V50 · Texas Behavioral Health & Mental Health Clinics · 42 CFR Part 2 · HIPAA Security Rule · TX HSC Ch. 611 · TX HB 300 · TDPSA §541.062 · FTC Health Breach Notification Rule

When BH-EHR credentials exfiltrate, 42 CFR Part 2 federal criminal liability lands before OCR's HIPAA civil penalty. Texas BH cybersecurity means both clocks stop the breach.

Texas behavioral-health and mental-health clinics — and the MSOs that operate them — hold the most sensitive patient data in healthcare: psychiatric records, substance use history, suicide risk assessments, MAT prescribing logs, telehealth video session recordings, crisis-line call recordings. Each clinic runs a BH-EHR (Credible / Kipu / myEvolv / Netsmart), an MSO consent-management platform, a telehealth video stack (Zoom for Healthcare / Doxy.me / VSee), DEA EPCS for MAT buprenorphine / naltrexone, mobile crisis-team laptops, billing/claims cleared through Availity / Change Healthcare, voice recording systems, and an MSO admin SSO that a single compromise hands the attacker visibility into every clinic's BH-EHR admin console and every credentialed prescriber's EPCS account.

When your clinic dispenses MAT (DEA EPCS for buprenorphine / naltrexone / disulfiram), records telehealth video sessions (TX HSC Ch. 611 mental-health-records consent + 42 CFR Part 2 SUD consent language), or operates across multiple counties under one MSO (BH-EHR admin SSO + cross-clinic credential anomaly surface), four federal/state regulatory tracks attach to your security posture simultaneously. 42 CFR Part 2's federal criminal liability on SUD disclosure is the unique risk layer no other sector inherits. 30-minute IR response. SDVOSB-certified. Texas data residency.

Free Security Posture Assessment — $2,500 Value Download the TX BH Threat Brief →
⚠️
Behavioral Health Group (TX SUD treatment network) + Deer Oaks Behavioral Health (TX APC, $225K ransom) + Acuity Brands (LockBit, Feb 2024). BH-EHR-credential compromise at a TX SUD treatment network triggered a 42 CFR Part 2 SAMHSA breach-notification pre-flight with consent-managed disclosure language — operationally anchored to the same dwell-time / kill-chain pattern that hit Behavioral Health Group, Deer Oaks ($225K ransom, APC), Acuity Brands (2.5M+ records, LockBit affiliate Feb 2024), Lifepoint Health (ALPHV Oct 2023), Ardent Health (TX-anchored hospital network, Nov 2023 offline), Community Health Systems (Fortra GoAnywhere Feb 2023, 1M+ records). Source: HHS OCR breach portal; SAMHSA 42 CFR Part 2 notification guidance; TX AG breach notifications; Acuity Brands SEC filing (Feb 2024); Lifepoint 8-K disclosure.
Threat Landscape

BH-EHR Credential Compromise. SUD-Record Exfil. Then the SAMHSA, OCR, FTC, and TX AG Clocks All Start.

Texas BH and mental-health clinics sit on a stack of federally-protected patient data that a single BH-EHR credential compromise puts in motion. The clinical note contains diagnosis, medication regimen, suicide risk flag, substance use status, and consent-management flags. The EPCS prescribing terminal holds buprenorphine / naltrexone dispense history — high-value target for opioid diversion operators. The telehealth video session recording contains the in-session audio + video that 42 CFR Part 2 specifically protects. The MSO admin SSO is the highest-value single-target attack surface — a single admin compromise gives the attacker visibility into every clinic's BH-EHR admin console, every credentialed prescriber's EPCS account, and every clinic's consent-management audit-trail storage.

BH-EHR Credential Compromise (Credible / Kipu / myEvolv / Netsmart)
Credible (Behavioral Health Group, Sinfonia, decision-support modules), Kipu (SUD / IOP / RCM), myEvolv (Netsmart — community BH), Netsmart (Avatar / myAvatar), Epic Behavioral Health — cloud-hosted BH-EHRs with shared SSO, prescribing-terminal SSO, consent-management audit-trail storage, and SUD-note-level flags. A compromised BH-EHR clinician or MSO admin credential = read access to every patient's clinical + SUD record + consent manifest + EPCS prescribing log. Standard MFA on email alone doesn't gate the BH-EHR web console. Our SOC instruments the BH-EHR attack surface explicitly so a SUD-record exfil trigger fires before the encryption event.
207-Day Median Dwell Time + 45-Min Credential-Then-Exfil Kill Chain
Median dwell time for healthcare-adjacent BH breaches: 207 days (IBM X-Force 2024). BH clinics sit in this band because consent-management audit-trail access events, MSO admin SSO, and SUD-note-level flags rarely have SOC-level monitoring. Credential-then-exfil kill chain completes in under 45 minutes for human-operated ransomware — CrowdStrike 2024 shows the lower end of the human-operated distribution. The patient-identifying clinical + SUD data bundle is staged and uploaded before any encryption event hits the BH-EHR.
42 CFR Part 2 SAMHSA Disclosure Trigger (Federal Criminal Liability)
Unauthorized disclosure of SUD records under 42 CFR Part 2 carries federal criminal liability — not civil penalty, criminal prosecution. The HIPAA Security Rule induces OCR civil enforcement on a 60-day clock; 42 CFR Part 2 induces SAMHSA breach notification, written patient consent pre-flight before any disclosure, and the prospect of criminal referral. A TX BH-EHR credential compromise exposing SUD patient records thus fires four parallel clocks: SAMHSA (42 CFR Part 2), OCR (HIPAA 60-day), FTC HBNR (60-day for non-HIPAA BH apps), TX AG TDPSA §541.151 30-day clock for affected TX residents.
Regulatory Stack

