Texas behavioral-health and mental-health clinics — and the MSOs that operate them — hold the most sensitive patient data in healthcare: psychiatric records, substance use history, suicide risk assessments, MAT prescribing logs, telehealth video session recordings, crisis-line call recordings. Each clinic runs a BH-EHR (Credible / Kipu / myEvolv / Netsmart), an MSO consent-management platform, a telehealth video stack (Zoom for Healthcare / Doxy.me / VSee), DEA EPCS for MAT buprenorphine / naltrexone, mobile crisis-team laptops, billing/claims cleared through Availity / Change Healthcare, voice recording systems, and an MSO admin SSO that a single compromise hands the attacker visibility into every clinic's BH-EHR admin console and every credentialed prescriber's EPCS account.
When your clinic dispenses MAT (DEA EPCS for buprenorphine / naltrexone / disulfiram), records telehealth video sessions (TX HSC Ch. 611 mental-health-records consent + 42 CFR Part 2 SUD consent language), or operates across multiple counties under one MSO (BH-EHR admin SSO + cross-clinic credential anomaly surface), four federal/state regulatory tracks attach to your security posture simultaneously. 42 CFR Part 2's federal criminal liability on SUD disclosure is the unique risk layer no other sector inherits. 30-minute IR response. SDVOSB-certified. Texas data residency.
Texas BH and mental-health clinics sit on a stack of federally-protected patient data that a single BH-EHR credential compromise puts in motion. The clinical note contains diagnosis, medication regimen, suicide risk flag, substance use status, and consent-management flags. The EPCS prescribing terminal holds buprenorphine / naltrexone dispense history — high-value target for opioid diversion operators. The telehealth video session recording contains the in-session audio + video that 42 CFR Part 2 specifically protects. The MSO admin SSO is the highest-value single-target attack surface — a single admin compromise gives the attacker visibility into every clinic's BH-EHR admin console, every credentialed prescriber's EPCS account, and every clinic's consent-management audit-trail storage.
Texas behavioral-health and mental-health clinics operate under a multi-track federal/state regulatory stack that no other sector inherits. 42 CFR Part 2 (SAMHSA) imposes federal criminal liability on SUD disclosure. HIPAA Security Rule (45 CFR §164.308 / §164.312) imposes OCR civil enforcement. TX HSC Ch. 611 imposes specific consent language on mental-health records. TX HB 300 (HSC Ch. 181) expands covered-entity scope on training and breach notification. TDPSA §541.062 enumerates sensitive-data categories including health and mental-health data. FTC Health Breach Notification Rule (16 CFR §318, 2024 Revision Final Rule) extends coverage to non-HIPAA BH apps and direct-to-consumer mental-health platforms. SAMHSA NIMDAT, DEA EPCS where MAT programs exist, CMS CoP for federally-qualified behavioral health centers. Each track has an active enforcement arm.
Generic managed IT treats a BH clinic like a dental office or a CPA firm — same EDR, same patch cadence, same MFA. BH-EHRs (Credible / Kipu / myEvolv / Netsmart / Epic Behavioral Health), consent-management audit-trail workflows, MAT EPCS prescribing, telehealth video session recording, MSO admin SSO across multiple TX clinics, and 42 CFR Part 2 SAMHSA disclosure trigger carry workflow-specific risks that no other sector inherits. Standard MSSPs watch EDR signals; our SOC watches BH-EHR signals.
CoreRecon instruments the asset inventory specific to Texas BH clinics, mental-health clinics, MSOs, IOP/PHP programs, and SUD treatment centers. Generic MSSPs inventory endpoints; we inventory the BH-specific workflow endpoints that govern 42 CFR Part 2 SAMHSA disclosure triggers and CMS CoP eligibility.
CoreRecon publishes pricing because BH clinic directors and BH-MSO leadership shouldn't need to spend 90 minutes on a sales call to learn whether a cybersecurity provider is in-bounds. Three tiers. Per-endpoint. All include 24/7 SOC coverage and 30-minute IR SLA.
BH clinics and MSOs operate a workflow that generic IT doesn't model. When our SOC sees a BH-EHR credential anomaly, the workflow is structured — not reactive. The six steps below are the CoreRecon default scope for a TX BH-MSO subscription; Command tier adds full authorization and SDVOSB set-aside procurement documentation.
