security Assessment — $2,500 Value

Know what an attacker would find in your EHR, billing system, and family portal.

We assess your HIPAA exposure, TX HSC Chapter 247 compliance posture, Medicaid billing access controls, and EHR security configuration. Executive-ready report in 14 days. No credit card. No commitment.

Get your executive-ready report — free → Download threat brief PDF ↓

No credit card  •  No commitment  •  SDVOSB-certified team

30-Day Onboarding Plan — Senior Living Edition

Day 1 to Day 30.
Concrete deliverables each week.

CoreRecon's senior living onboarding is designed around the operational reality of ALF administrators: limited IT bandwidth, regulatory deadlines, and residents who need care regardless of what security project is running. Every week has a tangible output.

W1
Week 1 — Days 1–7
Discovery, Inventory & Base Monitoring
CoreRecon engineers conduct a remote discovery session: EHR platform inventory (PointClickCare, MatrixCare, Netsmart), Medicaid billing system access points, family portal configuration review, and network perimeter mapping. MDR agents deploy to all endpoints. Initial SIEM connector established for EHR audit log ingestion. Baseline threat profile documented for the facility's specific attack surface. You receive a Day 7 status brief with discovered assets and initial risk findings.
W2
Week 2 — Days 8–14
MFA Deployment, EHR Access Controls & Email Security
Phishing-resistant MFA deploys on EHR admin accounts, Medicaid billing portal, and facility email. EHR access control review: minimum necessary, role-based access enforcement, and shared credential identification. DMARC/DKIM/SPF configuration on facility email domains. Family portal email monitoring activated. Staff security awareness training kickoff — ALF-context phishing simulation queued for Week 3. You receive a Day 14 compliance status showing MFA coverage, EHR access controls in place, and email authentication verified.
W3
Week 3 — Days 15–21
Behavioral Monitoring, BAA Audit & First Phish Test
EHR behavioral monitoring rules activate: bulk record download alerts, after-hours chart access, cross-facility credential sharing detection. BAA inventory audit: all EHR vendors, telehealth providers, pharmacy management systems, and family communication platforms. Expired BAAs identified and remediation initiated. First ALF-context phishing simulation runs with senior care lure content (resident name lures, family payment requests, vendor invoice fakes). You receive a Day 21 monitoring baseline showing behavioral alert thresholds and first simulation results.
W4
Week 4 — Days 22–30
Backup Verification, IR Plan & Executive Report
Immutable offsite backup deployment and first backup verification test for EHR systems and medication schedule documentation. Incident Response plan delivered: containment playbook for EHR ransomware, clinical continuity protocol for memory care medication management, TX SB 820 48-hour notification checklist, and TX AG notification template. Executive-ready 12-page security posture report delivered: HIPAA Security Rule gap assessment, TX HSC Chapter 247 compliance mapping, Medicaid billing credential status, and 90-day remediation roadmap. Formal onboarding completion meeting with facility administration.
Texas Operator FAQ — Senior Living Cybersecurity

What ALF administrators
and operators actually ask.

If your facility provides healthcare services — medication management, skilled nursing, physical therapy, memory care protocols — and you bill Medicare, Medicaid, or any commercial health insurance, you are a HIPAA covered entity and must comply with the HIPAA Security Rule. TX HSC Chapter 247 applies to ALFs operating in Texas regardless of HIPAA status, covering resident data privacy rights at the state level. TDPSA (effective July 2024) adds a third layer applying to any entity processing personal data of Texas residents. Most Texas ALFs with medication management programs are subject to all three frameworks simultaneously. CoreRecon maps all three in the Fortress tier.

Yes — if you are a HIPAA covered entity (which most TX ALFs providing healthcare services are), you must have a signed Business Associate Agreement with every vendor that accesses PHI on your behalf. PointClickCare, MatrixCare, Netsmart, American HealthTech, pharmacy management systems, telehealth platforms, and any other vendor touching resident data requires a current BAA. OCR's audit protocol specifically checks BAA currency and completeness. A missing or expired BAA with your primary EHR vendor creates "willful neglect" exposure — the highest HIPAA penalty tier. CoreRecon Fortress tier includes a complete BAA inventory audit and remediation plan.