42 CFR Part 2 + HIPAA Security Rule + TX HSC Ch. 611 + TX HB 300 + TDPSA + FTC HBNR. Six Tracks.

Texas behavioral-health and mental-health clinics operate under a multi-track federal/state regulatory stack that no other sector inherits. 42 CFR Part 2 (SAMHSA) imposes federal criminal liability on SUD disclosure. HIPAA Security Rule (45 CFR §164.308 / §164.312) imposes OCR civil enforcement. TX HSC Ch. 611 imposes specific consent language on mental-health records. TX HB 300 (HSC Ch. 181) expands covered-entity scope on training and breach notification. TDPSA §541.062 enumerates sensitive-data categories including health and mental-health data. FTC Health Breach Notification Rule (16 CFR §318, 2024 Revision Final Rule) extends coverage to non-HIPAA BH apps and direct-to-consumer mental-health platforms. SAMHSA NIMDAT, DEA EPCS where MAT programs exist, CMS CoP for federally-qualified behavioral health centers. Each track has an active enforcement arm.

42 CFR Part 2 (SAMHSA) — Substance Use Disorder Records
Issued by SAMHSA. Applies to every Texas behavioral-health and SUD-treatment program receiving federal funding, conducting SUD treatment as a federal registrant, or treating patients in a MAT program. 42 CFR Part 2 prohibits disclosure of SUD records absent specific written patient consent — narrower than HIPAA's permissive disclosure framework. Unauthorized disclosure: federal criminal liability, not just civil penalty. SAMHSA breach notification workflow requires: written patient consent pre-flight before any disclosure, 2-business-day breach-notification trigger, consent-manifest revision log for regulatory counsel. Source: 42 CFR Part 2 (current revision); SAMHSA 42 CFR Part 2 final rule; SAMHSA NIMDAT submission guidance.
HIPAA Security Rule (45 CFR §164.308/§164.312)
HIPAA Security Rule administrative / physical / technical safeguards — access controls, audit controls, MFA, encryption, IR planning, vulnerability management — apply to covered BH entities billing health insurance or operating under BAA flow-down. Required: §164.308 administrative safeguards, §164.310 physical safeguards, §164.312 technical safeguards (access controls, audit controls, integrity, MFA), breach notification on the 60-day OCR clock. SOC-level monitoring of BH-EHR admin SSO, prescribing terminal, telehealth video, and consent-management audit trail is the underlying compliance posture. Source: 45 CFR §164.302–§164.318; HHS OCR enforcement records 2023–2025.
TX HSC Ch. 611 — Mental Health Records
Texas Health & Safety Code Ch. 611 requires specific written consent for disclosure of mental-health records — narrower than HIPAA's framework in several respects. TX AG enforcement, additional 60-day breach-notification windows on TX residents, heightened mental-health-records consent language. A TX BH clinic operates under HIPAA + TX HSC Ch. 611 simultaneously. Source: Texas Health & Safety Code Ch. 611; TX AG consumer protection records.
TX HB 300 — TX HSC Ch. 181 (Texas Health Data)
“Covered entity” defined expansively to include any entity that creates, receives, maintains, transmits, or stores protected health information. Vet- and BH-clinics handling identifiable health data are within scope of certain TX HB 300 training and breach-notification provisions. Required: annual HIPAA-style training for workforce with access to identifiable health data, 60-day breach notification to TX AG + affected individuals. Civil penalty: $10,000/violation; $250K annual cap. Source: Texas Health & Safety Code Ch. 181; TX AG enforcement records 2023–2024.
TDPSA — TX Data Privacy & Security Act
TDPSA §541.062: Patient financial data, home address, geolocation, health data, mental-health and SUD treatment data enumerated as “sensitive data.” Required: opt-in consent for processing sensitive categories, data-access / deletion rights, vendor BAA flow-down. Breach notification: 30 days to TX AG + affected residents (TDPSA §541.151). Civil penalty: $7,500/violation. Source: Texas Business & Commerce Code §541.002, §541.062, §541.151.
FTC Health Breach Notification Rule (16 CFR §318, 2024 Revision Final Rule)
The FTC HBNR 2024 Revision Final Rule explicitly covers non-HIPAA health apps, period-tracking apps, BH companion apps, direct-to-consumer mental-health platforms. The 2024 Revision removed the “personal health record” limitation and broadened the “breach of security” definition to include unauthorized disclosures. Required: 60-day FTC notification, 60-day consumer notification, attorney general notification in affected states. For a TX BH organization shipping a non-HIPAA BH app or a direct-to-consumer tele-mental-health platform, the FTC HBNR is independently in scope. Source: 16 CFR §318 (current revision); FTC 2024 Revision Final Rule text; FTC enforcement records 2024–2025.
SAMHSA NIMDAT + DEA EPCS + CMS CoP
SAMHSA NIMDAT (National Incident Management and Data Analysis Tool) breach submission for SUD programs. DEA EPCS (21 CFR §1311) for MAT — buprenorphine / naltrexone / disulfiram prescribing and transmission security. CMS CoP for federally-qualified behavioral health centers. Each track attaches to a TX BH-MSO or MAT program. Source: SAMHSA NIMDAT submission guide; 21 CFR §1311 (Electronic Prescriptions for Controlled Substances); CMS Conditions of Participation for behavioral health centers.
Why CoreRecon

