CoreRecon Threat Intelligence  •  Texas Behavioral Health & SUD  •  July 2026 V46

TX Behavioral Health & SUD:
Psychiatric Records, EHR Breach, 42 CFR Part 2

Acuity Brands lost 2.5M+ records in February 2024 to a LockBit affiliate. Lifepoint Health (ALPHV, Oct 2023) had clinical operations disrupted. Ardent Health Services (Nov 2023) took 30+ hospitals — including TX facilities — offline. Community Health Systems (Fortra GoAnywhere, Feb 2023) exposed 1M+ patient records. Behavioral Health Group TX triggered a 42 CFR Part 2 SAMHSA notification on SUD record exposure. Deer Oaks TX paid $225,000 ransom on BH/ALF records. LockBit, Rhysida, and Qilin are actively targeting BH-EHR credentials — Credible, Kipu, myEvolv, Netsmart. 42 CFR Part 2 creates federal criminal liability on top of HIPAA civil penalties. TX HSC Ch. 611 governs mental-health records. TX HB 300 sweeps all BH data. TDPSA §541.062 enumerates SUD/psychiatric data as sensitive.

Download the Full Threat Brief — Free
July 2026 CoreRecon Intelligence Report V46 42 CFR Part 2 + HIPAA Security Rule + TX HSC Ch. 611 + TX HB 300 + TDPSA §541.062 38+ Verified Sources
5–10×
Psychiatric / SUD records
dark-web price multiple
vs standard medical
42 CFR
Federal criminal liability
for Part 2 SUD record
disclosure
38+
Verified sources
SAMHSA / HHS OCR /
Krebs / IBM X-Force
$89
Sentinel per
endpoint / month
TX-resident SOC
30min
CoreRecon IR SLA
TX-resident SOC
SDVOSB certified
What This Brief Covers

TX BH & SUD
Cyber Threat Brief

Full intelligence report on the attack surface facing Texas behavioral-health and SUD treatment clinics — from the Acuity Brands LockBit affiliate breach (2.5M+ records, Feb 2024) and Lifepoint Health ALPHV (Oct 2023), to the Ardent Health TX outage (Nov 2023), Community Health Systems Fortra GoAnywhere (Feb 2023, 1M+ records), Behavioral Health Group TX 42 CFR Part 2 SAMHSA notification, Deer Oaks TX ($225,000 ransom), and the regulatory stack that binds every Texas BH/SUD clinic: 42 CFR Part 2 federal criminal liability, HIPAA Security Rule, TX HSC Ch. 611 mental-health records + consent, TX HB 300, and TDPSA §541.062 sensitive-data enumeration. Coverage built for BH executive directors, clinical leadership, compliance officers, and IT leads at outpatient clinics, residential programs, MAT providers, and crisis stabilization units across Texas.

38+ Verified Sources Including:

  • Acuity Brands (Feb 2024) — 2,500,000+ records, LockBit 3.0 affiliate, HHS OCR + multi-state notification; BH/psychiatric component in exposed population
  • Lifepoint Health (Oct 2023) — ALPHV/BlackCat, large BH service line footprint, patient diversion from referring BH partners
  • Ardent Health Services TX (Nov 2023) — 30+ hospitals offline including TX facilities, psychiatric-unit diversion
  • Community Health Systems Fortra GoAnywhere (Feb 2023) — 1M+ patient records, CVE-2023-0669 zero-day, multi-state BH network affected
  • Behavioral Health Group TX (2024) — SUD patient record exposure; 42 CFR Part 2 SAMHSA notification triggered
  • Deer Oaks TX (2024) — $225K ransom; BH/ALF patient records exfiltrated; HHSC reportable event
  • 42 CFR Part 2 (SAMHSA SUD Confidentiality Law) — federal criminal liability for SUD record disclosure; 2024 Part 2/HIPAA alignment amendment
  • HIPAA Security Rule (45 CFR §164.308/§164.312) — Risk Analysis, MFA, EDR, IR plan mandate
  • TX HSC Ch. 611 (Mental Health Records) + TX HB 300 (TX HSC Ch. 181) + TDPSA §541.062 sensitive-data stack
  • BH-EHR attack vectors: Credible, Kipu, myEvolv, Netsmart credential compromise campaigns; telehealth platform SSO chains; DEA EPCS two-factor token theft
  • 30/60/90-day hardening checklist with 42 CFR Part 2 + HIPAA + TX HSC Ch. 611 + TX HB 300 + TDPSA control mapping
  • CoreRecon Sentinel / Fortress / Command tier fit for 10–250 endpoint BH/SUD practices, residential programs, MAT providers, and crisis stabilization units

Access the Full Brief

We email it as a PDF attachment. No newsletter. No spam. One delivery.

We use the contact details you provide to deliver this brief and respond to your request. Please do not include patient, client, account, case, or other sensitive information in this form.

Submission failed — please try again or email john@corerecon.com

Brief Sent.

Check your inbox — the PDF is on its way. If it lands in spam, drag it to your inbox so you find it later.

Want it immediately? Download below — we already emailed a copy. Then take the next step: protect sensitive patient and SUD records in stigma-sensitive care operations, test ransomware recovery readiness, and map HIPAA, 42 CFR Part 2, and Texas compliance obligations.

Download PDF Now → Review Your Behavioral-Health Security Posture → Read the Behavioral-Health Threat Analysis → Explore Managed Cybersecurity Services →

Questions before then? Call (800) 955-2596 — live TX SOC, not a call center.

SDVOSB Certified • TX-Based SOC • No offshore data routing
Questions? (800) 955-2596
✅ 38+ verified sources
✅ 42 CFR Part 2 + HIPAA + TX HSC Ch. 611 + TX HB 300 + TDPSA §541.062 covered
✅ 8-section 30/60/90 checklist
✅ TX-specific incidents: Acuity Brands, Lifepoint, Ardent, BHG, Deer Oaks
✅ One email delivery, one PDF