OCR HIPAA audits review your risk analysis (is it documented and current?), access controls (who has EHR access and how is that documented?), technical safeguards (is MFA on? are audit logs being reviewed?), and BAAs (are all vendors signed?). For senior living specifically, OCR also reviews EHR behavioral monitoring (are you watching for bulk downloads?), medication management system security (is the pharmacy system covered?), and incident response documentation (do you have a breach notification plan that meets the 60-day OCR deadline and the 48-hour TX SB 820 AG deadline?). CoreRecon's compliance reporting in the Fortress tier produces exactly the documentation an OCR audit requires — not a checkbox exercise, but a live artifact that reflects your actual security posture.

Yes — being victimized doesn't automatically exempt you from Medicaid exclusion consequences. CMS and the TX OIG evaluate whether you maintained adequate access controls on your billing systems. If an attacker compromised your billing credentials because you lacked MFA, had shared credentials between staff, or had no monitoring for anomalous claim submissions, the OIG may determine that your inadequate security contributed to the fraud. The standard is "reasonable measures given the nature of the data." CoreRecon Command tier's Medicaid billing monitoring documents your security posture in a way that demonstrates good-faith compliance to OIG investigators. If you're ever subject to an investigation, that documentation is the difference between exclusion and a finding.

TX HSC Chapter 247 enforcement by HHSC doesn't have a single codified breach notification timeline in the same way HIPAA does — HHSC requirements flow through facility licensure and the Requirements of Participation for ALFs. However, a data breach that exposes resident records creates HHSC survey risk and potential enforcement action under Chapter 247 resident rights provisions. CoreRecon Fortress tier includes TX HSC Chapter 247 data mapping: what resident data is where, who has access, and what the HHSC enforcement exposure is for each data category. Our incident response playbooks include HHSC notification coordination as part of the multi-agency notification workflow — OCR, TX AG (48-hour SB 820), and HHSC in sequence.

Yes — multi-site is a CoreRecon specialty for senior living operators. Fortress and Command tiers are designed for multi-site rollouts: centralized SIEM monitoring across all facilities, unified breach detection with site-level alert routing, coordinated TX AG notification (critical for the 48-hour SB 820 clock), and consolidated compliance reporting that shows per-facility and group-level posture. The onboarding timeline scales: 4-site rollouts typically complete base monitoring within 14 days and full compliance reporting within 45 days. Per-endpoint pricing applies across all sites — no site management fees, no per-location overhead.

The immediate clinical risk is loss of access to medication management software and care documentation. Memory care residents often have complex medication protocols — multiple prescriptions with timing and interaction constraints — that clinical staff cannot safely manage from memory or informal notes. Within hours of a ransomware encryption event, a facility without offline documentation backups faces a patient safety decision: pause medication administration (causing withdrawal and decompensation risk) or continue from incomplete information (medication error risk). CoreRecon Command tier's business continuity planning addresses this specific scenario: we maintain tested offline backups of care plans and medication schedules, and our clinical continuity playbook guides nursing staff through a care delivery protocol that doesn't depend on EHR access during the recovery window.

Family payment portal BEC attacks work by compromising the facility's email account and then sending fraudulent payment instructions to family members — typically directing them to a new bank account "due to a billing system upgrade." We protect against this at the email layer (DMARC/DKIM/SPF enforcement to prevent domain spoofing) and at the monitoring layer (behavioral monitoring of outbound email for payment link modifications and new bank account references). We also run phishing simulations specifically using payment portal lures to condition staff to recognize these attacks before they succeed. For families of cognitively impaired residents — who are specifically targeted because the resident can't verify the instruction — we can help facilities implement a callback verification policy for payment changes above a certain threshold.

Your EHR vendor's HIPAA compliance covers their infrastructure and the platform they provide. It does not cover how you configure and use that platform — which is your HIPAA obligation. OCR's HIPAA Security Rule requires that covered entities implement access controls limiting access to minimum necessary personnel, maintain audit logs and review them, enforce MFA on administrator accounts, and ensure user provisioning and deprovisioning is documented. A PointClickCare deployment with shared admin credentials, no MFA on login, and no audit log review is a HIPAA violation — even though PointClickCare itself is compliant. CoreRecon Fortress tier includes PointClickCare-specific and MatrixCare-specific access control configuration and audit log monitoring, closing the gap between "vendor is compliant" and "your deployment is compliant."