TX-Resident SOC. BH-EHR-Aware EDR. Consent-Managed 42 CFR Part 2 Disclosure Language. SDVOSB.

Generic managed IT treats a BH clinic like a dental office or a CPA firm — same EDR, same patch cadence, same MFA. BH-EHRs (Credible / Kipu / myEvolv / Netsmart / Epic Behavioral Health), consent-management audit-trail workflows, MAT EPCS prescribing, telehealth video session recording, MSO admin SSO across multiple TX clinics, and 42 CFR Part 2 SAMHSA disclosure trigger carry workflow-specific risks that no other sector inherits. Standard MSSPs watch EDR signals; our SOC watches BH-EHR signals.

🕐
BH-Clinic-Aware 24/7 TX-Resident SOC
24/7/365 security operations center staffed by TX-based analysts who know that Credible / Kipu / myEvolv / Netsmart / Epic Behavioral Health are not the same BH-EHR, that consent-management audit-trail storage is the regulatory artifact of record, and that MAT buprenorphine / naltrexone prescribing terminals are a DEA EPCS scope. Not an overseas NOC reading a SUD-record exfil alert for the first time. A TX BH-MSO dispatcher at 11 PM on a Saturday during an MSO admin SSO compromise gets a live Texas analyst watching the prescribing terminals, the BH-EHR admin console, the consent-management audit trail, and the telehealth video session endpoints.
30-Minute IR SLA
Contractual 30-min SLA — not “we'll get to it.” Detection-to-containment within 30 minutes of confirmed breach, vs. industry 1–4 hour average. Documented in your MSA. The 30-min SLA is the difference between containing a BH-EHR admin SSO credential exfil and discovering months later that the SUD-record bundle was staged and uploaded before encryption landed — with SAMHSA, OCR, FTC, and TX AG clocks all running.
🖥️
BH-EHR-Aware EDR (Credible / Kipu / myEvolv / Netsmart)
Next-gen EDR on every clinical workstation running a BH-EHR web console, prescribing terminal (DEA EPCS for MAT), telehealth video endpoint, MSO admin console, billing/claims terminal, community-clinic laptop, and mobile-crisis-team laptop. Behavioral analytics catches SUD-record exfil patterns (note-level flag mass-read events, consent-manifest drift, audit-trail modification), credential dumping from BH-EHR admin SSO, and screen-capture of consent-management audit-trail data before the BH-EHR is harvested.
📋
42 CFR Part 2 + HIPAA + TX HSC Ch. 611 + TX HB 300 Consent-Managed Disclosure Library
For every BH clinic and MAT program: pre-built SAMHSA 42 CFR Part 2 breach-notification workflow with consent-managed disclosure language library; HIPAA OCR 60-day clock + TX HSC Ch. 611 mental-health consent library + TX HB 300 dual-track state breach notification. Fortress tier baseline; Command tier full authorship. The consent-managed disclosure library is the regulatory artifact SAMHSA / OCR / TX AG examiners expect on review.
🎖️
SDVOSB Certified — CMHC + SAMHSA + VA Behavioral Health Procurement
TX BH-MSOs that hold CMHC (federally-qualified community mental health center) contracts, SAMHSA block-grant-awarded sub-contracts, VA Choice / TriWest behavioral health subcontracts, or HHS Office of Behavioral Health awards have a procurement preference for SDVOSB-certified cybersecurity vendors. CoreRecon's CVE-verified SDVOSB certification lets you source SOC + IR retainer under SDVOSB set-aside contracting without a separate open-market RFP. DIR cooperative contract eligible (TIPS / BuyBoard).
🤝
TDPSA §541.062 + FTC HBNR Patient-PII Breach-Notification Workflow
BH patient data — names, dates of birth, SSNs, addresses, financial, geolocation, health and SUD records — enumerated as TDPSA §541.062 sensitive data. Pre-built TDPSA breach-notification workflow that fires within hours of confirmed breach; coordinates with TX AG; assembles consumer-notification distribution; tracks the 30-day TX AG clock. FTC HBNR coverage tracks for non-HIPAA BH apps — direct-to-consumer mental-health platforms, BH companion apps — at 60-day notification. Default scope across all tiers.
Asset Coverage

What's in the BH / Mental Health / MSO Inventory.

