Acuity Brands lost 2.5M+ records in February 2024 to a LockBit affiliate. Lifepoint Health (ALPHV, Oct 2023) had clinical operations disrupted. Ardent Health Services (Nov 2023) took 30+ hospitals — including TX facilities — offline. Community Health Systems (Fortra GoAnywhere, Feb 2023) exposed 1M+ patient records. Behavioral Health Group TX triggered a 42 CFR Part 2 SAMHSA notification on SUD record exposure. Deer Oaks TX paid $225,000 ransom on BH/ALF records. LockBit, Rhysida, and Qilin are actively targeting BH-EHR credentials — Credible, Kipu, myEvolv, Netsmart. 42 CFR Part 2 creates federal criminal liability on top of HIPAA civil penalties. TX HSC Ch. 611 governs mental-health records. TX HB 300 sweeps all BH data. TDPSA §541.062 enumerates SUD/psychiatric data as sensitive.
Full intelligence report on the attack surface facing Texas behavioral-health and SUD treatment clinics — from the Acuity Brands LockBit affiliate breach (2.5M+ records, Feb 2024) and Lifepoint Health ALPHV (Oct 2023), to the Ardent Health TX outage (Nov 2023), Community Health Systems Fortra GoAnywhere (Feb 2023, 1M+ records), Behavioral Health Group TX 42 CFR Part 2 SAMHSA notification, Deer Oaks TX ($225,000 ransom), and the regulatory stack that binds every Texas BH/SUD clinic: 42 CFR Part 2 federal criminal liability, HIPAA Security Rule, TX HSC Ch. 611 mental-health records + consent, TX HB 300, and TDPSA §541.062 sensitive-data enumeration. Coverage built for BH executive directors, clinical leadership, compliance officers, and IT leads at outpatient clinics, residential programs, MAT providers, and crisis stabilization units across Texas.
We email it as a PDF attachment. No newsletter. No spam. One delivery.