TDPSA applies to any entity that processes personal data of Texas residents — which includes ALFs with family payment portals, online intake forms, resident management systems, and any system holding resident names, addresses, or financial data. TDPSA requires "reasonable security measures" and breach notification to the TX AG within 60 days. Critically: TDPSA applies in parallel with HIPAA. Satisfying HIPAA is not a complete defense to TDPSA enforcement. If you have a breach and HIPAA compliance can be demonstrated, that helps — but TDPSA has independent enforcement authority and independent penalties. CoreRecon Sentinel and above include TDPSA compliance documentation as a standard deliverable, with parallel mapping to HIPAA requirements to avoid duplicated effort.

Credentials & Client Profile — CoreRecon Senior Living

What operators like yours
are already running.

CoreRecon serves senior living operators across Texas — from single-facility ALFs to multi-site memory care groups. Here's what the program looks like in practice.

SDVOSB-Certified MSSP
Service-Disabled Veteran-Owned Small Business. SDVOSB status gives our clients priority consideration in CMS contracts, Texas state vendor procurements, and federal healthcare programs. AT&T State of Texas vendor. No offshore SOC — every analyst is Texas-based.
Verified SDVOSB
🌍
TX-Resident Analyst Team
Every CoreRecon SOC analyst works from Texas. Our San Antonio operations center covers all Texas time zones and operates 24/7/365. When a TX OIG investigation is mentioned in an incident, our analysts know exactly who that is and what their enforcement track record looks like.
TX-Based Operations
🕒
Client Profile: DFW Memory Care Group
A 4-facility memory care operator in the Dallas-Fort Worth area deployed CoreRecon Fortress tier across 220 endpoints after the Avamere breach wave raised board concerns. 30-day full onboarding. Zero incidents in 14 months of monitoring. Medicaid billing credential monitoring activated within Week 2. OCR audit file delivered at Month 3 — used in successful CMS survey response.
4-Facility Memory Care, DFW
📣
Client Profile: Central TX ALF Group
A 6-ALF assisted living group in Central Texas covering 380 residents deployed CoreRecon Command tier after a near-miss phishing incident compromised an admin email account. MFA deployment completed within 72 hours of onboarding start. Family portal BEC protection prevented a $47,000 payment diversion attempt in Month 2. TX SB 820 notification workflow documented and tested in Month 1.
6-Facility ALF Group, Central TX
📊
Transparent Pricing — No surprises
Every pricing tier is published on this page. No "call for quote." No 3-year contract. 10-endpoint minimum. A 60-resident ALF running Fortress tier at 45 endpoints knows their monthly spend is $5,805 — and that's the number their CFO sees, not a procurement mystery. Month-to-month means we earn your business every month.
Month-to-Month. No Lock-in.
📄
BAA Ready — HIPAA Business Associate
CoreRecon executes BAAs as a standard part of onboarding. We are a HIPAA Business Associate, not just a security vendor. Our BAAs cover all services we provide: SOC monitoring, incident response, EHR log ingestion, billing system access monitoring, and vCISO functions. No additional legal review required — our BAA template is reviewed by healthcare counsel and updated annually.
BAA Standard — No Extra Charge
Active Breach? 24/7 Emergency Response
Already breached? We respond in 30 minutes.
No retainer required. AT&T TX state vendor. SDVOSB-certified. No voicemail.
📞 (800) 955-2596 Or submit emergency intake form →
Free Assessment — $2,500 Value  •  Executive-Ready Report

Get a HIPAA, TX HSC 247 & Medicaid security posture report in 14 days.

We map your full attack surface — EHR access controls, Medicaid billing credentials, family portal security, staff security awareness, and TX SB 820 breach notification readiness. You get a 12-page executive-ready report suitable for your board and your HHSC surveyor. No credit card. No commitment.

Get your executive-ready report — free → Download threat brief PDF ↓

Delivered within 14 days  •  No credit card  •  SDVOSB-certified team  •  30-min SLA

Related Coverage — Texas Healthcare
Texas Healthcare Cybersecurity Overview
CoreRecon covers the full Texas healthcare sector — hospitals, outpatient clinics, behavioral health, senior living, and specialty providers. HIPAA Security Rule, TX HB 300, and TX HSC Chapter 247 mapped together.
Healthcare Overview →