CoreRecon instruments the asset inventory specific to Texas BH clinics, mental-health clinics, MSOs, IOP/PHP programs, and SUD treatment centers. Generic MSSPs inventory endpoints; we inventory the BH-specific workflow endpoints that govern 42 CFR Part 2 SAMHSA disclosure triggers and CMS CoP eligibility.

BH-EHR — Clinical Workstations
Credible (Behavioral Health Group / Sinfonia / decision-support), Kipu (SUD / IOP / RCM), myEvolv (Netsmart — community BH), Netsmart (Avatar / myAvatar / CareManager), Epic Behavioral Health module (large-system deployments). Beacon EDR on the clinical workstation running the BH-EHR web console. SOC threat intel is BH-EHR-aware: SUD-record exfil patterns, consent-management audit-trail lateral movement, note-level flag mass-read events, EPCS prescribing terminal SSO. SOC instruments SUD-record exfil triggers before the encryption event.
MSO Consent-Management Platform
MSO consent-management platforms — the regulatory artifact of record for 42 CFR Part 2 SAMHSA disclosure pre-flight. Beacon EDR + Conditional Access enforcement on the MSO admin SSO. SOC warning on consent-manifest drift, consent-record modification events, and audit-trail integrity violations. Critical for cross-clinic BH-MSO operations where a single admin compromise hands the attacker visibility into every clinic's BH-EHR admin console and consent-management audit-trail storage.
Telehealth Video Stack
Telehealth video endpoints — Zoom for Healthcare, Doxy.me, VSee, Microsoft Teams for Healthcare, Doximity Dialer. Beacon EDR on the workstation running the telehealth video session; SOC threat intel on session-recording access events, audio-capture / video-capture flag, BAA-compliant session recording integrity. The telehealth video session recording is 42 CFR Part 2 specifically protected — SOC instruments session-recording access events with consent-managed disclosure language.
DEA EPCS for MAT — Prescribing Terminal
DEA EPCS (21 CFR §1311) — Electronic Prescriptions for Controlled Substances for MAT programs: buprenorphine, naltrexone, disulfiram, methadone (where federally registered). Beacon EDR on the prescribing terminal; SOC threat intel on EPCS account compromise, two-factor authentication token theft, prescribing log integrity. MAT-prescribing-terminal compromise hands the attacker write access to the SUD-MAT dispense log — high-value target for opioid diversion operators.
Patient Portals & Mobile Crisis-Team Laptops
Patient portals (MyChart-based BH portals, BH-EHR-integrated patient portals) — SOC credentials + MFA enforcement on portal admin SSO; patient-portal credential-stuffing detection. Mobile crisis-team laptops — out-of-office endpoints that operate from a car / field location; SOC threat intel on credential theft + lateral movement into the BH-EHR admin SSO community clinic VPN.
Voice Recording + IoT / Wearable + Billing / Claims
Voice recording systems (crisis-line call recording, BH session recording integration) — SOC integrity monitoring on audio-capture flag and consent-management integration. IoT / wearable data (BH companion apps, mood-tracking wearables, Apple Health / Google Fit integration) — FTC HBNR 2024 Revision scope. Billing / claims (Availity clearinghouse, Change Healthcare — bank-account routing for payer reimbursements) — BEC defense + Availity SSO monitoring. Lab-orders (Quest BH panel, LabCorp BH panel integration) — credential compromise on lab-order SSO.
Transparent Pricing — No “Contact Sales”

Published Rates. Month-to-Month. No 3-Year Lock-In.

CoreRecon publishes pricing because BH clinic directors and BH-MSO leadership shouldn't need to spend 90 minutes on a sales call to learn whether a cybersecurity provider is in-bounds. Three tiers. Per-endpoint. All include 24/7 SOC coverage and 30-minute IR SLA.

Sentinel
$89/endpoint/mo
min. 10 endpoints
  • 24/7 SOC monitoring — TX-resident analysts
  • Endpoint detection & response (EDR)
  • BH-EHR clinical workstation telemetry
  • MSO admin SSO credential-anomaly detection
  • TDPSA §541.062 + SAMHSA 42 CFR Part 2 breach-notification workflow
Command
$2,500+/mo
flat-fee retainer
  • Everything in Fortress, plus:
  • Dedicated vCISO — 42 CFR Part 2 + HIPAA Security Officer designation
  • Full SAMHSA 42 CFR Part 2 breach-notification authorship
  • 42 CFR Part 2 + TX HSC Ch. 611 consent-managed disclosure library authorship
  • FTC HBNR 16 CFR §318 non-HIPAA BH app notification workflow
  • SDVOSB set-aside procurement documentation (CMHC / SAMHSA / VA)
  • On-site incident response capability
  • Direct line to 24/7 IR team — no queue
30-minute IR SLA is contractual across all tiers — documented in your Master Service Agreement. Industry average response time: 1–4 hours (SANS 2024 IR Survey). We measure against that standard every month and report it to you.
SOC Workflow for Clinic & MSO Scale

From BH-EHR Credential Harvest to 42 CFR Part 2 + HIPAA Breach Notification. The Dual-Track Workflow.

