CoreRecon Threat Intelligence  •  Behavioral Health & Mental Health Clinics  •  July 2026 V50

TX Behavioral Health & Mental Health Clinics:
BH-EHR Credential Theft, 42 CFR Part 2 Re-Disclosure Trap, BH-MSO M&A Cyber Risk

Behavioral Health Group TX (2024 ransomware-mediated SUD record exposure — 42 CFR Part 2 SAMHSA notification triggered, dual-track disclosure). Deer Oaks Behavioral Health TX APC ($225K ransom — BH/ALF records exfiltrated, HHSC reportable event). Acuity Brands (Feb 2024 LockBit 3.0 affiliate — 2.5M+ records, BH-affiliated workforce slice). Lifepoint Health (Oct 2023 ALPHV/BlackCat — large BH service-line footprint). Ardent Health Services TX (Nov 2023 — 30+ hospitals offline including TX facilities, psychiatric-unit diversion). Community Health Systems Fortra GoAnywhere (Feb 2023, CVE-2023-0669, 1M+ records). BH-EHR credential compromise at Credible, Kipu, Netsmart myEvolv. 42 CFR Part 2 federal criminal liability on SUD record disclosure — 2024 Part 2/HIPAA single-consent amendment did NOT remove criminal liability. TX HB300 (TX HSC Ch. 181) 60-day AG notification clock + $7,500/violation. TDPSA §541.062 sensitive-data enumeration of SUD/psychiatric data. FTC HBNR (16 CFR Part 318, 2024 update) 30-day clock for non-HIPAA-covered mental-health apps.

V50 — distinct from V46 SUD-Treatment brief. V50 covers outpatient BH / IOP-PHP / psychiatry MSO networks / M&A cyber due-diligence and BH-EHR credential-vector analysis (Credible, Kipu, myEvolv, Netsmart), beyond the V46 SUD/residential-program scope.
Download the Full Threat Brief — Free
July 2026 CoreRecon Intelligence Report V50 HIPAA + 42 CFR Part 2 + TX HB 300 + TX HSC Ch. 611 + TDPSA §541.062 + FTC HBNR 60+ Verified Sources
5–10×
Psychiatric / SUD records
dark-web price multiple
vs standard medical
42 CFR
Federal criminal liability
for Part 2 SUD record
disclosure
60d
TX HB300
AG notification
clock
$89
Sentinel per
endpoint / month
TX-resident SOC
$2.5K+
Command tier
flat monthly retainer
M&A-active BH
What This Brief Covers

TX BH & Mental Health
Cyber Threat Brief

Full intelligence report on the attack surface facing Texas behavioral-health and mental-health clinics — from Behavioral Health Group TX (2024 ransomware-mediated SUD record exposure), Deer Oaks Behavioral Health TX APC ($225K ransom, BH/ALF records exfiltrated), and Acuity Brands (Feb 2024 LockBit 3.0 affiliate, 2.5M+ records, BH-affiliated workforce slice), to the BH-EHR credential compromise campaigns targeting Credible, Kipu, Netsmart myEvolv, the 42 CFR Part 2 federal criminal liability on SUD record disclosure (2024 Part 2/HIPAA single-consent amendment did NOT remove criminal liability), TX HB 300 (TX HSC Ch. 181) 60-day AG notification clock + $7,500/violation civil penalty, TX HSC Ch. 611 mental-health records + consent, TDPSA §541.062 sensitive-data enumeration of SUD/psychiatric data, and the FTC Health Breach Notification Rule (16 CFR Part 318, 2024 update) 30-day clock for non-HIPAA-covered mental-health apps. Coverage built for BH executive directors, clinical leadership, compliance officers, IT leads at outpatient clinics, IOP/PHP programs, psychiatry practices, MAT providers, and BH-MSO networks across Texas.

8 Sections — 60+ Verified Sources Including:

  • Section 1 — HIPAA Pain Points: BH-EHR credential hygiene (Credible, Kipu, Netsmart myEvolv); multi-county MSO cross-county credential anomaly surface; telehealth recording storage (TX Medicaid TAC §354.1432); patient-portal MFA bypass; intake-paper residual PHI
  • Section 2 — 42 CFR Part 2 Re-Disclosure Trap: Federal criminal liability on SUD record disclosure; 2024 Part 2/HIPAA single-consent amendment (did NOT remove criminal liability); SAMHSA NIMDAT integration; court-ordered disclosure exceptions; written-consent language requirements; dual-track Part 2 + HIPAA breach notification calendar
  • Section 3 — SAMHSA / M&A Vendor Risk: BH roll-up cyber-due-diligence (BHG TX, Deer Oaks TX, Green Ridge BH TX); hosted BH-EHR concentration risk; third-party BH-EHR BAA enforcement gaps; MSO M&A representations & warranties
  • Section 4 — TX HB300 + FTC HBNR Notification Clock: 60-day AG disclosure ($7,500/violation); 30-day individual notice; TDPSA §541.062 sensitive-data enumeration; FTC 30-day HBNR for non-covered-entity mental-health apps
  • Section 5 — Named TX BH Breach Case Study: BHG TX SUD record exposure, Deer Oaks TX APC $225K ransom, Acuity Brands BH workforce slice — timeline, attack chain, regulatory penalty stack
  • Section 6 — CoreRecon Wedge Stack: 30-min IR SLA, SDVOSB (TX DIR TIPS / BuyBoard / TXMAS), TX data residency, 24/7 SOC + BH-EHR-aware EDR, BH-EHR vendor pivot-aware playbook
  • Section 7 + 8 — Pricing & Engagement Anchors: Sentinel $89/endpoint, Fortress $109–$129, Command $2,500+ flat retainer; 30-day activation roadmap
  • CoreRecon Sentinel / Fortress / Command tier fit for TX solo BH practitioners (10–40 endpoints) up to large BH MSO networks (120–250+ endpoints)

Access the Full Brief

We email it as a PDF attachment. No newsletter. No spam. One delivery.

Submission failed — please try again or email john@corerecon.com

Brief Sent.

Check your inbox — the PDF is on its way. If it lands in spam, drag it to your inbox so you find it later.

Want it immediately? Download below — we already emailed a copy.

Download PDF Now → Book Free Assessment →

If verification of your work email is delayed, we’ll re-send the PDF as soon as the check completes.

Questions before then? Call (800) 955-2596 — live TX SOC, not a call center.

SDVOSB Certified • TX-Based SOC • No offshore data routing
Questions? (800) 955-2596
✅ 60+ verified sources
✅ HIPAA + 42 CFR Part 2 + TX HB 300 + TX HSC Ch. 611 + TDPSA §541.062 + FTC HBNR covered
✅ 8-section BH-EHR credential-vector + M&A cyber due-diligence review
✅ TX-specific incidents: BHG TX, Deer Oaks TX APC, Acuity Brands BH slice
✅ One email delivery, one PDF