CoreRecon maps every SOC function to the specific regulation or framework that requires it. When SAMHSA, OCR, FTC, TX AG, or DEA EPCS-audit examiner asks—what does your security program actually cover?—this is the answer.
| Requirement | Federal (42 CFR Part 2 / HIPAA / FTC HBNR) | Texas (HSC Ch. 611 / HB 300 / TDPSA) | CoreRecon Control | Monitored KPI |
|---|---|---|---|---|
| 42 CFR Part 2 (SAMHSA — SUD records) | 42 CFR §2.13 — disclosure with written consent; §2.16 — breach notification | — | Consent-managed disclosure language library; SAMHSA NIMDAT breach workflow; consent-manifest drift detection | SUD-note-level flag access events / 24h |
| HIPAA Security Rule | 45 CFR §164.308 / §164.310 / §164.312 (administrative / physical / technical safeguards) | — | EDR + Conditional Access + MFA on BH-EHR admin SSO; audit log ingest; 12-month retention | BH-EHR admin sign-in events / 24h |
| TX HSC Ch. 611 (Mental Health Records) | — | TX HSC Ch. 611 — written consent for mental-health records disclosure | Mental-health consent-managed disclosure library; dual-track state breach notification | Mental-health record disclosure events / 24h |
| TX HB 300 (TX HSC Ch. 181) | — | HSC Ch. 181 — workforce training; 60-day breach notification to TX AG + residents | Documented workforce training events; TX AG breach-notification pre-positioned templates | Training completion % per quarter |
| TDPSA §541.062 + §541.151 | — | TDPSA §541.062 sensitive-data enumeration; §541.151 — 30-day breach notification | Sensitive-data DLP on PHI / SUD / mental-health data; 30-day TX AG + consumer notification | Sensitive-data DLP events / 24h |
| FTC Health Breach Notification Rule (16 CFR §318) | 16 CFR §318 (2024 Revision Final Rule) — non-HIPAA BH apps + direct-to-consumer platforms | — | Non-HIPAA BH app credential hardening; FTC HBNR notification workflow; consumer-notification distribution | Non-HIPAA BH app access events / 24h |
| SAMHSA NIMDAT | SAMHSA National Incident Management & Data Analysis Tool — SUD program breach submission | — | Automated breach-event capture + consent-managed disclosure pre-flight before any NIMDAT submission | NIMDAT submission SLA (≤2 business days) |
| DEA EPCS (21 CFR §1311) | 21 CFR §1311 — Electronic Prescriptions for Controlled Substances — MAT prescription integrity | — | EDR + 2FA token monitoring on prescribing terminal; EPCS audit-log integrity; SUD-MAT dispense log monitoring | EPCS sign-in events / 24h |
| CMS CoP (Federally-Qualified BH Centers) | 42 CFR §485 — Conditions of Participation for community mental-health centers | — | BH-EHR admin SSO + prescribing-terminal + telehealth video + consent-management audit trail; quarterly vCISO report | SOC containment SLA (≤30 min confirmed) |
TX behavioral-health and mental-health MSOs have a procurement edge that generic MSSPs don't service. SDVOSB positioning on CMHC (federally-qualified BH center) contracts. SAMHSA block-grant sub-contract awards. VA Choice / TriWest behavioral health subcontracts. HHS Office of Behavioral Health awards. Texas DIR cooperative contracting (TIPS / BuyBoard) preference for state-funded BH programs.
Behavioral Health Group (TX SUD treatment network) experienced a BH-EHR credential compromise pattern that matches the dwell-time / kill-chain observed across the BH sector: Acuity Brands (LockBit affiliate Feb 2024), Lifepoint Health (ALPHV Oct 2023), Ardent Health TX-anchored hospital network (Nov 2023 offline), Community Health Systems (Fortra GoAnywhere Feb 2023, 1M+ records). What follows is the operationally reconstructed kill-chain sequence a TX SUD treatment center walked through with CoreRecon's SOC.
6 documented incidents. Acuity Brands (LockBit Feb 2024, 2.5M+ records). Lifepoint Health (ALPHV Oct 2023). Ardent Health TX-anchored network (Nov 2023). Community Health Systems (Fortra GoAnywhere Feb 2023, 1M+ records). Behavioral Health Group TX SUD exposure. Deer Oaks Behavioral Health TX APC ($225K ransom). Threat actor profile (LockBit / BlackCat / Rhysida). 60+ verified sources. Print-ready PDF.
Direct answers. Not legal advice. Not a substitute for your BH-MSO counsel — but enough to know whether we're a fit.
Acuity Brands lost 2.5M+ records to LockBit in Feb 2024. Lifepoint Health ALPHV Oct 2023. Ardent Health TX offline Nov 2023. Behavioral Health Group TX SUD exposure with SAMHSA breach-notification triggered. Deer Oaks TX $225K ransom. 42 CFR Part 2 federal criminal liability stacks on HIPAA civil penalties. TX HSC Ch. 611 + TX HB 300 + TDPSA + FTC HBNR run on parallel clocks. The only question is whether your BH-MSO has a documented BH-EHR-aware SOC, a consent-managed 42 CFR Part 2 disclosure language library, and four-clock dual-track IR — or a hope and an underwriter carve-out.
Start the free BH-MSO security posture assessment. Takes 20 minutes. Written report with prioritized findings. No sales deck.