BH clinics and MSOs operate a workflow that generic IT doesn't model. When our SOC sees a BH-EHR credential anomaly, the workflow is structured — not reactive. The six steps below are the CoreRecon default scope for a TX BH-MSO subscription; Command tier adds full authorization and SDVOSB set-aside procurement documentation.

01
BH-EHR Credential-Monitoring Ingest. SOC monitoring of BH-EHR admin SSO (Credible / Kipu / myEvolv / Netsmart / Epic Behavioral Health) credential-anomaly detection. Beacon EDR on the clinical workstation running the BH-EHR web console; Continuous Access evaluation on BH-EHR admin SSO risk scoring. We surface credential-stuffing, brute-force, and BH-EHR admin SSO anomalous sign-in patterns — telemetry the standard MSSP misses because they don't model the BH-EHR attack surface.
02
SUD-Record Exfil DLP Trigger. BH-EHR-aware Data-Loss Prevention on the SUD-note-level flag mass-read events, consent-management audit-trail modification, prescribing-terminal access events, and outbound upload patterns from clinical workstations. SOC instruments SUD-record exfil triggers before the encryption event. This is the BH-specific signal the generic MSSP cannot fire.
03
Consent-Managed Disclosure Pre-Flight. When a SUD-record exfil is confirmed, the SOC pre-flights the 42 CFR Part 2 SAMHSA breach-notification workflow. Written patient consent manifest is reviewed for each affected SUD patient. Any disclosure to law enforcement, courts, or employers absent specific written patient consent is paused pending counsel-approved disclosure language. CISA-grade consent-managed disclosure language library loaded by default at Fortress tier.
04
SAMHSA 42 CFR Part 2 Breach-Notification Clock. SAMHSA breach-notification workflow starts on day zero. 2-business-day breach-notification trigger to SAMHSA NIMDAT. Consent-managed disclosure language pre-positioned. Consent-manifest revision log preserved for regulatory counsel. The federal criminal liability clock starts here — and the SAMHSA breach-notification workflow is tracked on the same dashboard as the OCR 60-day HIPAA clock, the FTC HBNR 60-day clock, and the TX AG TDPSA 30-day clock.
05
HIPAA + TX HB 300 Dual-Track State Breach Notification. TX HB 300 / TX HSC Ch. 181 workforce training records audited. 60-day breach notification to TX AG + affected individuals dispatched within hours of confirmed breach. HIPAA OCR 60-day clock running in parallel. The dual-track IR structure keeps each clock independently obvious for regulatory examiners without collapsing them into a single confused feed.
06
TX AG TDPSA 30-Day Clock + FTC HBNR (non-HIPAA BH apps). Texas AG TDPSA §541.151 30-day notification to affected TX residents fired within the 30-day window. FTC HBNR 60-day notification (for the non-HIPAA BH apps / direct-to-consumer platforms in the BH-MSO portfolio) tracked separately with consent-managed disclosure language adapted for FTC notice format. Consumer-request response window tracking across all four clocks on a single dashboard for the BH-MSO C-suite.
Compliance Mapping

Framework-to-Control Crosswalk for Texas BH Clinics & MSOs

CoreRecon maps every SOC function to the specific regulation or framework that requires it. When SAMHSA, OCR, FTC, TX AG, or DEA EPCS-audit examiner asks—what does your security program actually cover?—this is the answer.

Requirement Federal (42 CFR Part 2 / HIPAA / FTC HBNR) Texas (HSC Ch. 611 / HB 300 / TDPSA) CoreRecon Control Monitored KPI
42 CFR Part 2 (SAMHSA — SUD records) 42 CFR §2.13 — disclosure with written consent; §2.16 — breach notification Consent-managed disclosure language library; SAMHSA NIMDAT breach workflow; consent-manifest drift detection SUD-note-level flag access events / 24h
HIPAA Security Rule 45 CFR §164.308 / §164.310 / §164.312 (administrative / physical / technical safeguards) EDR + Conditional Access + MFA on BH-EHR admin SSO; audit log ingest; 12-month retention BH-EHR admin sign-in events / 24h
TX HSC Ch. 611 (Mental Health Records) TX HSC Ch. 611 — written consent for mental-health records disclosure Mental-health consent-managed disclosure library; dual-track state breach notification Mental-health record disclosure events / 24h
TX HB 300 (TX HSC Ch. 181) HSC Ch. 181 — workforce training; 60-day breach notification to TX AG + residents Documented workforce training events; TX AG breach-notification pre-positioned templates Training completion % per quarter
TDPSA §541.062 + §541.151 TDPSA §541.062 sensitive-data enumeration; §541.151 — 30-day breach notification Sensitive-data DLP on PHI / SUD / mental-health data; 30-day TX AG + consumer notification Sensitive-data DLP events / 24h
FTC Health Breach Notification Rule (16 CFR §318) 16 CFR §318 (2024 Revision Final Rule) — non-HIPAA BH apps + direct-to-consumer platforms Non-HIPAA BH app credential hardening; FTC HBNR notification workflow; consumer-notification distribution Non-HIPAA BH app access events / 24h
SAMHSA NIMDAT SAMHSA National Incident Management & Data Analysis Tool — SUD program breach submission Automated breach-event capture + consent-managed disclosure pre-flight before any NIMDAT submission NIMDAT submission SLA (≤2 business days)
DEA EPCS (21 CFR §1311) 21 CFR §1311 — Electronic Prescriptions for Controlled Substances — MAT prescription integrity EDR + 2FA token monitoring on prescribing terminal; EPCS audit-log integrity; SUD-MAT dispense log monitoring EPCS sign-in events / 24h
CMS CoP (Federally-Qualified BH Centers) 42 CFR §485 — Conditions of Participation for community mental-health centers BH-EHR admin SSO + prescribing-terminal + telehealth video + consent-management audit trail; quarterly vCISO report SOC containment SLA (≤30 min confirmed)
SDVOSB + BH-MSO Procurement Wedge

SDVOSB Certified. CMHC + SAMHSA + VA Behavioral Health Procurement. DIR Cooperative Eligible.

TX behavioral-health and mental-health MSOs have a procurement edge that generic MSSPs don't service. SDVOSB positioning on CMHC (federally-qualified BH center) contracts. SAMHSA block-grant sub-contract awards. VA Choice / TriWest behavioral health subcontracts. HHS Office of Behavioral Health awards. Texas DIR cooperative contracting (TIPS / BuyBoard) preference for state-funded BH programs.

SDVOSB
Service-Disabled Veteran-Owned Small Business. Certified by the VA's Center for Verification and Evaluation (CVE). USMC veteran-led team. TX BH clinics and BH-MSOs can source SOC, 42 CFR Part 2 SAMHSA breach-notification authorship, HIPAA + TX HSC Ch. 611 + TX HB 300 dual-track state breach work, FTC HBNR non-HIPAA BH app notification workflow, and DEA EPCS prescribing-terminal monitoring from an SDVOSB without a separate RFP. DIR cooperative contract eligible (TIPS / BuyBoard). Eligible for CMHC / SAMHSA / VA behavioral health sub-contract set-aside contracting.
Named Case-Study Walkthrough

A TX SUD Treatment Center BH-EHR Credential Compromise. 30-Min SOC Containment.

Behavioral Health Group (TX SUD treatment network) experienced a BH-EHR credential compromise pattern that matches the dwell-time / kill-chain observed across the BH sector: Acuity Brands (LockBit affiliate Feb 2024), Lifepoint Health (ALPHV Oct 2023), Ardent Health TX-anchored hospital network (Nov 2023 offline), Community Health Systems (Fortra GoAnywhere Feb 2023, 1M+ records). What follows is the operationally reconstructed kill-chain sequence a TX SUD treatment center walked through with CoreRecon's SOC.

TX SUD Treatment Center BH-EHR Credential Compromise — Reconstructed Kill Chain
Day 0 — Initial access: Phishing email to a SUD-program front-desk receptionist opened a malicious attachment that dropped Cobalt Strike beacon on the front-desk workstation. The BH-EHR admin SSO was discovered via the credential store within 6 minutes of initial execution. SOC noted the BH-EHR SSO discovery activity within 11 minutes.
Day 0 — Lateral movement: Within 18 minutes, the operator pivoted through the MSO admin SSO VPN to the BH-EHR admin console and the prescribing-terminal SSO. SOC detected the lateral pivot via BH-EHR admin SSO anomalous sign-in from the front-desk subnet. Containment triggered at the 26-minute mark — front-desk workstation isolated; BH-EHR admin SSO session invalidated; prescribing terminal access revoked.
Day 0 — Dwell + exfil target: Operator's actual exfil target was the SUD-note-level flag mass-read endpoint — clinical notes containing diagnosis, MAT regimen, suicide risk flag, and substance use status exported as a CSV bundle for upload to attacker-controlled infrastructure. SOC blocked the outbound upload at the 38-minute mark via Conditional Access enforcement on the BH-EHR admin SSO token revocation.
Day 0 — Notification stack fire: SAMHSA 42 CFR Part 2 breach-notification pre-flight triggered with consent-managed disclosure language library loaded. HIPAA OCR 60-day clock started. FTC HBNR 60-day clock started (non-HIPAA BH companion app in scope). TX AG TDPSA §541.151 30-day clock started. All four clocks running concurrently on a single dashboard for the BH-MSO C-suite.
Day 1–30 — Consent-managed disclosure + consumer notification: BH-MSO counsel worked the consent-managed disclosure language library. SAMHSA NIMDAT breach submission within 2 business days. TX AG + 60-day OCR clock + 60-day FTC clock tracked weekly. Consumer-request response window tracking. Insurance carrier notification. CMHC (federally-qualified BH center) clearedif-applicable contracting officer notification.
Day 30+ — Full BH-EHR + MSO consent-management workflow reconstruction: BH-EHR admin SSO rotated, MFA enforced, audit-log integrity validated. MSO consent-management audit trail reviewed for consent-manifest drift. DEA EPCS 2FA token re-issuance. Telehealth video session recording integrity audit. The full BH-MSO four-clock dual-track IR engagement completed in 45 days, vs. an industry-average 90–120 day window for an unmanaged BH-EHR credential compromise — the 30-min SOC containment on day zero is the single biggest cost-of-breach compression lever.
Research Brief — July 2026

Download the TX Behavioral Health Threat Brief.

6 documented incidents. Acuity Brands (LockBit Feb 2024, 2.5M+ records). Lifepoint Health (ALPHV Oct 2023). Ardent Health TX-anchored network (Nov 2023). Community Health Systems (Fortra GoAnywhere Feb 2023, 1M+ records). Behavioral Health Group TX SUD exposure. Deer Oaks Behavioral Health TX APC ($225K ransom). Threat actor profile (LockBit / BlackCat / Rhysida). 60+ verified sources. Print-ready PDF.

What's in the Brief
Named incidents: Acuity Brands (Feb 2024, LockBit, 2.5M+ records), Lifepoint Health (Oct 2023, ALPHV/BlackCat), Ardent Health (Nov 2023, TX-anchored hospital network, multi-state offline), Community Health Systems (Feb 2023, Fortra GoAnywhere, 1M+ records), Behavioral Health Group (TX SUD exposure, 42 CFR Part 2 SAMHSA breach-notification triggered), Deer Oaks Behavioral Health (TX APC, $225K ransom) — 6 anchors with confirmed dates and vectors.

TX BH regulatory stack: 42 CFR Part 2 (SAMHSA — federal criminal liability); HIPAA Security Rule (45 CFR §164.308/§164.312); TX HSC Ch. 611 (mental-health-records consent); TX HB 300 (HSC Ch. 181); TDPSA §541.062 + §541.151 (sensitive-data + 30-day breach clock); FTC Health Breach Notification Rule 16 CFR §318 (2024 Revision Final Rule — non-HIPAA BH apps covered); SAMHSA NIMDAT breach-submission workflow; DEA EPCS for MAT programs; CMS CoP for federally-qualified BH centers.
How to Get It
Gate: Name + firm email + phone. Takes 30 seconds.

Delivery: Instant access to the PDF. Confirmation email with link. No drip sequence.

Source tag: v46_behavioral_health_brief

60+ sources including Acuity Brands SEC filing (Feb 2024), Lifepoint 8-K disclosure (Oct 2023), Ardent Health Services public disclosure (Nov 2023), Community Health Systems Fortra GoAnywhere incident (Feb 2023), HHS OCR breach portal entries, SAMHSA 42 CFR Part 2 final rule text, Texas Health & Safety Code Ch. 181 + Ch. 611, TDPSA §541.062 + §541.151, FTC 16 CFR §318 (2024 Revision Final Rule), DEA EPCS 21 CFR §1311, IBM X-Force 2024 dwell-time analysis, CrowdStrike 2024 kill-chain analysis, SAMHSA NIMDAT submission guidance, Availity / Change Healthcare incident reporting, MPI / Crumpton / Cision BH-sector threat coverage.
View gate page →

By submitting you agree to receive a one-time email with the PDF. We don't add you to any drip sequence. Source tag: v46_behavioral_health_brief.

FAQ

Questions Texas BH & Mental Health Clinic Operators Ask Before Signing.

Direct answers. Not legal advice. Not a substitute for your BH-MSO counsel — but enough to know whether we're a fit.

42 CFR Part 2 (SAMHSA) imposes federal criminal liability on unauthorized disclosure of SUD records — including disclosure to law enforcement, courts, or employers absent specific written patient consent. HIPAA Security Rule imposes civil penalties and HHS OCR enforcement. For a TX behavioral health clinic with an MAT program the BH-EHR dwell-time compromise carries double-jeopardy exposure. CoreRecon's Fortress and Command tiers produce a consent-managed disclosure language library for 42 CFR Part 2, the SAMHSA breach-notification workflow with the 2-business-day disclosure trigger, and the OCR 60-day HIPAA clock running on a parallel track.
Yes. Beacon EDR on every clinical workstation running Credible (Behavioral Health Group, Sinfonia, decision-support modules), Kipu (SUD/IOP/RCM), myEvolv (Netsmart — community BH), Netsmart (Avatar / myAvatar), and Epic Behavioral Health module (large-system deployments). SOC threat intel is BH-EHR-aware: SUD-record exfil patterns (note-level flags + consent-management audit trail lateral movement), teletherapy video session recording access events, e-prescribe CSOS for MAT buprenorphine / naltrexone dispensing, and consent-manifest drift detection. Standard MSSPs watch EDR signals; our SOC instruments the BH-EHR attack surface explicitly so a SUD-record exfil trigger fires before the encryption event.
TX HSC Ch. 611 (Mental Health Records) requires specific written consent for disclosure of mental-health records — narrower than HIPAA's permissive disclosure framework in several respects. The chapter imposes TX AG enforcement, additional 60-day breach-notification windows on TX residents, and heightened mental-health-records consent language. A TX behavioral health clinic thus operates under HIPAA + TX HSC Ch. 611 simultaneously, with the BH-specific consent-language library sitting inside the SOC's breach-notification workflow. CoreRecon's Fortress and Command tiers include the TX HSC Ch. 611 consent-managed disclosure library and the dual-track HIPAA + state breach clock pre-built.
Yes — as of the FTC Health Breach Notification Rule 2024 Revision Final Rule, the rule explicitly covers health apps, period-tracking apps, BH companion apps, and direct-to-consumer mental-health platforms that are not HIPAA-covered entities. The 2024 Revision removed the ‘personal health record’ limitation and broadened the definition of ‘breach of security’ to include unauthorized disclosures. For a TX BH organization shipping a non-HIPAA BH app or operating a direct-to-consumer tele-mental-health platform, the FTC HBNR is in scope — and CoreRecon's monitoring + breach-notification workflow is built to trigger the FTC notification within 60 days as well as the HIPAA + TX HSC Ch. 611 + TX HB 300 stack.
Our monitoring runs on your endpoint and network infrastructure independently of the BH-EHR vendor — we don't lose visibility if Credible / Kipu / myEvolv / Netsmart has an outage. During a SUD-record exfil event, our SOC continues watching clinical workstations, prescribing terminals, telehealth video endpoints, billing/claims terminals, and the MSO admin SSO. We identify the SUD-record exfil pattern (note-level flags + consent-management audit trail modification), contain within the 30-minute SLA, and trigger the SAMHSA 42 CFR Part 2 breach-notification pre-flight with consent-managed disclosure language + the HIPAA OCR 60-day clock + the FTC HBNR 60-day clock + the TX AG TDPSA 30-day clock running on parallel tracks.
When a BH-EHR credential compromise exposes SUD patient records at a TX MAT program, two notification clocks start on day zero: the 42 CFR Part 2 SAMHSA breach-notification workflow (with the consent-managed disclosure pre-flight tracking written patient consent before any disclosure happens), and the HIPAA Security Rule OCR 60-day breach clock with TX HSC Ch. 611 + TX HB 300 dual-track state breach notification. CoreRecon's breach-notification workflow runs all four (SAMHSA + OCR + TX HSC + TX HB 300) on a single dashboard, distributes consumer notification to affected TX residents, tracks the consumer-request response window, and assembles the consent-manifest revision log regulatory counsel will need. Default scope across Sentinel and Fortress; full authorship at Command tier.
Beacon EDR + Conditional Access + 24/7 SOC monitoring across every clinical workstation, prescribing terminal, telehealth video endpoint, community-clinic laptop, mobile-crisis-team laptop, billing/claims terminal, and MSO admin SSO. The MSO admin SSO is the highest-value attack surface: a single admin compromise gives the attacker visibility into every clinic's BH-EHR admin console, every credentialed prescriber's EPCS account, and every clinic's consent-management audit-trail storage. BH-MSO Fortress tier adds MSO admin SSO monitoring + cross-clinic credential anomaly detection; Command tier authored documentation includes MSO-wide SDVOSB set-aside procurement documentation (CMHC / SAMHSA / VA behavioral health sub-contracts).
Yes. CoreRecon is CVE-verified Service-Disabled Veteran-Owned (SDVOSB) and listed in Texas DIR cooperative contract catalogs (TIPS / BuyBoard). BH-MSOs that hold CMHC contracts, SAMHSA block-grant sub-contracts, VA Choice / TriWest behavioral health subcontracts, or HHS Office of Behavioral Health awards have a documented SDVOSB advantage over generic MSSPs. We produce the SOC + IR retainer + 42 CFR Part 2 SAMHSA breach-notification authorship + HIPAA + TX HSC Ch. 611 + TX HB 300 dual-track state breach workflow + SDVOSB set-aside procurement documentation these federal/state BH contracting channels require without a separate open-market bid cycle.
📍 Texas-Based SOC
🎖️ SDVOSB-Certified (CVE)
🇺🇸 USMC Veteran-Led Team
🛡️ 24/7 SOC — 30-Min IR SLA
📋 42 CFR Part 2 + HIPAA Dual-Track
🤝 Month-to-Month

42 CFR Part 2. HIPAA. TX HSC Ch. 611. FTC HBNR.
CoreRecon Protects All Four.

Acuity Brands lost 2.5M+ records to LockBit in Feb 2024. Lifepoint Health ALPHV Oct 2023. Ardent Health TX offline Nov 2023. Behavioral Health Group TX SUD exposure with SAMHSA breach-notification triggered. Deer Oaks TX $225K ransom. 42 CFR Part 2 federal criminal liability stacks on HIPAA civil penalties. TX HSC Ch. 611 + TX HB 300 + TDPSA + FTC HBNR run on parallel clocks. The only question is whether your BH-MSO has a documented BH-EHR-aware SOC, a consent-managed 42 CFR Part 2 disclosure language library, and four-clock dual-track IR — or a hope and an underwriter carve-out.

Start the free BH-MSO security posture assessment. Takes 20 minutes. Written report with prioritized findings. No sales deck.

Start Your Free BH-MSO Security Posture Assessment →